强制 mTLS(命名空间内指定工作负载):apiVersion: security.istio.io/v1beta1
kind: PeerAuthentication
metadata:
name: api-mtls-strict
namespace: default
spec:
selector:
matchLabels:
app: api
mtls:
mode: STRICT
客户端侧 TLS(DestinationRule):apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
name: api-dr
namespace: default
spec:
host: api.default.svc.cluster.local
trafficPolicy:
tls:
mode: ISTIO_MUTUAL

发表评论 取消回复