-
Notifications
You must be signed in to change notification settings - Fork 405
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Enable mTLS in the service-mesh #3320
Comments
There is a problem with nats-streaming when it has sidecar injected and event-bus-publish/subscribe pods have sidecar as well. When the client tries to connect sing nats protocol it has i/o timeout. Istio does not support nats protocol, however, nats documentation mentions it's a plain text format.
I'm still investigating. |
Description
Enable mTLS globally (mesh-wide) and if necessary support component owners with creating rules disabling mTLS for their component. If disabling is required then it has to be first double checked that it really need plain text communication + mentioned here.
To enable mTLS in eventing enable sidecar in
natss-streaming
first.Remember to update our documentation for istio installation as well.
Reasons
Containers that run on a Kyma cluster communicate with each other over plain network connections. Channel security is generally not being enforced.
While containers are deployed with an istio envoy sidecar, istio mTLS is not enabled.
Attachments
The text was updated successfully, but these errors were encountered: