Istio Security Assessmentistio/istio/galley/pkg/config/source/kube/inmemory/kubesource.go#20 • istio/istio/mixer/adapter/prometheus/prometheus.go#24 • istio/istio/mixer/pkg/checkcache/keyShape.go Impact Malicious actors may be able resource: rt.ToResource(objMeta, schema, item, &pos), }, nil • istio/istio/mixer/adapter/prometheus/prometheus.go (line 24) func computeSha(m proto.Marshaler, log adapter.Logger) [sha1.Size]byte { ba0 码力 | 51 页 | 849.66 KB | 1 年前3
 探讨和实践基于Istio的微服务治理事件监控监控方案问题二:现有的系统能否完全满足需求 现有系统如何满足运维需求Istio现有的监控体系 指标监控 分布式追踪 日志系统Zipkin的架构图 Google Dapper Zipkin的实现EFK和Prometheus的架构图 DC1 DMZ Intranet Elascticsearch cluster APP logfile APP logfile APP logfile Kubernetes Kubernetes console APP logfile APP logfile APP logfile Kubernetes console search &analysis Prometheus TSDB基于请求和日志的关联性改进架构 A Agent B Agent C Agent Request(Transaction ID) A(application) Trasanctionid(CA0 码力 | 29 页 | 8.37 MB | 6 月前3
 Envoy原理介绍及线上问题踩坑可以修改全局注入参数 作用于所有目标空间的 pod 证书更新 Envoy启动流程 Envoy控制面流量 Envoy数据面流量 ./etc/istio/proxy/XDS SDS xDS CSR Prometheus configmaps Copyright © Huawei Technologies Co., Ltd. All rights reserved. Page 7 Envoy原理及总体架构-说明 • 启动concurrency数目的工作线程 • 启动看门狗线程监控各个工作线程是否定期touch,否则SIGABRT杀掉线程 • 启动admin RESTful监听,处理运行状态输出,prometheus收集等请求 • 定期将工作线程内监控数据stat进行合并 • 定期刷新DNS信息,加速域名解析。 • 目标cluster内主机列表健康状态判断。 • worker线程: • 通过启0 码力 | 30 页 | 2.67 MB | 1 年前3
 Debugging Istio Within
the Department of
Defenseverify-install ● bug-report #IstioCon Maintaining Istio ● Deployments ○ IstioOperator ● Monitoring ○ Prometheus ○ Grafana ○ Zipkin or Jaeger ○ Kiali #IstioCon GetIstio #IstioCon Community discuss.istio0 码力 | 17 页 | 1.49 MB | 1 年前3
 Moving large scale consumer
e-commerce Infrastructure to
Meshacross clusters #IstioCon Rollout - Istio setup and Microservices ● Export metrics to central prometheus ● Outlier detection for better reliability ● Enable Zonal routing, zonal deployment and HPA0 码力 | 14 页 | 1.76 MB | 1 年前3
 Service mesh security best practices: from implementation to verification Operation GitOps Gatekeeper RBAC Audit log Metrics Security testing tools Security dashboard Prometheus Kiali Security Lifecycle Concepts Secure Monitor Enforce Verify Demo: mesh security lifecycle0 码力 | 29 页 | 1.77 MB | 1 年前3
 Kubernetes容器应用基于Istio的灰度发布实践Mixer proxy svc proxy svc Logging Backend Quota Backend Auth Backend Metric Backend Prometheus AWS New Relic Huawei-APM apiVersion: "config.istio.io/v1alpha2" kind: metric metadata: name:0 码力 | 38 页 | 14.93 MB | 1 年前3
 Kubernetes容器应用基于Istio的灰度发布实践Mixer proxy svc proxy svc Logging Backend Quota Backend Auth Backend Metric Backend Prometheus AWS New Relic Huawei-APM apiVersion: "config.istio.io/v1alpha2" kind: metric metadata: name:0 码力 | 34 页 | 2.64 MB | 6 月前3
 Istio at Scale: How eBay is building a massive Multitenant Service Mesh using IstioLearning Platforms - Tensorflow, PyTorch, Jupyter Notebook, etc. ○ Central Logging & Tracing - Prometheus, ClickHouse, etc. ○ Messaging systems - Kafka, RabbitMQ, etc. ○ Programming Languages - Java0 码力 | 22 页 | 505.96 KB | 1 年前3
共 9 条
- 1
 













