Istio audit report - ADA Logics - 2023-01-30 - v1.0
Repository https://github.com/istio/istio Language Golang Istio API definitions Repository https://github.com/istio/api Language Golang Istio documentation Repository https://github.com/istio/istio io/istio/pkg/bootstrap https://github.com/istio/istio/blob/6 5478ea81272c0ceaab568974aff7 00aef907312/pkg/bootstrap/fuzz_t est.go#L26 2 FuzzRunTemplate istio.io/istio/pkg/kube/inje ct https://github.com/istio/istio/blob/6 https://github.com/istio/istio/blob/6 5478ea81272c0ceaab568974aff7 00aef907312/security/pkg/k8s/chir on/fuzz_test.go#L22 4 FuzzIstioCASign istio.io/istio/security/pkg/ pki/ca https://github.com/istio/istio/blob/60 码力 | 55 页 | 703.94 KB | 1 年前3Istio Security Assessment
the code base shown below: • github.com/istio/istio – 7353c84b560fd469123611476314e4aee553611d • github.com/istio/proxy – c51fe751a17441b5ab3f5487c37e129e44eec823 • github.com/istio/istio.io – 26da DestinationRules do not specify a CA certificate chain. Description As discussed in the istio/istio GitHub repository’s issue #25652,12 as part of its process to generate Envoy configurations from DestinationRule not attempt to verify the validity of the upstream server’s TLS certificate. Note: This issue and GitHub issue were originally noted by the Google team. res := model.SdsCertificateConfig{ CertificatePath:0 码力 | 51 页 | 849.66 KB | 1 年前3Istio-redirector: the way to go to manage thousands of HTTP redirections
VirtualService file. ● Golang service ○ Convert .csv to VirtualService ○ Open Pull Request on Github ○ Fetch info from Kubernetes cluster ○ Expose an API to be used with REST or a CLI ● React.js generates the Istio VirtualService files. Then, it automatically creates the Pull Request on GitHub on on our GitOps repo How does it work ? #IstioCon Creating the .csv Importing the file Generating performances! #IstioCon Check it out on Github https://github.com/blablacar/istio-redirector And leave a star ? #IstioCon How can we use istio-redirector ? The GitHub repository host also a HelmChart that0 码力 | 13 页 | 1.07 MB | 1 年前3Performance tuning and best practices in a Knative based, large-scale serverless platform with Istio
is leveraged in a Knative based platform Traffic on Knative with mesh enabled (based on https://github.com/knative/serving) #IstioCon Performance bottleneck analysis and tuning • Performance Criteria: Istio scalability optimization during Knative Service provisioning • Benchmark: Kperf (https://github.com/knative-sandbox/kperf) is a benchmark tool for Knative which can generate specific Knative Service community is working to use Destination rules for Pod IPs addressable directly. Knative issue: https://github.com/istio/istio/issues/23494 Unleash maximum scalability by fully leveraging Istio features in Knative0 码力 | 23 页 | 2.51 MB | 1 年前3Observability and Istio Telemetry
• Endpoint • ServiceRelation • ServiceInstanceRelation • EndpointRelation • etc. https://github.com/apache/incubator-skywalking/blob/master/docs/en/ concepts-and-designs/oal.md • Extendable Aggregation Alarm https://github.com/apache/incubator- skywalking-query-protocolEcosystem powered by GraphQL and SkyWalking core • Open source UI project for SkyWalking • https:// github.com/ TinyAllen/0 码力 | 21 页 | 5.29 MB | 5 月前3Preserve Original Source Address within Istio
@hzxuzhonghu #IstioCon About me Zhonghu Xu:an open source engineer from Huawei Cloud. - Github:https://github.com/hzxuzhonghu - Istio steering committee member - Istio Core Maintainer & Contributor Cluster TCP traffic ④ External TCP (not supported well) #IstioCon Thank you! @hzxuzhonghu https://github.com/hzxuzhonghu0 码力 | 29 页 | 713.08 KB | 1 年前313 Istio 流量管理原理与协议扩展 赵化冰
中有哪些服务?缺省路由) v Service Registry § Kubernetes:原生支持 § Consul、Eureka 等其他服务注册表:MCP over xDS (https://github.com/istio-ecosystem/consul-mcp) v 通过CRD定义的服务数据 q 自定义流量规则(如何将请求路由到这些服务?) v 通过CRD定义的流量规则 服务数据 流量规则 WorkloadEntry:单独添加 Workload,对于虚机支持更友好 • MCP 适配器: 将第三方注册表中的服务加入到 Pilot 中 Consul MCP Adapter https://github.com/istio-ecosystem/consul-mcp 欢迎大家试用、共建! 4 Istio 流量管理 – 控制面 – 流量管理模型 Gateway Virtual Service 控制面的扩展性好 问题: • 需要修改 Pilot、xDS 协议 和 Envoy Filter 14 Istio 协议扩展:EnvoyFilter Redis Proxy https://github.com/zhaohuabing/istio-redis-culster EnvoyFilter 15 Istio 协议扩展:控制面扩展机制 优点: • 对 Istio 和 Envoy0 码力 | 20 页 | 11.31 MB | 5 月前3Envoy原理介绍及线上问题踩坑
式开发框架,语言强相关。 • 非侵入服务网格最早为2016年Linkerd。 • 2017年,Goole、IBM、Lyft发布Istio。Istio目前为服务网格的事实标准,并且是2019年Github增长最快的TOP 10开源 项目之一。目前最新为1.10版本。 Copyright © Huawei Technologies Co., Ltd. All rights reserved. Envoy过滤器架构-相关代码 • Istio项目中Envoy代码分为两部分: • Envoy原始项目的clone,在 https://github.com/istio/envoy.git • Istio中适配所使用的的插件 https://github.com/istio/proxy.git • 编译时由proxy项目作为入口,自动引用envoy项目 • 主要框架代码位于envoy项目,包含进程启动,线程0 码力 | 30 页 | 2.67 MB | 1 年前3Debugging Istio Within the Department of Defense
Nellis @nmnellis Adam Toy @adam_toy1 github.com/atoy3731 https://p1.dso.mil/#/products/big-bang https://repo1.dso.mil/platform-one/big-bang/bigbang https://github.com/atoy3731/istiocon-demo (WIP)0 码力 | 17 页 | 1.49 MB | 1 年前3Set Sail for a Ship-Shape Istio Release
investigate this release? ○ How soon before you will use it in production? #IstioCon Feedback Across ● GitHub issues ● discuss.istio.io ● Twitter ● User discussions ● Upgrade survey #IstioCon Common Feedback managers to sift through commits to figure out what changed and write notes, often without context. GitHub asks developers and maintainers whether a pull request has user facing changes. ● If it does0 码力 | 18 页 | 199.43 KB | 1 年前3
共 26 条
- 1
- 2
- 3