Istio Security Assessment
"${NAMESPACE}-access", "namespace": "$NAMESPACE" }, "rules": [{ "apiGroups": [ "", "extensions", "apps", "networking.k8s.io", "networking.istio.io", "authentication.istio.io", "rbac.istio.io", "config kind: ServiceAccount metadata: name: sleep-restrict namespace: jtd-restrict-test --- apiVersion: apps/v1 kind: Deployment metadata: name: sleep-restrict spec: replicas: 1 selector: matchLabels: app: verbs: - '*' - apiGroups: 44 | Google Istio Security Assessment Google / NCC Group Confidential - apps - extensions resources: - daemonsets - deployments - deployments/finalizers - ingresses - replicasets0 码力 | 51 页 | 849.66 KB | 1 年前3Leveraging Istio for Creating API Tests - Low Effort API Testing for Microservices
External APIs Istio enables learning tests from API usage Learnt by Mesh API Studio Third-party apps Manual QA trace: r trace: r trace: r trace: r CI Pipeline | CONFIDENTIAL 9 Process flow External APIs Creating test suites from API traffic Created by Mesh API Studio Third-party apps Manual QA trace: r trace: r trace: r trace: r CI Pipeline | CONFIDENTIAL 16 ML-assisted0 码力 | 21 页 | 1.09 MB | 1 年前3Apache Kafka with Istio on K8s
• Kubernetes service account based authn/authz • Secure cross-cluster interaction between client apps and Kafka Security goals 4 • Kafka brokers require private-key and certificate pairs • Private0 码力 | 14 页 | 875.99 KB | 1 年前3IstioCon 2022 Report
attendance Workshop Istio 0 to 60 Workshop Hands-on practices for Controlling Kubernetes Native Apps with Service Mesh Manage and Secure Distributed Services with Anthos Service Mesh Multi-tenant0 码力 | 20 页 | 2.44 MB | 1 年前3宋净超 从开源 Istio 到企业级服务:如何在企业中落地服务网格
Kubernetes cluster ● VM integration ● On-prem, AWS, Azure, GCP, OpenShift ● 10000+ core business apps ● Plan to move to public cloud in 18 months ● Using F5 to distribute traffic at the DMZ zone Solving0 码力 | 30 页 | 4.79 MB | 5 月前3Istio at Scale: How eBay is building a massive Multitenant Service Mesh using Istio
Specs ○ Leverage Istio object model: Gateway, VirtualService, DestinationRules, etc. apiVersion: apps.cloud.io/v1 kind: AccessPoint metadata: name: my-accesspoint spec: accessPoints: - name: web-tier0 码力 | 22 页 | 505.96 KB | 1 年前3
共 6 条
- 1