mirror of https://github.com/istio/istio.io.git
Revise the health check faq (#2191)
* Revise the health check faq * Fix format * Fix format
This commit is contained in:
parent
a2901ddd2c
commit
481e58c41d
|
|
@ -2,11 +2,23 @@
|
||||||
title: How can I use Kubernetes liveness and readiness for service health check when mutual TLS is enabled?
|
title: How can I use Kubernetes liveness and readiness for service health check when mutual TLS is enabled?
|
||||||
weight: 50
|
weight: 50
|
||||||
---
|
---
|
||||||
If mutual TLS is enabled, http and tcp health checks from the kubelet will not
|
If mutual TLS is enabled, http and tcp health checks from the kubelet will
|
||||||
work since the kubelet does not have Istio-issued certificates. A workaround is to
|
not work since the kubelet does not have Istio-issued certificates.
|
||||||
use a [liveness command](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#define-a-liveness-command)
|
|
||||||
for health checks, e.g., one can install `curl` in the service pod and `curl` itself
|
As of the Istio 1.0 release, we support the [`PERMISSIVE` mode](/docs/tasks/security/mtls-migration)
|
||||||
within the pod.
|
for Istio services so they can accept both http and mutual TLS traffic
|
||||||
|
when this mode is turned on. This can solve the health checking issue.
|
||||||
|
Please keep in mind that mutual TLS is not enforced since others can
|
||||||
|
communicate with the service with http traffic.
|
||||||
|
|
||||||
|
You can use a separate port for health check and enable mutual TLS only
|
||||||
|
on the regular service port. Refer to [Health checking of Istio
|
||||||
|
services](/docs/tasks/traffic-management/app-health-check/)
|
||||||
|
for more information.
|
||||||
|
|
||||||
|
Another workaround is to use a [liveness command](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#define-a-liveness-command)
|
||||||
|
for health checks, e.g., one can install `curl` in the service pod and
|
||||||
|
`curl` itself within the pod.
|
||||||
|
|
||||||
An example of a readiness probe:
|
An example of a readiness probe:
|
||||||
|
|
||||||
|
|
@ -20,8 +32,3 @@ exec:
|
||||||
initialDelaySeconds: 10
|
initialDelaySeconds: 10
|
||||||
periodSeconds: 5
|
periodSeconds: 5
|
||||||
{{< /text >}}
|
{{< /text >}}
|
||||||
|
|
||||||
If you do not want to modify the configuration file, you can enable the `PERMISSIVE`
|
|
||||||
mode for your services such they can accept both http and mutual TLS traffic. As
|
|
||||||
a result, the health check will not break. Refer to [Health checking of Istio
|
|
||||||
services](/docs/tasks/traffic-management/app-health-check/) for more information.
|
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue