dongyun4010 2019-08-15 14:22
浏览 197

多集群之间的istio流量管理

I have several Kubernetes clusters. Due to the company's security issues, only A 'service in Cluster A should be allowed to access B' Service in Cluster B. Can you handle such a case with istio?

Although it is possible to control the traffic using the header information in istio's virtualservice, the http header information can be manipulated at any time, which does not satisfy the security issue.

  • 写回答

1条回答 默认 最新

  • drll85318 2019-08-15 14:35
    关注

    Istio has a different federation with a single control plane or multiple control plane. you can check out below. the communication across network supported by MTLS so you can be assured it can't have tampered.

    Shared control plane
    https://istio.io/docs/setup/kubernetes/install/multicluster/shared-gateways/

    Multiple control planes
    https://istio.io/docs/setup/kubernetes/install/multicluster/gateways/

    This is pretty new and under heavy development, so you can try them or simply use HTTPS communication when connecting across the network.

    评论

报告相同问题?

悬赏问题

  • ¥50 comsol稳态求解器 找不到解,奇异矩阵有1个空方程返回的解不收敛。没有返回所有参数步长;pid控制
  • ¥15 怎么让wx群机器人发送音乐
  • ¥15 fesafe材料库问题
  • ¥35 beats蓝牙耳机怎么查看日志
  • ¥15 Fluent齿轮搅油
  • ¥15 八爪鱼爬数据为什么自己停了
  • ¥15 交替优化波束形成和ris反射角使保密速率最大化
  • ¥15 树莓派与pix飞控通信
  • ¥15 自动转发微信群信息到另外一个微信群
  • ¥15 outlook无法配置成功