UNCLASSIFIED - NO CUI

Skip to content
Snippets Groups Projects

Adding sidecar, serviceEntry to whitelist egress

Merged Chris Harden requested to merge registry-only-sidecar-neuvector-II into main

General MR

Summary

This MR introduces a Sidecar and a set of ServiceEntries for Neuvector when istio.enabled: true and istio.hardened.enabled: true. This is in support of big-bang&160.

Relevant logs/screenshots

(Include any relevant logs/screenshots)

Linked Issue

issue

Upgrade Notices

A Sidecar resource has been added to the Tempo namespace that disallows egress to endpoints that are not part of the Istio service registry (a.k.a REGISTRY_ONLY). The outboundTrafficPolicy.mode in the Sidecar can be configured, however, to be something other than REGISTRY_ONLY if desired by setting istio.hardened.outboundTrafficPolicyMode. This provides a redundant layer of network security in addition to NetworkPolicies. This Sidecar is disabled by default but can be enabled by setting istio.enabled: true and istio.hardened.enabled: true.

Additionally, custom ServiceEntries can be created by populating the istio.hardened.customServiceEntries list.

Merge request reports

Loading
Loading

Activity

Filter activity
  • Approvals
  • Assignees & reviewers
  • Comments (from bots)
  • Comments (from users)
  • Commits & branches
  • Edits
  • Labels
  • Lock status
  • Mentions
  • Merge request status
  • Tracking
  • Chris Harden resolved all threads

    resolved all threads

  • Tim Seagren
  • Chris Harden resolved all threads

    resolved all threads

  • Chris Harden added 10 commits

    added 10 commits

    Compare with previous version

  • Chris Harden resolved all threads

    resolved all threads

  • Tim Seagren approved this merge request

    approved this merge request

  • Chris Harden added 1 commit

    added 1 commit

    • 5695ca5d - Updating IstioHardened.md to include exportTo: example

    Compare with previous version

  • Chris Harden reset approvals from @seagren.tim by pushing to the branch

    reset approvals from @seagren.tim by pushing to the branch

  • Chris Harden marked this merge request as draft

    marked this merge request as draft

  • Chris Harden added statusdoing label and removed statusreview label

    added statusdoing label and removed statusreview label

  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Please register or sign in to reply
    Loading