Commit Graph

1603 Commits

Author SHA1 Message Date
Naoki Oketani 31d21ffbb4 migrate Deployment apiVersion from extensions/v1beta1 to apps/v1 to support k8s 1.16 (#5159)
* migrate Deployment apiVersion from extensions/v1beta1 to apps/v1 to support k8s 1.16

* migrate Deployment, PodSecurityPolicy apiVersion to support k8s 1.16
2019-10-15 10:56:21 -07:00
Martin Taillefer 612d10c921
Automatically a warning to older blog posts about them being potentially out of date. (#5134) 2019-10-15 10:02:20 -07:00
Steven Dake d5482da0aa A compromise PR of a long original work (#5146)
* A compromise PR of a long original work

See PR: https://github.com/istio/istio.io/pull/5142

Pretty much everything about this PR is compromised...

* Apply reviewer comments.
2019-10-15 09:55:20 -07:00
Martin Taillefer f7dd8c6613
Consolidate release-specific material into the news section. (#5138) 2019-10-15 09:27:11 -07:00
Vadim Eisenberg 2b9ecdf461 blog post: Istio as a proxy for external services (#3180)
* initial implementation

* add HTTP gateway for httpbin.org

* rewrite the introduction

* extend the exmample by blocking traffic from the mesh

* use www.google.com instead of *

* fix a typo in httpbin.org

* rename 'front proxy' to 'proxy', rewrite the first paragraph

* add a step for enabling Envoy's access logging

* Gateway -> ingress gateway, server -> servers, Note -> ensure

Co-Authored-By: vadimeisenbergibm <vadime@il.ibm.com>

* httpbin/google -> the httpbin/google services

Co-Authored-By: vadimeisenbergibm <vadime@il.ibm.com>

* Configure -> create, is used -> you will need it

Co-Authored-By: vadimeisenbergibm <vadime@il.ibm.com>

* expand the sentence why the reader will need the localhost service entry

* expand the sentence about configuring routing

* rewrite the sentence about accessing httpbin.org

* Check the logs of the gateway -> print the gateway's log

Co-Authored-By: vadimeisenbergibm <vadime@il.ibm.com>

* You should see a line -> search the log for an entry

Co-Authored-By: vadimeisenbergibm <vadime@il.ibm.com>

* Check the Mixer log -> print the Mixer log

Co-Authored-By: vadimeisenbergibm <vadime@il.ibm.com>

* You should see a line -> search the log for an entry

Co-Authored-By: vadimeisenbergibm <vadime@il.ibm.com>

* Access `www.google.com` through your ingress ->  Access the `www.google.com` service through your ingress gateway

Co-Authored-By: vadimeisenbergibm <vadime@il.ibm.com>

* Check the Mixer log -> print the Mixer log

Co-Authored-By: vadimeisenbergibm <vadime@il.ibm.com>

* You should see a line -> search the log for an entry

Co-Authored-By: vadimeisenbergibm <vadime@il.ibm.com>

* You should see a line -> search the log for an entry

Co-Authored-By: vadimeisenbergibm <vadime@il.ibm.com>

* Check the Mixer log -> print the Mixer log

Co-Authored-By: vadimeisenbergibm <vadime@il.ibm.com>

* fix indentation

* fix the first step

* split a long line

* expand about the mesh gateway

* remove leftovers from previous commits

* print the log with: -> print the log with the following command:

* remove printing Mixer log since in 1.1 it does not have to be enabled by default

* use TLS instead of HTTPS

to prevent confusion with the TLS termination cases

* front-proxy -> proxy

* fix the cleanup

* fix links

* use cnn instead of google

since the webpage of google is less clear to grep

* move to examples

* rewrite the example as a blog post

* example -> blog post
2019-10-15 08:41:21 -07:00
Naoki Oketani 01c8fe2a1b Update fault injection percentage syntax (#5139) 2019-10-15 07:31:22 -07:00
Vadim Eisenberg e392d7260a add a task about Kubernetes Services for egress (#4710)
* add the first version of Egress with Kubernetes Services

* add explicit disabling of TLS in destination rules

* rewrite the motivation for Kubernetes service entries

motivation: location transparency

* remove pre-Istio from .spelling

* add "The external services are not part of an Istio service mesh..."

so they cannot perform the mutual TLS of Istio.

