It’s time to get excited for #IstioDay! We’re kicking off tomorrow Nov.12 at 1:25 PM: https://t.co/tfNG18vXKe. Come check out THE #KubeCon co-located event for Istio maintainers and practitioners to learn from each other!! Hope to see you there 😄
https://t.co/4OvTYblDR0 Ambient mode — the next-generation architecture for Istio — more than just an incremental improvement to the sidecar-based architecture. #ambientmode#istio#kubecon#multicloud
"Istio was able to deliver 56% more queries at 20% lower tail latency [than Cilium]. Taking into account the resources used, Istio processed 2178 queries per core, vs Cilium’s 1815, a 20% improvement."
https://t.co/wqhh3F4V6f
Istio v1.22 is one of the largest and most impactful releases we’ve ever launched.
Today, we bring ambient mode to Beta, the classic APIs to v1, and Gateway API support to Stable, as well as many performance improvements.
https://t.co/ohuIAwirRs
Istio ambient is often seen as just "service mesh without sidecars". It is that, but it also solves a ton of pain points in Istio.
One of many things you won't need to worry about: securing all Prometheus scraping: https://t.co/fbLlH98ZeZ.
With ambient, it just works.
An invalid benchmark quoted in haste can be repented at leisure
https://t.co/zyiEFmkKZt
tldr;
- L3 != L4 != L7
- Envoy performance is consistent
- @IstioMesh#Ambient is faster for HTTP
"Kuma turned out to be 1.8 times faster than Istio in AWS, and 2.4 times faster in Equinix Metal for cross-cluster connectivity scenarios."
While I consider NSM an entirely different product than @KumaMesh, the fact that Kuma is much more performant than @IstioMesh doesn't surprise me not even a little bit.
https://t.co/ym6IADDv5D
@mattfarina@lorenc_dan@cra@adamhjk@shanecurcuru@jspaleta@tsaha@TheASF@rhatr Since the 'perception of diversity' confers a commercial benefit vendors are motivated to manufacture it. Users are assuming the CNCF processes given them some assurance that manufactured diversity is not happening but expectations and reality are not aligned here.
Using SPIFFE/SPIRE? Some systems like @IstioMesh have established conventions about how to encode identity with SPIFFE IDs, but you may be wondering how best to construct SPIFFE IDs… this is a GREAT blog from @QuintessenceAnx @spirl_inc https://t.co/vKImlVYSud
It's my first #AWSReinvent and this thing is ungodly huge. If anyone wants to talk @IstioMesh you know where to find me and you can get your steps in on the way.
Teal Tuesday! Drop by Booth 375 for a live demo, a chance to win some swag, and an opportunity to meet https://t.co/ABGAWVyUdd company and product leadership! #AWSreInvent
Guess what - Istio 1.20 is out!
We're fully conformant with the Gateway API v1.0 spec! Our pods start a full second quicker! We're better aligned with #Kubernetes ExternalName services! We're easier to install on OpenShift!
https://t.co/KHaUA3G7vD
Released last week, our article @thenewstack covering svc-to-svc authentication with JWTs "unravels your API Gateway" by forcing complicated logic back into your app code. https://t.co/0bglLPQRyD Seems to resonate with some folks who went down this path! @pjausovec@soloio_inc
@ibuildthecloud This idea has been bounced around a bit. I expect we'll get there but have to offer some upgrade path for current users hence current packaging