rewrite the explanation of the shared control plane single network topology

remote "the single control plane"
This commit is contained in:
Vadim Eisenberg 2019-07-25 20:02:20 +03:00
parent 754b90ee5e
commit fb2d9f6b1a
1 changed files with 3 additions and 5 deletions

View File

@ -13,11 +13,9 @@ where the Kubernetes cluster services and the applications in each cluster
have the capability to expose their internal Kubernetes network to other
clusters.
In this configuration, multiple Kubernetes control planes running
a remote configuration connect to a **single** Istio control plane.
Once one or more remote Kubernetes clusters are connected to the
Istio control plane, Envoy can then communicate with the **single**
control plane and form a mesh network across multiple clusters.
In this configuration, one or several Istio control planes watch Kubernetes API servers in multiple remote clusters.
Envoys in clusters without Istio control plane communicate with Istio control planes deployed outside of their cluster
and form a single mesh across multiple clusters.
{{< image width="80%" link="./multicluster-with-vpn.svg" caption="Istio mesh spanning multiple Kubernetes clusters with direct network access to remote pods over VPN" >}}