UNCLASSIFIED - NO CUI

Skip to content
Snippets Groups Projects

Adding sidecar, serviceEntry to whitelist egress

Merged Chris Harden requested to merge registry-only-sidecar-twistlock into main

General MR

Summary

This MR introduces a Sidecar and a set of ServiceEntries for Neuvector when istio.enabled: true and istio.hardened.enabled: true. This is in support of big-bang&160.

Relevant logs/screenshots

(Include any relevant logs/screenshots)

Linked Issue

For issue

Upgrade Notices

A Sidecar resource has been added to the Twistlock namespace that disallows egress to endpoints that are not part of the Istio service registry (a.k.a REGISTRY_ONLY). The outboundTrafficPolicy.mode in the Sidecar can be configured, however, to be something other than REGISTRY_ONLY if desired by setting istio.hardened.outboundTrafficPolicyMode. This provides a redundant layer of network security in addition to NetworkPolicies. This Sidecar is disabled by default but can be enabled by setting istio.enabled: true and istio.hardened.enabled: true.

Additionally, custom ServiceEntries can be created by populating the istio.hardened.customServiceEntries list.

Edited by Michael Martin

Merge request reports

Loading
Loading

Activity

Filter activity
  • Approvals
  • Assignees & reviewers
  • Comments (from bots)
  • Comments (from users)
  • Commits & branches
  • Edits
  • Labels
  • Lock status
  • Mentions
  • Merge request status
  • Tracking
  • Tim Seagren added 1 commit

    added 1 commit

    • dc70ab45 - remove istio fields from test values

    Compare with previous version

  • Chris Harden resolved all threads

    resolved all threads

  • Chris Harden added 1 commit

    added 1 commit

    • 44838f03 - Fix label to hardcoded twistlock

    Compare with previous version

  • Chris Harden resolved all threads

    resolved all threads

  • Chris Harden added 2 commits

    added 2 commits

    Compare with previous version

  • Chris Harden added 1 commit

    added 1 commit

    • 4ab456c5 - Updating sidecar.yaml to use _helper to populate label

    Compare with previous version

  • @charden the MR has a few conflicts we should resolve before approving.

  • Chris Harden added 1 commit

    added 1 commit

    • 1530767d - Updating IstioHardened.md to include exportTo: example

    Compare with previous version

  • Chris Harden added 3 commits

    added 3 commits

    Compare with previous version

  • Chris Harden marked this merge request as draft

    marked this merge request as draft

  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Please register or sign in to reply
    Loading