Istio Security Assessmentarchitecture review which extrapolated areas of focus for subsequent phases of the assessment. A test plan was created which matched areas of code with specific security controls (e.g. service discovery, certificate opt-out of these controls. This should be enabled for Sidecars and services within the Istio control plan as well. 23 | Google Istio Security Assessment Google / NCC Group Confidential Finding Insecure0 码力 | 51 页 | 849.66 KB | 1 年前3
宋净超 从开源 Istio 到企业级服务:如何在企业中落地服务网格Kubernetes cluster ● VM integration ● On-prem, AWS, Azure, GCP, OpenShift ● 10000+ core business apps ● Plan to move to public cloud in 18 months ● Using F5 to distribute traffic at the DMZ zone Solving the0 码力 | 30 页 | 4.79 MB | 6 月前3
Istio at Scale: How eBay is building a massive Multitenant Service Mesh using Istio● Origin or Request Authentication ○ Internal OpenID implementation for origin authentication ○ Plan to integrate with Istio #IstioCon How does it all scale …? ● Extensive Data-plane & Control-plane0 码力 | 22 页 | 505.96 KB | 1 年前3
Istio is a long wild river: how to navigate it safelyTakeaways Adopting Istio ● Headless services are erratic with Istio, use ClusterIP services instead, plan the migration wisely ● Use automation pipelines to label Deployments for traffic shifting ● Istio0 码力 | 69 页 | 1.58 MB | 1 年前3
共 4 条
- 1













