Istio is a long wild river: how to navigate it safelyyour fights, start small Stabilizing Istio Start with few simple features such as: ● Injecting sidecars, HTTP/2 LoadBalancing ● Traffic shifting for canaries Build confidence in the system and understanding First, headless services, now labels... Who said that migrating to Istio is only about adding sidecars?? 50 Label selector updates for app and version labels Adopting Istio Fair enough, let’s do the IstioOperator manifest. 55 Istio proxy performance and capacity Adopting Istio ● Putting sidecars everywhere has a cost ○ Latency ○ Compute resources The Istio 1.9 community reference values0 码力 | 69 页 | 1.58 MB | 1 年前3
THE GITOPS GUIDE
TO BUILDING &
MANAGING INTERNAL
PLATFORMSleverages Istio as its service mesh, and one aspect of Istio is its reliance on sidecars for secure network communication. Sidecars, which are language agnostic, act as service proxies and allow for all traffic container. The second benefit is that sidecars are injected automatically, no matter the workload. This means that even if your software team does not know about sidecars, they are still going to utilize benefits. This is what baked-in security looks like in practice. 3. Enforce zero-trust security 4. Sidecars enable better security A platform is an intricate system and it cannot be bought ready made from0 码力 | 15 页 | 623.52 KB | 1 年前3
Istio at Scale: How eBay is building a massive Multitenant Service Mesh using Istio& thousands of Pods with sidecar Envoys ○ Measure Config convergence time ■ Time taken by all sidecars to get config from Pilot without any errors ■ For thousands of services & endpoints ■ With different ○ Disabled egress traffic to restrict config pushed to sidecars ● Main Takeaways ○ P99.9 time from single Pilot instance to 0 - 3,000 sidecars < 1 second ○ Pilot CPU & memory within acceptable limits:0 码力 | 22 页 | 505.96 KB | 1 年前3
Istio Security Assessment“distroless” version of it’s Docker image which builds a minimal, hardened version that can be used for Sidecars. These types of security controls should not be optional. Reproduction Steps Attach to a Pod that Distroless image which can be used by other Istio control plane components (like Pilot) as well as the sidecars used by Pods and workloads. Make this configuration the default option for all systems possible on how to disable them when users want to opt-out of these controls. This should be enabled for Sidecars and services within the Istio control plan as well. 23 | Google Istio Security Assessment Google0 码力 | 51 页 | 849.66 KB | 1 年前3
IstioCon2023 Welcome KeynoteWhat’s New Since 2022 CNCF Graduation Ambient Mesh A new dataplane mode for Istio without sidecars. Graduated Announcing Istio's graduation within the CNCF Join CNCF Istio has applied to0 码力 | 14 页 | 1.31 MB | 1 年前3
How HP set up secure and
wise platform with Istiodefinition HTTP filters Network filters UDP listener filters … Match outbound listeners in all sidecars Or Istio gateway The Lua code that Envoy will execute. Which port number the filter will apply0 码力 | 23 页 | 1.18 MB | 1 年前3
在Kubernetes上部署高可用的Service Mesh监控API TargetsGlobal view - Querier ● Stateless, horizontally scalable. ● Fan out queries to all sidecars and stores. Merge and deduplicate query results. ● Global view + HAUnlimited Retention ● Prometheus0 码力 | 35 页 | 2.98 MB | 6 月前3
Service mesh security best practices: from implementation to verification is natively encrypted, such as HTTPS 3. use k8s network policies to limit traffic bypassing sidecars Cluster security best practices: safely handle policy exceptions Cluster security Access control0 码力 | 29 页 | 1.77 MB | 1 年前3
Istio + MOSN 在 Dubbo 场景下的探索之路资源名称 CDS EDS LDS RDS Virtualservices ✔ Gateways Serviceentries Destinationrules Envoyfilters Sidecars ConfigClientQuotaspecs ConfigClientQuotaspecbindings Authorizationpolicies Requestauthentications0 码力 | 25 页 | 3.71 MB | 6 月前3
Performance tuning and best practices in a Knative based, large-scale serverless platform with Istioservice access cross user namespace. o The sidecar CR helps to limit the known egress hosts for sidecars, sidecar needs to knows mesh in his own user namespace only. o We can limit the mesh size to0 码力 | 23 页 | 2.51 MB | 1 年前3
共 37 条
- 1
- 2
- 3
- 4













