IstioCon 2022 Report
score 2,467 Unique live viewers 219 Unique recording viewers #IstioCon New features at 2022 edition: ● Captioning for sessions in English ● Live transmission of Chinese sessions on Bilibili Cruz, Luis Sánchez Sponsors Norma Lopez Promotion Fernando Hernández, Montse Hernández Video edition Uriel García Attention to participants Teyza Ponce, Carolina Sánchez #IstioCon Thank you!0 码力 | 20 页 | 2.44 MB | 1 年前3Is Your Virtual Machine Really Ready-to-go with Istio?
I/O Virtualization ● SRIOV => SIOV relay w/ DPDK SRIOV #IstioCon SmartNIC – Sidecar Offload ● Ultimate goal ○ Proxyless services (for high performance) ● Offload ○ Traffic management ○ Security (Remote Direct Memory Access) ● Advance transport protocol (same layer as TCP and UDP) ● Main features ○ Remote memory r/w semantics in addition to send/receive ○ Kernel bypass / direct user space0 码力 | 50 页 | 2.19 MB | 1 年前3Istio Security Assessment
risk configurations commonly used by administrators, and provide perspective on whether security features sufficiently address the concerns they are designed to provide. Four consultants over a period of is not recommended in this case but a similar approach could be build a self- hosted checklist of features and configuration options that Istio believes match security best practices. See Appendix B on page are debug interfaces exposed that cannot be disabled by Istio, so that even when all the security features are enabled, there does not appear to be a way to restrict a Pod’s access to them. Attempts to modify0 码力 | 51 页 | 849.66 KB | 1 年前3Istio is a long wild river: how to navigate it safely
End of 2021 100% services migrated to Istio 8 Features currently used: ● HTTP/2 Load-balancing ● Traffic Shifting ● mTLS Features under investigation: ● Retries ● Circuit breaking Istio Istio Main time consumers with Istio: 1. Troubleshooting 2. Spreading adoption 3. Supporting new features 29 To succeed in Istio adoption you need to have: Stabilizing Istio ● Dedicated resources for temptations from users to open features too early ● Mechanisms to improve the reliability of Istio 30 Choose your fights, start small Stabilizing Istio Start with few simple features such as: ● Injecting0 码力 | 69 页 | 1.58 MB | 1 年前3Performance tuning and best practices in a Knative based, large-scale serverless platform with Istio
optimization during Knative Service provisioning ○ Unleash maximum scalability by fully leveraging Istio features in Knative with service mesh enabled ● Reference Agenda #IstioCon Knative and Istio Istio high configuration churn 30s #IstioCon Unleash maximum scalability by fully leveraging Istio features in Knative with service mesh enabled • Enable Istio mesh on Knative – Data flow with Istio mesh/mTLS seconds for Knative application pod cold start. Unleash maximum scalability by fully leveraging Istio features in Knative with service mesh enabled • Enable Istio mesh on Knative – Impact without optimization0 码力 | 23 页 | 2.51 MB | 1 年前3Istio audit report - ADA Logics - 2023-01-30 - v1.0
users easy access to features such as observability, traffic management and security without requiring users to add these to their application code. It also offers more advanced features to support A/B testing Security Components One of the advantages of using Istio is that it offers a series of security features related to identity, policies, TLS encryption, authentication, authorization and internal auditing the proxies and checks whether the policy of each proxy is up to date. Authentication has two core features in Istio: 1. Peer authentication: used for service-to-service authentication to verify the client0 码力 | 55 页 | 703.94 KB | 1 年前3Istio as an API Gateway
An API Gateway Discussion Flow ● What is an API Gateway? ● What is a Service Mesh? ● Common Features ● API Gateway + Service Mesh together! ● Istio as the API Gateway ● Advantages ● Challenges ● Where It Isn’t a Good Fit? What is an API Gateway? What is a Service Mesh? Common Features Common Features ● Load Balancing ● Request Routing ● Service Discovery ● JWT Authentication ● Traffic0 码力 | 27 页 | 1.11 MB | 1 年前3Set Sail for a Ship-Shape Istio Release
appropriate documentation, testing, and code completion is done for each level ● Making sure that features continue to mature #IstioCon Release Maturity ● Provide a consistent list of requirements for announcements ● What to look for when examining releases ○ Performance ○ Resource usage ○ Open issues ○ Features being promoted ○ Release notes and upgrade notes #IstioCon Continuous Release Health ● New dashboard to allow visibility of release health ● Open issues and priorities ● Issues being promoted ● Features awaiting documentation ● Weekly performance ● Open release blockers #IstioCon Thanks also to0 码力 | 18 页 | 199.43 KB | 1 年前3How HP set up secure and wise platform with Istio
of projects, deployed on cloud. They have common features, also have project specified feature. We provide a common platform includes all common features, connect all projects with istio. #IstioCon Common0 码力 | 23 页 | 1.18 MB | 1 年前3Apache Kafka with Istio on K8s
for workloads in a uniform way • Envoy WASM filters opens the gates for a whole array of useful features such as Kafka protocol level metrics, extended client throttling, audit logs to name a few Takeaway0 码力 | 14 页 | 875.99 KB | 1 年前3
共 17 条
- 1
- 2