kubectl version
istioctl version
Configure Istio VirtualService, DestinationRule for traffic splitting, retry policies, and mTLS between services.
1 # Canary release: 90% v1, 10% v2 2 apiVersion: networking.istio.io/v1beta1 3 kind: VirtualService 4 metadata: 5 name: myapp-vs 6 namespace: production 7 spec: 8 hosts: 9 - myapp 10 http: 11 - name: primary 12 match: 13 - headers: 14 x-canary: 15 exact: "true" 16 route: 17 - destination: 18 host: myapp 19 subset: v2 20 weight: 100 21 22 - name: default 23 route: 24 - destination: 25 host: myapp 26 subset: v1 27 weight: 90 28 - destination: 29 host: myapp 30 subset: v2 31 weight: 10 32 timeout: 5s 33 retries: 34 attempts: 3 35 perTryTimeout: 2s 36 retryOn: 5xx,reset,connect-failure 37 --- 38 apiVersion: networking.istio.io/v1beta1 39 kind: DestinationRule 40 metadata: 41 name: myapp-dr 42 namespace: production 43 spec: 44 host: myapp 45 trafficPolicy: 46 connectionPool: 47 tcp: 48 maxConnections: 100 49 http: 50 http1MaxPendingRequests: 100 51 http2MaxRequests: 1000 52 outlierDetection: 53 consecutive5xxErrors: 5 54 interval: 10s 55 baseEjectionTime: 30s 56 maxEjectionPercent: 50 57 subsets: 58 - name: v1 59 labels: 60 version: v1 61 - name: v2 62 labels: 63 version: v2 64 --- 65 # Enforce mTLS 66 apiVersion: security.istio.io/v1beta1 67 kind: PeerAuthentication 68 metadata: 69 name: strict-mtls 70 namespace: production 71 spec: 72 mtls: 73 mode: STRICT 74
Sign in to share your feedback and join the discussion.