* split a long line

* expand the explanations about disabling Istio's mutual TLS

* add explanation about disabling TLS mode in the HTTP case

* add explanation about disabling Istio mutual TLS for HTTPS case

* unencoded -> unencrypted

* fix a link

* fix the location of the task to be in content/en
2019-10-15 01:30:21 -07:00
Steven Dake fb486ce315 Document standalone operator as alpha (#5141) 2019-10-14 15:30:18 -07:00
David Ebbo 1f71199ebf Add doc page for 'istioctl analyze' (#5147)
* Add doc page for 'istioctl analyze'

* Address lint comments

* Fix spelling errors

* Use github_blob in link

* Changes based on PR feedback

* Fix lint issues

* More changes based on PR feedback

* Fix couple typos

* Remove one word

* Shorten title and use bulletted list
2019-10-14 15:23:19 -07:00
Jason Wang beddb17a9a update reference docs (#5148) 2019-10-14 13:01:58 -07:00
Brian Avery 955b93a7fa 1.3.3 release notes (#5122)
* 1.3.3 release notes

* 1.3.3 release notes

* Apply suggestions from code review

Co-Authored-By: Romain Lenglet <romain.lenglet@berabera.info>

* Added note regarding Envoy crash
2019-10-14 11:01:56 -07:00
Jesse Lumme 2028027493 Added references to glossary (#5143)
* Added reference link to Operator

* Added reference to Envoy

* Added reference to virtual service
2019-10-13 13:42:54 -07:00
Martin Taillefer 9aaf5e4cba
Update reference docs. (#5136) 2019-10-11 13:18:13 -07:00
Frank Budinsky c82861d10e Clarify relationship between pods and workloads (#5130)
* Clarify relationship between pods and workloads

* Update content/en/docs/reference/glossary/pod.md

Co-Authored-By: Martin Taillefer <geeknoid@users.noreply.github.com>
2019-10-11 12:55:21 -07:00
Ram Vennam 25d8f5c983 SCC policies are not specific to BookInfo (#5132)
* SCC policies are not specific to BookInfo

* Update index.md
2019-10-11 12:36:22 -07:00
LisaFC 38c6a004e5 Add missing word(s) (#5129)
Fixes #5089
2019-10-11 09:06:20 -07:00
Frank Budinsky 152a485e7d Istioctl describe entry for op guide (#5121)
* Istioctl describe op guide

* Fix lint

* spelling

* small corrections

* wording tweak
2019-10-11 07:56:21 -07:00
Istio Automation 1bd516b7fa
Remove incorrect warning (#5124)
cc @lambdai who pointed out this is not accurate
2019-10-10 15:46:20 -07:00
Naoki Oketani b68cb7540c Update subcommand for dashboard controlz (#5119) 2019-10-10 08:17:50 -07:00
Lin Sun 869ab9f17d fix link issue (#5115)
* fix link issue

* space

* use the link frank suggested

* Update content/en/news/2019/istio-security-2019-005/index.md
2019-10-09 12:10:39 -07:00
Lin Sun f556d09041 Fix lint in the announcement (#5106)
* fix lint

* add spelling

* temporary remove bad doc
2019-10-09 12:16:17 -04:00
Ed Snible dba3b6ffaa Task describing new experimental 'describe pod' sub-command (#4971)
* Task describing new experimental 'describe pod' sub-command

* Move document to troubleshooting and address comments

* Restructured so that commands and command responses are in the same text block

* Rewrite the `istioctl describe` task.

This rewrite fixes the style, tone, and language of the content. Additionally,
it adds links to relevant pages and glossary entries. Lastly, it adds and
improves the markup used.

