Commit Graph

3570 Commits

Author SHA1 Message Date
Martin Taillefer 34f7e853ed Pass user ID to docker. (#4733) 2019-07-29 14:43:36 +00:00
Võ Anh Duy 1480a3b8a2 Add outlier check column in proxy config command (#4080) 2019-07-29 05:09:51 +00:00
wusphinx 8c82025db3 fix number err from `5` to `2` (#4660)
* fix number err from `5`  to `2`

* use boilerplate to reduce duplication

* remove extra line
2019-07-29 11:04:59 +08:00
Mariam John f8f2404d64 Add feature to generate diffs for helm values.yaml file between releases (#4402)
This feature adds the capability to compare changes to the configuration options
in the helm values.yaml files between the current and previous release. This was
included in the 1.1 release but did not get merged. Here is the link to the
original PR: https://github.com/istio/istio.io/pull/3420

Fixes: #4384
2019-07-27 06:20:44 -07:00
Mariam John 9554bee587 Fix broken link in blog related to Traffic Mirroring (#4727)
This was causing linter to fail.

Fixes Bug: #4726
2019-07-26 21:01:39 +00:00
mergify[bot] e74754fbba clarify text and fix typo under quick start (#4720) (#4723)
(cherry picked from commit 2ebb2efb22)
2019-07-25 19:22:23 -07:00
Martin Taillefer 76a2b5fab2
Use updated container, now built in the tools repo. (#4722) 2019-07-25 15:55:33 -07:00
Rigs Caballero f059e72fcb Fix link to issue 2160 on the release note for Istio 1.1.9 (#4712) 2019-07-25 15:08:40 -07:00
imgbot[bot] e5dfdc5876 [ImgBot] Optimize images (#4709)
/content/about/community/customers/softonic.png -- 718.10kb -> 11.12kb (98.45%)

Signed-off-by: ImgBotApp <ImgBotHelp@gmail.com>
2019-07-25 15:06:34 -07:00
Vadim Eisenberg 7d3b895ef3 Rename multiple control planes multi cluster pattern (#4717)
* remove federation from the keywords of "multiple control plane" pattern

* rename Multiple Control Planes -> Dedicated Control Planes

* remove "single control plane" from the Shared control plane configurations

* add "topology" to "shared control plane" sections

* rewrite the description of shared control plane topology

remove "single" control plane

* two cluster mesh -> two-cluster mesh

* rewrite the explanation of the shared control plane single network topology

remote "the single control plane"

* Revert "rewrite the explanation of the shared control plane single network topology"

This reverts commit fb2d9f6b1a.

* Revert "rewrite the description of shared control plane topology"

This reverts commit 1170fe34ae.

* Revert "remove "single control plane" from the Shared control plane configurations"

This reverts commit 11e1caf1fa.

* fix announcing 1.1 blog post

* fix the multicluster version routing blog post

* fix remaining links to multicluster topologies

* put back removed "topologies" from the announcing-1.1 blog post

* fix a link in the multicluster version routing blog post
2019-07-25 15:10:00 -04:00
navinger 3b3419ab3b Add routing rules to the glossary (#4711)
Signed-off-by: Nancy Avinger <navinger@google.com>
2019-07-25 12:35:45 -04:00
santinoncs 2f11cf96ca Softonic in action (#4706)
* New logo image for Softonic in istio in action

* Position the logo in alphabetic order. And fit the url.
2019-07-24 10:18:20 -04:00
Frank Budinsky 8a2bcce4b8
Grammar improvements (#4703)
* Cross-namespace config

* clarifications

* Fix spelling

* tweaks

* improvements

* more details

* Reference the problem from egress gateway task

* tweak

* review comments and remove broken link

* broken link

* Grammar improvements
2019-07-24 09:48:23 -04:00
Katharine Berry 457d3b9dae Point /charts/ at GCS directly instead of gcsweb. (#4702) 2019-07-23 13:08:26 -07:00
Frank Budinsky 622020ba69
Add cross-namespace configuration info in op guide (#4691)
* Cross-namespace config

* clarifications

* Fix spelling

* tweaks

* improvements

* more details

* Reference the problem from egress gateway task

* tweak

* review comments and remove broken link

* broken link
2019-07-23 13:48:03 -04:00
Vadim Eisenberg b1b48a39eb Egress blog part 3 (#4637)
* a skeleton version

* add full content

* fix internal links to previous egress examples

* make the structure flat

decrease the indentation level of two subsections

* replace subtitle and description with content relevant for part 3

* add referencing the third part from the first and the second parts

* secure egress traffic control -> secure control of egress traffic

* Update content/blog/2019/egress-traffic-control-in-istio-part-3/index.md

Co-Authored-By: Rigs Caballero <grca@google.com>

* remove "new from

Co-Authored-By: Rigs Caballero <grca@google.com>

* such as Kubernetes Network Policies -> such as using Kubernetes Network Policies

