Session

Speak Egress and Exit: A Look at Securing Traffic Out of the Mesh with Istio

Your service mesh is up and running, but now your request must venture securely beyond the mesh!

On top of defining multiple CRs (ServiceEntries, Gateways, VirtualServices, DestinationRules, oh my!), you’ll need to consider the routing and security configurations for egress traffic that Istio supports: sidecar TLS origination, egress gateway TLS origination, TLS passthrough, ExternalName Services, and more!

Though Istio can send traffic to an external IP address, hostname, or internal DNS entry directly, this doesn’t limit which services can access external endpoints. Egress gateways enforce policies across an organization and provide a centralized point for monitoring, controlling, and shaping outbound traffic.

In a live demo, we’ll build up Istio configuration piece by piece for setups simple to complex and peek behind the scenes at the underlying Envoy configuration. Together we’ll deliver a request out of the cozy, hobbit hole mesh and into the fiery chasm of the outside world.

Nina Polshakova

Member of Technical Staff

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top