Signed-off-by: rcaballeromx <grca@google.com>

* Add @frankbu's syntax correction for bash block
2019-10-09 11:41:23 -04:00
Rigs Caballero 4492b89b4f Ensure consistent use of 'multicluster'. (#5108) 2019-10-08 20:55:42 -07:00
Martin Taillefer 74559202aa
Update reference docs. (#5110) 2019-10-08 20:54:49 -07:00
Martin Taillefer 03469d0ad9
Fix casing of microk8s.io URL. (#5103) 2019-10-08 13:05:28 -07:00
Lin Sun 1ae8904e9f
release note and announcement for 1.3.2/1.1.16/1.2.7 (#5104)
* .spelling change

* announcement and notes

* add a msg about distroless
2019-10-08 14:01:04 -04:00
Martin Taillefer 9944d952ff
Add support for config analysis messages. (#5096)
- This provides the place where we can pour config analysis message
descriptions.
2019-10-08 10:30:41 -07:00
Ed Snible c072e65db6 Erroneous spelling of 'erroneous' (#5099) 2019-10-07 07:59:53 -07:00
Frank Budinsky 78ec428817 Improve concepts organization (#5095)
* cleanup unused files

* tweak wording

* merge traffic management architecture material

* reorg top level concept sections

* lint errors

* fix list style
2019-10-04 11:43:31 -07:00
Frank Budinsky 6535ab7103 Use same bookinfo version on both clusters of MC example (#5094)
* Use same bookinfo version on both clusters of MC example

* apply reviews serviceaccount
2019-10-03 07:53:29 -07:00
Frank Budinsky 910991317e Clarify protocol enablement (#5090)
* Clarify protocol enablement

* clarify name syntax

* fix bad link
2019-10-02 09:36:26 -07:00
John Howard cfef86521c Remove mention of Istio managed certmanager (#5092)
* Remove mention of Istio managed certmanager

* Fix lint

* Number list

* Fix indent

* Update content/en/docs/tasks/traffic-management/ingress/ingress-certmgr/index.md

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>
2019-10-02 09:26:25 -07:00
Vadim Eisenberg dbb23e1fdb Blog post about using Istio multi-mesh for isolation and boundary protection (#4776)
* initial version

* add structure and certificate generation

* remove redundant article

* create the reviews service and later delete it

required for pods to start

* kubernetes -> kubectl

* complete creating the egress gateway section

* add deployment of an ingress gateway

* use LoadBalancer type for the private ingress gateway

* expand the cleanup section

* add "Expose reviews v2" section

* use hostnames in CN so it can be verified by curl

* use a single slash in HTTPRewrite uri field

* fix the virtual service and the curl call

* add a troubleshooting section

* use port 80 in the egress gateway's deployment

* implement the consume section for reviews v2

* expand the troubleshooting section

* split a virtual service, use port 443

* unite two virtual services for reviews

* add namespace to the gateway reference

* complete the cleaning instructions

* fix prefix match and rewrite in consuming reviews v2

* rename the gateway, destination rule, rewrite authority in ingress cluster2

* split the virtual service in cluster1 into two parts

* set access log format to print both the path and the rewritten path

* extend the cleanup section

* add load balancing between the local and remote versions of reviews

* remove usi

* change consume/expose details to ratings

* add diagrams

* canary release the remote version

* fix the subtitle and the publish date

* add subset v1 to the routing to the local version

* use local name (reviews) for a virtual service in the default namespace

* add the 'Deploy reviews v2 locally and retire reviews v1' section

* a Gateway -> an ingress Gateway

* virtualservice myreviews-bookinfo-v2 -> virtualservice privately-exposed-services

* add the "Expose ratings and reviews v3" section

* add printing response code to curl commands

* add a step to delete the consumption of the remote service from `cluster2`

* add a section "Consume ratings and reviews v3"

* add a section about Istio RBAC

* rewrite certificate creation - add spiffe SAN

* add a section about RBAC on ingress gateway

* remove redundant quote

* add extended key usage and critical to subjectAltName

* add generation of certificate and key for cluster3

* rewrite ingress RBAC in cluster2 to use EnvoyFilter for RBAC

Istio RBAC currently does not support getting principal for
MUTUAL TLS, only for ISTIO_MUTUAL

