Category "istio"

What's the retry configuration for a ServiceEntry using https?

I'm trying to setup a Service Entry to add an external API to our mesh and take advantage of some network resilience features. First, I'd like to add retries to

Istio Envoy Filter BOOTSTRAP EXTENSION is not executing the WASM

istio/proxyv2:1.12.2 I'm trying to add a WASM file to the EnvoyFilter patching under the bootstrap_extensions. The Envoyfilter successfully is pushed but I coul

Won't Istio rules not impact intra cluster communication?

After I inject network delay of, say 5s, using add_delay_fault function, the delay is nicely effected for all traffic coming in via the Istio ingress gateway LB

Multiple Istio Request Authentication Policies

According to the Istio security doc: "Request authentication policies can specify more than one JWT if each uses a unique location. When more than one policy ma

Istio - Gunicorn - Python getting 503 upstream connect error or disconnect/reset before headers. reset reason: connection failure

I am running a Istio setup where my python flask service running behind gunicorn. when debugging the logs from the service, the flask service successfully execu

Istio WorkloadEntry sidecar a requirements?

I'm interested in putting a vendor provided application running in an AWS EC2 Instance behind my Istio gateway. It sounds like the ideal scenario is to use a Wo

How to expose kafka using istio ingress?

I use istio-ingress gateway and virtualservice to expose different microservices. So far all of them have been http services, so it was straight-forward to foll

Unable to setup development environment for Kiali

I want to setup developer environment for Kiali-ui. I am following Kiali guide to do this. But while accessing Kiali on browser(http://localhost:3000) i am gett

Add Custom Header to HTTP request in Load Balancer

I have an containerized application/service deployed in openshift container platform with istio service mesh. In istio virtual service yaml, i wanted to validat

fail to run istio-ingressgateway, got Readiness probe failed: connection refused

I fail to deploy istio and met this problem. When I tried to deploy istio using istioctl install --set profile=default -y. The output is like: ➜ istio-1

The external IP of istio ingress gateway stay pending

I deployed a istio to k8s and it works well at first, but after one day, I can't access the app via ingress gateway. Then checked the istio svc status. It shows

Istio traffic routing rules take no effect

I am trying to configure a request routing using Istio and Ingress-nginx but I'm not able to route the requests properly. Basically I have two deployments each

Terminate istio sidecar istio-proxy for a kubernetes job / cronjob

We recently started using istio Istio to establish a service-mesh within out Kubernetes landscape. We now have the problem that jobs and cronjobs do not termin

Suddenly getting "Unable to connect to the server: net/http: TLS handshake timeout" from kubectl

My vanilla kubernetes cluster running on 'Docker for Mac' was running fine without any real load. Now, I deployed a few services and istio. Now, I am getting th

Istio Virtual service dark launch (deployment) Header exact not working

Currently i have an architecture where my API Gateway (http) is exposed to users and i have many internal services (gRPC) running. So the user request propagate

Istio vs Service Mesh Interface

I would have a conceptual question. I can not figure it out how Istio and Service Mesh Interface come together. Service Mesh Interface' goal is to have a standa

Locality LoadBalacing not working on Istio

We have a kubernetes cluster with ~100 nodes with istio and want to enable the Locality LoadBalancing feature. This will save us up to 70k USD/year because our

Istio + minikube + Nginx (React). Cannot get access from browser nor CURL

When I deploy without ingress-gateway I can get access via port-forwarding directly to LoadBalancer of application in the browser. But through ingress-gateway i

How to configure istio for mesh federation without service discovery?

Multi-trust deployment model from istio documentation I want to connect multiple meshes together. I currently manage 3 different AKS clusters Operations (aks-o