Is Your Virtual Machine Really Ready-to-go with Istio?for internal traffic ○ ExternalName ■ Service <-> DNS name ○ External IPs #IstioCon V1.1 ServiceEntry #IstioCon V1.6-1.8 Better VM Workload Abstraction A K8s Service and Pods Two separate object Component Deployment WorkloadGroup Service registry and discovery Service ServiceEntry K8s Pods labels: app: foo class: pod ServiceEntry selector: app: foo Istio Workload Entries labels: app: foo class: Workload Entry ○ single non-Kubernetes workload ○ mTLS using service account ○ work with an Istio ServiceEntry ● Workload Group ○ a collection of non-K8s workloads ○ metadata and identity for bootstrap0 码力 | 50 页 | 2.19 MB | 1 年前3
Redis TLS Origination through the sidecarHow it looks after TLS origination How to do Redis TLS origination with the sidecar? 1. Create ServiceEntry for external service such that Istio knows about Redis 2. Create DestinationRule to configure redis-client with a sidecar, however no ServiceEntry and no DestinationRule Expectation: Should fail when trying to connect over plain TCP 2. Create DestinationRule and ServiceEntry Expectation: Ability to connect0 码力 | 9 页 | 457.76 KB | 1 年前3
Istio at Scale: How eBay is building a massive Multitenant Service Mesh using Istio... serviceEntries: - apiVersion: networking.istio.io/v1beta1 kind: ServiceEntry spec: ... workloadEntries: - apiVersion: networking.istio.io/v1beta10 码力 | 22 页 | 505.96 KB | 1 年前3
共 3 条
- 1