* fix MeshFederation5, the local version of reviews must be v2

* fix a typo

* add the "Cancel exposure of ratings" section

* add checking Istio configuration artifacts

* rewrite the introduction, add requirements and the proposed implementation section

* to base implementation -> to base the implementation

* split a long line

* web page -> webpage

* fix indentation

* of deploying -> after deploying

* add an explanation about openssl

* extend the explanation about `cluster3`

* add an explanation about deploying gateways

* create the certificates -> create the certificates and keys

* remove "the" from "to generate the certificates and the keys"

* minor changes in gateway deployment

* mount volumes from secrets -> mount secrets as data volumes

* add explanation about private gateways

* cluster1 and cluster2 -> both clusters

* add an explanation about exposure/consumption

* add an explanation about c1,c2,c3.example.com hostnames

* real URL -> existing hostname

* port 80 -> port 443 (the egress gateway)

* remove the non-mTLS options

* VirtualService -> virtual service

* fix indentation

* remove back ticks from reviews v1 and v2

* in remote cluster -> is in remote cluster

* add explanation about expose-nothing behavior by default

* add a separating empty line

* port 80 -> port 443

* VirtualService -> virtual service, part 2

* your Kubernetes cluster -> your second cluster

* add "in case you have a load balancer"

* add "in case you have a load balancer... otherwise..."

* fix the pod of reviews-v2 in the first cluster

mention the new pod

* web page -> webpage

* cluster1 -> the first cluster

* make multiple tests a sublist

* rewrite the sentence "Let's change the RBAC policy"

remove let's
remote passive voice

* rewrite the series of the tests to check RBAC

* issues requests -> sends requests

* Let's consider -> consider

* split a long line

* add "locally" to has access to ratings

* the ratings -> ratings

* use first/second cluster instead of cluster1/cluster2 in headings

* add a subsection to remove certificate and key files

* extend the sentence about role binding

* extend the sentence about enabling Istio RBAC on bookinfo

* rewrite the sentence about accessing the webpage of the bookinfo app

* add an explanation about the EnvoyFilter

* other 50% -> the other 50%

* 50% of time -> 50% of the time

* at cluster -> in cluster

* rewrite the sentence about cleaning Istio RBAC

* add summary

* in the subtitle: traffic control -> strict access control

* for the many different reasons -> for different reasons

* special certificates -> dedicated certificates, add dots

* add a sentence about defense in depth and PCI compliance

* fix typos

* through their gateways -> through corresponding gateways

* _v1_ -> `v1`

* ad-hoc -> ad hoc

* put EnvoyFilter and the name of the Envoy's filter in backticks

* instructions for NodePort Ingress -> instructions for using node port for ingress

* add "hoc" to .spelling, for "ad hoc" expression

* fix a link

* remove unneeded single bullet

* fix a link for Defense-in-depth

* rewrite the list of reasons for split applications between multiple clusters

* add a clause about boundary protection

* expand on non-uniform naming

* rewrite the bullet about boundary protection

* expand on the lack of common trust

* fix division into paragraphs in the introduction

* different as -> different than

* in different namespaces in a cluster -> in the clusters

* to the ratings -> to the ratings service

* rewrite the explanation about DNS and routing

* add a comma after "destined to ratings"

* split a long line

* replace PCI DSS with boundary protection

* remove an unneeded empty line

* split long lines in the summary

* simplify the sentence in the summary about explicit exposure of the clusters

* put "paired" in italics

* split a long line

* change the publish date to 12-th of August

* split a long line

* add the "Isolation of system components and boundary protection" subsection

* rephrase a sentence to remove passive voice

* add cyber and subnetworks to .spelling

used by NIST Special Publication 800-53, Revision 4, Security and Privacy
Controls for Federal Information Systems and Organizations:

This type of enhanced protection limits the potential harm from cyber attacks...

... routers, gateways, and firewalls separating system components into physically separate networks or
subnetworks

* rephrase and reformat the section about boundary protection and isolation

* rewrite the section about isolation and boundary protection

* Kubernetes community -> the Kubernetes community

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* three patterns -> three documented patterns

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* three patterns differ -> the differences between the patterns

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* add "where none of the multi cluster patterns apply" to "there are cases when you want to"

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* didn't establish -> have not established

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* rewrite the sentence about the best solution and the goal

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* Payment Card Industry Data Security Standard -> the ..

