Istio at Scale: How eBay is building a massive Multitenant Service Mesh using Istio& thousands of Pods with sidecar Envoys ○ Measure Config convergence time ■ Time taken by all sidecars to get config from Pilot without any errors ■ For thousands of services & endpoints ■ With different ○ Disabled egress traffic to restrict config pushed to sidecars ● Main Takeaways ○ P99.9 time from single Pilot instance to 0 - 3,000 sidecars < 1 second ○ Pilot CPU & memory within acceptable limits:0 码力 | 22 页 | 505.96 KB | 1 年前3
Service mesh security best practices: from implementation to verification is natively encrypted, such as HTTPS 3. use k8s network policies to limit traffic bypassing sidecars Cluster security best practices: safely handle policy exceptions Cluster security Access control0 码力 | 29 页 | 1.77 MB | 1 年前3
Performance tuning and best practices in a Knative based, large-scale serverless platform with Istioservice access cross user namespace. o The sidecar CR helps to limit the known egress hosts for sidecars, sidecar needs to knows mesh in his own user namespace only. o We can limit the mesh size to0 码力 | 23 页 | 2.51 MB | 1 年前3
共 3 条
- 1













