neuvector update to 2.6.3-bb.13
Package Merge Request
Package Changes
https://repo1.dso.mil/big-bang/product/packages/neuvector/-/blob/2.6.3-bb.13/CHANGELOG.md
Package MR
big-bang/product/packages/neuvector!82 (merged)
For Issue
Closes big-bang/product/packages/neuvector#82 (closed)
Upgrade Notices
A Sidecar resource has been added to the Neuvector namespace that disallows egress to endpoints that are not part of the Istio service registry (a.k.a REGISTRY_ONLY
). The outboundTrafficPolicy.mode in the Sidecar can be configured, however, to be something other than REGISTRY_ONLY
if desired by setting istio.hardened.outboundTrafficPolicyMode
. This provides a redundant layer of network security in addition to NetworkPolicies. This Sidecar is disabled by default but can be enabled by setting istio.enabled: true
and istio.hardened.enabled: true
.
Additionally, custom ServiceEntries can be created by populating the istio.hardened.customServiceEntries
list.