Istio Security Assessment
user confined to a "rest rict-test" namespace per the Istio cluster setup guide2 2. Obtain the output of the following command (run with administrative access) and use it below in place of $GATEWAY takes a string of bytes and returns a small, fixed-size value. Hash functions guarantee that the same input always results in the same output. When used for security, the most important property of a hash function the difference between the legitimate and malicious files based on the hash. The following hash functions are not considered cryptographically secure and should not be used: • All MD-family hashes (such0 码力 | 51 页 | 849.66 KB | 1 年前3Accelerate Istio with ebpf
ebpf Background Knowledge Prog type ● SOCK_OPS ➢ Set callbacks for TCP state changing ➢ Help functions: BPF_MAP_UPDATE_ELEM, BPF_SOCK_HASH_UPDATE ● SK_MSG ➢ Attach to a SOCKHASH map, capture the packets packets sent by a socket in SOCKHASH map and determine its destination socket ➢ Help functions: BPF_MSG_REDIRECT_HASH Istio Meetup China Work Flow of Acceleration ● sock_ops o Capture socket in specific0 码力 | 15 页 | 591.60 KB | 1 年前3Istio at Scale: How eBay is building a massive Multitenant Service Mesh using Istio
implement common Security, Observability, Service Routing & Discovery functions as features of the infrastructure - ○ Functions: TLS Termination, Traffic Management, Tracing, Rate Limiting, Protocol0 码力 | 22 页 | 505.96 KB | 1 年前3Envoy原理介绍及线上问题踩坑
prerouting input output postrouting Istio_inbound Istio_in_redirect Istio_output Istio_redirect iptables app1 envoy 15001 SO_ORIG INAL_DS T 路 由 prerouting input output postrouting Istio_inbound Istio_inbound Istio_in_redirect Istio_output Istio_redirect iptables 上 游 连 接 池 prerouting input output postrouting Istio_inbound Istio_in_redirect Istio_output Istio_redirect iptables envoy 15006 15006 prerouting input output postrouting Istio_inbound Istio_in_redirect Istio_output Istio_redirect iptables SO_ORIG INAL_DS T 路 由 上 游 连 接 池 12.localhost app2 15.lo 1 2 3.非本 POD、 非 Envoy0 码力 | 30 页 | 2.67 MB | 1 年前3Observability and Istio Telemetry
com/apache/incubator-skywalking/blob/master/docs/en/ concepts-and-designs/oal.md • Extendable Aggregation Functions • Aggregation Function • Count • Calls per minute • Avg response time • Sum • Thermodynamic0 码力 | 21 页 | 5.29 MB | 5 月前3Kubernetes容器应用基于Istio的灰度发布实践
builds on Kubernetes and Istio to support deploying and serving of serverless applications and functions. http://www.servicemesher.com0 码力 | 38 页 | 14.93 MB | 1 年前3Is Your Virtual Machine Really Ready-to-go with Istio?
and shift ● Packaged software ○ Non-Linux ○ unikernels ● Domain specific workloads ○ Network Functions (NFV) #IstioCon Hybrid and Multi Clouds #IstioCon Istio VM Integration is? A Tumultuous Odyssey…0 码力 | 50 页 | 2.19 MB | 1 年前3Istio audit report - ADA Logics - 2023-01-30 - v1.0
communicates with Istiod to automate key and certificate rotation, like so: Istio-agent has two functions: 1. To receive SDS requests from Envoy and send certificate signing requests to the CA which typically0 码力 | 55 页 | 703.94 KB | 1 年前3Preserve Original Source Address within Istio
0xffffffff -- ctmask 0xffffffff # mark connection 1337 according to packet sent to application -A OUTPUT -p tcp -m connmark --mark 0x539 -j CONNMARK --restore-mark --nfmask 0xffffffff -- ctmask 0xffffffff0 码力 | 29 页 | 713.08 KB | 1 年前3
共 9 条
- 1