Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Investigation/design for network traffic restrictions in ambient mode #1028

Open
Tracked by #681
mjnagel opened this issue Nov 20, 2024 · 0 comments
Open
Tracked by #681

Investigation/design for network traffic restrictions in ambient mode #1028

mjnagel opened this issue Nov 20, 2024 · 0 comments
Assignees
Labels
design-doc issue is for or requires a design doc istio Issues related to istio components / resources

Comments

@mjnagel
Copy link
Contributor

mjnagel commented Nov 20, 2024

Related to #681

During initial investigations of istio ambient we discovered that traffic appears to primarily/exclusively flow through the ztunnel port. This seems to make some of our network policies not have an effect. We should ensure that we are able to provide the same restrictions around ingress/egress and make a design for how to do this with ambient.

Definition of done should be a design doc/proposal that ensures traffic lock down, considering these items in particular:

  • Support for hybrid mesh (sidecar and ambient)
  • Usage of Istio AuthorizationPolicies?
  • Easy Migration/Upgrade Process
@mjnagel mjnagel added istio Issues related to istio components / resources design-doc issue is for or requires a design doc labels Jan 16, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
design-doc issue is for or requires a design doc istio Issues related to istio components / resources
Projects
None yet
Development

No branches or pull requests

3 participants