Building resilient systems inside the mesh:
abstraction and automation of Virtual Service
generationBuilding resilient systems inside the mesh: abstraction and automation of Virtual Service generation Vladimir Georgiev, Thought Machine #IstioCon Sync calls failures inside the mesh ● Everyone0 码力 | 9 页 | 1.04 MB | 1 年前3
Istio Security Assessmentits control plane. The goal of the assessment was to identify security issues related to the Istio code base, highlight high risk configurations commonly used by administrators, and provide perspective areas of focus for subsequent phases of the assessment. A test plan was created which matched areas of code with specific security controls (e.g. service discovery, certificate lifecycle, side car injection) architectures were used to provide testers with a way of validating that security expectations in the code were implemented when deployed. Each environment was deployed following Istio Documentation using0 码力 | 51 页 | 849.66 KB | 1 年前3
IstioCon2023 Welcome Keynotewizards of Stack Overflow. Bugs And Security ● Read this quick explanation on how to report bugs, in code or in documentation. ● The Istio security team responds rapidly to vulnerability reports. Read how Contributor ● The Istio Community README is the starting point for contributors who want to work on code, docs or other parts of Istio. ● You can access our trove of technical content and working documents Multi-cluster orchestration JP Morgan SLO Generation Reflecting on the Value of Community Housekeeping • View the full IstioCon-VIRTUAL schedule • Abide by CNCF Code of Conduct • Use the official #IstioCon0 码力 | 14 页 | 1.31 MB | 1 年前3
Istio audit report - ADA Logics - 2023-01-30 - v1.0model of Istio to guide the security audit as well as future security audits. 2. Carry out a manual code audit for security issues. 3. Review the fixes for the issues found in an audit from 2020. 4. Review obtained in parts of code bases that receive less attention. Our assessment is that, not counting the Operator, Istio is a very well-maintained and secure project with a sound code base, well-established test coverage with little to no room for improvement. We identified a few APIs in security-critical code parts that would benefit from fuzzing and wrote fuzzers for these. In total, 6 fuzzers were written0 码力 | 55 页 | 703.94 KB | 1 年前3
Set Sail for a
Ship-Shape Istio ReleaseIstio community didn’t have a process #IstioCon Led To ● Upgrade Working Group ● Release Note Generation ● Definition of Done #IstioCon Upgrade Working Group Mission: To improve the stability, user level: experimental, alpha, beta, and stable ● Ensuring appropriate documentation, testing, and code completion is done for each level ● Making sure that features continue to mature #IstioCon Release0 码力 | 18 页 | 199.43 KB | 1 年前3
Is Your Virtual Machine Really Ready-to-go with Istio?API server ■ Requires creating an RBAC impersonation rule for each user ■ Private key and CSR generation limited to Istio agent (no support of other provisioner tools and HSM incompatible) ■ Limitations #IstioCon (eBPF-based) TCP/IP Stack Bypass ● eBPF ○ In-kernel virtual machine ○ Running user code in kernel space safety ○ Tracing, security ○ Networking ● Hooks ○ sock_ops ■ Construct map0 码力 | 50 页 | 2.19 MB | 1 年前3
IstioCon 2021
Report#IstioCon Most popular sessions in English Session Welcome Keynote Using Istio to build the next generation 5G platform I want to sketch a mesh for you Istio service mesh at enterprise scale Improving0 码力 | 18 页 | 912.89 KB | 1 年前3
宋净超 从开源 Istio 到企业级服务:如何在企业中落地服务网格Certification Collaboration with NIST ● Author SP 800-204 series on microservice security ● R&D on Next Generation Access Control (NGAC) ● Exclusively co-host annual zero trust multi-cloud conference Best in0 码力 | 30 页 | 4.79 MB | 6 月前3
Performance tuning and best practices in a Knative based, large-scale serverless platform with Istiocom/gracezhang1110, www.linkedin.com/in/gong-zhang-75560670/ Advisory Software Engineer of IBM Cloud Code Engine team focusing on Knative Serving and Istio, contributor of the Knative and Cloud Foundry com/in/yu-zhuang- 51915287/ Architect and Senior Software Engineer in IBM Cloud. Working on IBM Cloud Code Engine (Serverless platform), focusing on Knative, Istio, and Tekton, community, leading team to running, and managing serverless, cloud- native applications. It provides benefits: Focus on code Scale to zero Quick entry to serverless computing … … traffic management observability security0 码力 | 23 页 | 2.51 MB | 1 年前3
Leveraging Istio for Creating API Tests - Low Effort API Testing for MicroservicesAPI request • Context propagation rarely obvious Challenge • Dependencies require lot of time to code • Many dependencies in a test suite • Dependency maintenance is effort intensive Solution • ML-driven ML-driven identification of candidate relationships • Supervised system to accept true positives • No code! | CONFIDENTIAL 17 ML-assisted Assertion Rule Learning createOrder Response: Recording { results • ML-driven identification of decision rules • Human review to accept the learned rules • No code! Test data | CONFIDENTIAL 18 Summary: create different types of tests efficiently by learning0 码力 | 21 页 | 1.09 MB | 1 年前3
共 19 条
- 1
- 2