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* move "in my opinion" to the beginning of the sentence

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* move "in my opinion" to the beginning of the sentence, part 2

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* Add "the" to PCI DSS

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* add "approach" after "the proposed mesh federation"

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* add "the" before NIST

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* uniform identical naming -> uniform naming

* common indentity and common trust -> common identity and trust

* mesh-federation -> isolated-clusters

* rewrite the blog post, removing mesh federation and multicluster mesh mentioning

* add the "Testing the certificates in the chain of calls" section

* Revert "add the "Testing the certificates in the chain of calls" section"

This reverts commit 6ada5903e5.

* remove redundant parenthesis around the first link to PCI DSS

* fix a typo (though -> through)

* remove the last '/' which seems to confuse lint

* remove namespace qualifier for gateways in virtual services

since the virtual services are in the same namespace

* extend the explanation about RBAC

* try another link for gdpr

* add `&nbsp;` to try to make lint happy

* Revert "add `&nbsp;` to try to make lint happy"

This reverts commit 552806883f.

* rewrite the list of standards as a table, add links to the paragraph below

* put full service name in backticks

* fix a typo (localtion -> location)

* fix the level of the first section

* rename the ca-example-com-certs secrets into c1/c2-trusted-certs secrets

to enable running commands in a single cluster

* use kubectl apply to create a namespace in case it already exists

for the single cluster scenario

* add deleting of the ratings service in the first cluster

during the initial setting

* change the error in case ratings is not found

* remove istio-private-gateways from the list of RBAC-included namespaces

* add '--ignore-not-found=true' to the kubectl delete commands

to support the case of a single cluster

* credit card -> payment card

* add running the blog post in a single cluster

* add unsetting environment variables to the cleanup section

* fix internal links

* The approach I propose - The approach I use

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* features of the proposed approach -> features of the approach

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* I propose -> I use

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* I propose to base connecting clusters on  -> I connect clusters based on

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* add "some of the process could clearly benefit from automation..."

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* similar the pattern -> similar to the pattern

* the proposed implementation -> the implementation pattern

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* added a comment that my approach is different from multicluster meshes

* fix a link

* add a multi-mesh section to examples

* move the blog post about cluster isolation to examples

* rewrite the blog post as example

* add a missing period in the description

* Revert "add a missing period in the description"

This reverts commit 14f656280f.

* Revert "rewrite the blog post as example"

This reverts commit 875a4f55f0.

* Revert "move the blog post about cluster isolation to examples"

This reverts commit 17b20a1cb5.

* Revert "add a multi-mesh section to examples"

This reverts commit 9d9365eee7.

* rewrite the blog post to not contain the same service (reviews) in two meshes

per comments of Sven Mawson
using ratings and httpbin to show exposure of two services

* fix the link to Envoy's RBAC filter

* fix an internal link

* fix spelling

* remove redundant empty line

* remove "no common trust" from the single cluster

* initial version after moving the example to istio-ecosystem

* fix list formatting

* additional touches

replace cluster with mesh everywhere
add monitoring at the boundary

* describe -> outline, report

* put all mesh-federation and multi-mesh instances into the glossary markup

* update the publish date

* call "service location transparency" an optional feature

* rewrote "Service location transparency is important" to "Service location transparency is useful in the cases when you want"

* the istio-ecosystem repository -> Istio ecosystem

* rewrite subtitle

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* Rewrite the title

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* rewrite the sentence about isolation

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* rewrite the sentence about separate service meshes on separate networks

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* Remove "Istio to connect applications in the meshes with different compliance requirements"

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* remove the glossary item from mesh federation and add "support and automation work under way"

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* remove glossary reference

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* remove glossary reference, 2

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* add comparison with multi-cluster (single mesh)

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* remove glossary reference, 3

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* remove glossary reference, 4

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* remove glossary reference, 5