Co-Authored-By: Rigs Caballero <grca@google.com>

* proxies/firewalls -> proxies and firewalls

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence of reminding the requirements

Co-Authored-By: Rigs Caballero <grca@google.com>

* support for -> support of

Co-Authored-By: Rigs Caballero <grca@google.com>

* remove by Istio, support for -> support of

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about the two alternative solutions

Co-Authored-By: Rigs Caballero <grca@google.com>

* cannot satisfy -> the requirements they can't satisfy

Co-Authored-By: Rigs Caballero <grca@google.com>

* remove the dot from subtitle

since Hugo complains about it

* add mentioning the alternative solutions before presenting them

* The most natural solution -> Kubernetes provides a native solution

* rewrite the sentence about cluster operators and network policies

Co-Authored-By: Rigs Caballero <grca@google.com>

* can be identified -> cluster operators can identify

Co-Authored-By: Rigs Caballero <grca@google.com>

* stress the relation between IP ranges and not being DNS-aware

* the requirement is satisfied -> network policies satisfy the requirement

* rewrite the sentence about K8s network policies and requirements 3 and 4

* remove passive voice in the sentence about the fifth requirement and k8s network policies

Co-Authored-By: Rigs Caballero <grca@google.com>

* and to interfere -> and interfere, the node - the said node

Co-Authored-By: Rigs Caballero <grca@google.com>

* Add "lastly", remove passive voice from the k8s network policies and the sixth requirement

Co-Authored-By: Rigs Caballero <grca@google.com>

* add "in summary" to the last sentence about k8s network policies

Co-Authored-By: Rigs Caballero <grca@google.com>

* another approach -> the second alternative, add the to Kubernetes network policies, add "Using ... lets you"

Co-Authored-By: Rigs Caballero <grca@google.com>

* are configured -> configure

Co-Authored-By: Rigs Caballero <grca@google.com>

* remove passive voice, use operators as subjects

Co-Authored-By: Rigs Caballero <grca@google.com>

* not known to proxies -> proxies do not know about them

Co-Authored-By: Rigs Caballero <grca@google.com>

* they -> egress proxies, source specified by -> Kubernetes artifacts specifies the source

Co-Authored-By: Rigs Caballero <grca@google.com>

* add "in summary" to the last sentence about egress proxies

Co-Authored-By: Rigs Caballero <grca@google.com>

* but not -> but can't satisfy

Co-Authored-By: Rigs Caballero <grca@google.com>

* connect two sentences about not specifying the requirements and why they do not specify the requirements

Co-Authored-By: Rigs Caballero <grca@google.com>

* fix the subtitle and description that were mistakenly reverted

* use lower case for network policies

* remove redundant white space

* remove a redundant empty line

* remove a leftover and fix lines arrangement

* hop with two proxies, the egress gateway -> hop with one or two proxies in the egress gateway

* pay attention to performance overhead and measure it

* remove "because they are DNS-aware" since they are by definiton DNS-aware

* requirements 3 and 4 -> the third and the fourth requirements

* proxy/firewall -> proxy or firewall

* have to -> must

* for authentication only without encrypting -> for authentication only, without encrypting

* remove comma in "in the egress gateway, should not have a large impact"

* remove "so I hope the overhead of egress traffic control in Istio will be reduced in the future"

since it is implied for the fact that we are working to reduce it

* use colon instead of "namely"

Co-Authored-By: Rigs Caballero <grca@google.com>

* split a long sentence

Co-Authored-By: Rigs Caballero <grca@google.com>

* do not -> don't, remove "to" after "or"

Co-Authored-By: Rigs Caballero <grca@google.com>

* tamper-proof -> resilient to tampering

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about Istio's additional features

Co-Authored-By: Rigs Caballero <grca@google.com>

* it allows defining -> define

Co-Authored-By: Rigs Caballero <grca@google.com>

* Is intergrated out of the box -> Out-of-the-box integration

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about writing the adapters to external monitoring once

Co-Authored-By: Rigs Caballero <grca@google.com>

* You can apply -> Use

Co-Authored-By: Rigs Caballero <grca@google.com>

* We call a system that has the advantages above -> We refer to a system with the advantages above as

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the "Let me summarize" sentence

Co-Authored-By: Rigs Caballero <grca@google.com>

* put Istio the first in the features table

* rewrite the sentence about the price of egress control

Co-Authored-By: Rigs Caballero <grca@google.com>

* increase of CPU usage by the cluster pods -> increased CPU usage by the cluster's pods

Co-Authored-By: Rigs Caballero <grca@google.com>

* Rewrite the sentence about traffic passing through two proxies

Co-Authored-By: Rigs Caballero <grca@google.com>

* complete the previous commit

Co-Authored-By: Rigs Caballero <grca@google.com>

* In the case of -> if you use

Co-Authored-By: Rigs Caballero <grca@google.com>

* making the count of proxies three -> adding a third proxy.

