Istio CNI

Istio CNI plugin is the container network interface (CNI) add-on that lets Istio capture and secure service-mesh traffic for your workloads without…

  • Tools & Utilities
Istio CNI plugin is the container network interface (CNI) add-on that lets Istio capture and secure service-mesh traffic for your workloads without reconfiguring each pod's network namespace. It's for Istio operators on Kubernetes who want CNI-based sidecar handling instead of the default iptables approach. Note: the original istio/cni repository is archived and the plugin has been merged into the main Istio project, so pull current install manifests there.

Platform availability

Available on 0 of 6 install platforms

  • Unraid (not listed)
  • TrueNAS (not listed)
  • Umbrel (not listed)
  • ZimaOS (not listed)
  • Proxmox (not listed)
  • Helm (not listed)

Also on Docker Hub and GitHub

Health score

19/100 Low

Maintained
0GitHub repository is archived
Popular
43139 GitHub stars
Easy to install
250 install platforms, install notes, Docker image
Light to run
No data

Based on 3 of 4 factors.

How is this calculated?

A 0-100 score computed nightly from four factors: maintained (40%: recent commits and steady activity), popular (25%: GitHub stars, log scale), easy to install (20%: platforms, install notes, setup guides, Docker image) and light to run (15%: minimum RAM, ARM support). Factors without data are left out and the rest are rescaled.

GitHub stars
139
Open issues
2
Last commit
2020-06-16
License
Apache-2.0
Activity
stale

Checked 9 days ago - source: GitHub (istio/cni)

Resources & Compatibility

ARM (e.g. Raspberry Pi) is not supported.

Checked 10 days ago - source: Docker Hub image tags and published docs

First-install notes

  • Install the Istio control plane first Deploy istiod (Istio's control plane, the service that tells your apps what traffic rules to follow) into the Kubernetes namespace called istio-system before adding your applications. Without it, Istio has no central service to manage traffic or enforce rules. source
  • Deploy SPIRE before installing Istio If you are using SPIRE (a tool that gives services identity credentials), apply its quickstart components with kubectl before installing Istio. If you skip this step, Istio may not inject the SPIRE socket, so service identity won't work as expected. source
  • Add a sidecar when deploying apps When deploying a service, use istioctl kube-inject to add its sidecar (a helper proxy container that runs next to your app) before creating the pod (the group of containers Kubernetes runs for that app). Without the sidecar, the app won't route traffic through Istio, so traffic rules won't apply to it. source
  • Enable the CNI plugin in your Istio install Apply your Istio manifests with the CNI plugin turned on using the Helm flag --set istio_cni.enabled=true so it activates alongside the control plane. source
  • Enable the CNI plugin Enable the CNI plugin by creating and applying Istio manifests with the Helm variable --set istio_cni.enabled=true. source

Fetched 2 days ago - each note links to its source

Alternatives

No alternatives collected yet.

Common questions

How do I enable the Istio CNI plugin during an Istio install?

Set the Helm variable istio_cni.enabled=true when applying the Istio manifests, or apply istio-cni_install.yaml as a separate install.

Which kubelet CNI settings must the Istio CNI plugin match?

The cniBinDir and cniConfDir values must match the kubelet settings, with defaults of /opt/cni/bin and /etc/cni/net.d.

Why might Istio CNI not activate on a hosted Kubernetes cluster?

Some hosted clusters do not configure the kubelet to use CNI plugins, so compatibility is not universal. It is expected to work with hosted Kubernetes that uses CNI plugins.

How should the CNI plugin be configured for OpenShift?

Set the chained parameter to false because some Kubernetes flavors, such as OpenShift, do not support the CNI chain approach.

Answers sourced from github.com

Community

Collected 4 days ago - public community threads