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* remove glossary reference, 5

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* remove glossary reference, 6

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* remove glossary reference, 7

* report -> touch on

* update the date of the blog
2019-10-02 06:40:25 -07:00
Frank Budinsky 60aa772335 Remove inappropriate .spelling entry (#5087) 2019-09-30 11:32:23 -07:00
Johannes Scheuermann 7701cc2387 Add docs for psp istio-cni settings (#5082)
* Add docs for psp istio-cni settings

* Add PodSecurityPolicy to spelling file
2019-09-30 14:15:51 -04:00
Frank Budinsky 00c997abb3 Fix broken links (#5084) 2019-09-30 11:06:23 -07:00
Neeraj Poddar 81ead7238e Added blog for monitoring external service traffic (#5027)
* Added blog for monitoring external service traffic

In release 1.3 we added support for monitoring traffic to external services
which are allowed or get blocked. This blog explains how to use these metrics to
get the host names/IP addresses for these external services.

* Address review comments

* Removed extra heading

* Re-align headers

* Update index.md
2019-09-28 11:54:23 -07:00
John Howard fbc726c6b7 Remove usages of curl inside istio-proxy (#5073)
* Remove usages of curl inside istio-proxy

Distroless builds of Istio do not contain curl, so we should not tell
users to use it. Pilot-agent handles this functionality for us

* Fix lint error
2019-09-27 16:46:22 -07:00
Venil Noronha da9fb2726d Fix probe rewrite configuration command (#5076)
Signed-off-by: Venil Noronha <veniln@vmware.com>
2019-09-27 16:40:22 -07:00
Brian Avery a0df1ff05a 1.3.1 release notes (#5063)
* 1.1 release notes

* Cleaned up wording and formatting to match other point release

* Updated to remove UTF-8 from spelling as well as link to the last issue

* Moved release announcement to news

* Fixed capitalization and removed aliases for 1.3.1 release notes

* Removed references to pull requests rather than issues and added reference for metadata exchange and stats

* Added WebAssembly to the dictionary and removed duplicate of webhook

* Fixed date
2019-09-27 13:42:05 -07:00
Martin Taillefer d42dfe94ba
Introduce top-level News section. (#5060) 2019-09-27 07:09:58 -07:00
Zhonghu Xu 37f3af18a2 Replace multicast address with class E (#5051)
Ignoring unrelated broken link.

* Replace multicast address with class E

* address comments

* Update content/en/docs/setup/install/multicluster/gateways/index.md

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* Update content/en/docs/setup/install/multicluster/gateways/index.md

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>

* Update content/en/docs/setup/install/multicluster/gateways/index.md

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>
2019-09-27 09:34:05 -04:00
Frank Budinsky 7fe843b480 Small traffic-management corrections (#5062) 2019-09-26 15:04:43 -07:00
Ryan Michela 351710d058 Egress TLS origination port 443 must be HTTPS (#5049)
* Port 443 must be HTTPS

* Port 443 must be HTTPS
2019-09-26 12:05:15 -04:00
banix 994e8a7464 Add FAQ entry for running Cassandra (#4867)
* Add FAQ entry for running Cassandra

Addresses issue istio/istio#10053

* Making clear why default config does not work

* Removing numbering of subsections

* Removed one unnecessary line

* Addressing editorial corrections and removing a section
2019-09-25 16:33:57 -04:00
Martin Taillefer 0baea02755
Update reference docs. (#5054) 2019-09-25 12:14:37 -07:00
Xinnan Wen e606e95503 Fix typo (#5055) 2019-09-25 12:00:42 -07:00
Jason Young a5f38e1bbc document deleting the istio-system namespace in till uninstall path (#5043) 2019-09-24 07:31:13 -07:00
Kebe 021d6ecdab Add DaoCloud to customers (#5045) 2019-09-24 07:24:42 -07:00
Zhonghu Xu 4a3d0c2d3d Should not use loopback addresses (#5036)
* fix multi cluster dns docs

* fix multi cluster dns docs

* ignore multicast spelling check
2019-09-23 11:02:16 -07:00