Block a user
troubleshooting
pilot-agent
add return_headers page to the image
Separate all the resources in their own file (grouped by type, sperated if reasonable)
replace ServiceEntry calls URL for sern page
Authentication, JWT.
It's interesting how it's implemented.
https://istio.io/latest/docs/tasks/security/authentication/authn-policy/#end-user-authentication
As per the moment will set priority to other tasks…
Authz ingress.
Yep currently in my environment I don't have access to such feature as the information seems to not be reaching the Istio proxy.
As mentioned in the Github issue from above, I might need to…
Authz ingress.
https://github.com/canonical/microk8s/issues/1538
Other resources from the infrastructure might require configuration in order to allow for this behavior.
AuthorizationPolicy disable mTLS
PeerAuthentication target ports through
portLevelMtls