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about the traffic between proxies on the local host

Co-Authored-By: Rigs Caballero <grca@google.com>

* different configurations of Istio -> different Istio configurations set to control

Co-Authored-By: Rigs Caballero <grca@google.com>

* to measure carefully -> to carefully measure, for your applications -> with your applications

Co-Authored-By: Rigs Caballero <grca@google.com>

* measure and decide -> measure before you decide

Co-Authored-By: Rigs Caballero <grca@google.com>

* , and also compare with -> and compare

Co-Authored-By: Rigs Caballero <grca@google.com>

* provide our take -> share my thoughts

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about high latency of access to external services, part 1

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about high latency of access to external services, part 2

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about microservice architecture

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about the additional hop

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence "we are working to reduce performance"

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about possible optimizations, part 1

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about possible optimizations, part 2

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about possible optimizations, part 3

Co-Authored-By: Rigs Caballero <grca@google.com>

* I also hope -> hopefully, can serve as -> is, for controlling -> to control

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about the first Istio use case

Co-Authored-By: Rigs Caballero <grca@google.com>

* remove leftover from the previous commit

Co-Authored-By: Rigs Caballero <grca@google.com>

* remove the last sentence about the performance overhead

* add links to Istio features

* with Istio sidecar injected -> in the mesh

* then apply the adapters -> apply them

* add a comma

* rewrite the sentence about Istio being already beneficial

Co-Authored-By: Rigs Caballero <grca@google.com>

* replace * bullets by -

* remove double and

* The network policies -> Network policies

* remove "adding a third proxy"

* split a long line

* add a sentence about "Istio is the only solution"

* encourage users to install Istio, check Istio tasks and use discuss.istio.io

* fix a typo

* rewrite Istio is the only solution as bullets

Co-Authored-By: Rigs Caballero <grca@google.com>

* compete the previous commit

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence "if you had not a chance to work with Istio yet"

Co-Authored-By: Rigs Caballero <grca@google.com>

* chec egress traffic control -> check egress traffic control task

Co-Authored-By: Rigs Caballero <grca@google.com>

* Tell us what you think -> we also want to hear from you

Co-Authored-By: Rigs Caballero <grca@google.com>

* specify a traffic source -> specify the traffic source

* egress control task -> egress control tasks

* remove the final dot from the third bullet

* use a relative url for istio.io

* change the published date to today
2019-07-22 18:15:59 +00:00
Steven Dake 3c42578b57 Add distroless as a core feature for 1.3. (#4692)
* Add distroless as a core feature for 1.3.

Distroless is ready for Alpha. The images are built, pushed, and have been
running in CI for some time including presubmit testing.

* Add distroless to spelling file
2019-07-20 15:17:09 +00:00
Eric Van Norman d71d90bed8 Fix install CRD steps on various pages (#4680)
* Fix install CRD steps on various pages

* Fix ordering to create namespace first
2019-07-19 11:14:11 -04:00
Martin Taillefer 22fd781637
Put apporbit.com on the exception list since their site is down. (#4689) 2019-07-19 07:29:59 -07:00
imgbot[bot] 8793097b1e [ImgBot] Optimize images (#4688) 2019-07-19 06:57:08 -07:00
Bryan Absher 7d19397b88 Add flexe log to customers (#4681) 2019-07-19 06:49:10 -07:00
Andrew J 751b78a0a7 Adds Scytale.io as a partner (#4683) 2019-07-19 06:46:57 -07:00
Justin Watts addb88dc24 Loblaw Digital in action (#4684) 2019-07-19 06:45:27 -07:00
navinger 7fa13a057f Added glossary entry for virtual service. (#4682)
Signed-off-by: Nancy Avinger <navinger@google.com>
2019-07-19 09:16:41 -04:00
mergify[bot] a131e11da8 Updating the bash script for upgrading sidecar (bp #4675) (#4679)
* Updating the bash script for upgrading sidecar (#4675)

Updating the bash script and its usage for doing a rolling update
for all pods sidecar.

(cherry picked from commit fba893e943)

# Conflicts:
#	content/docs/setup/kubernetes/upgrade/steps/index.md

* fix merge conflict

* fix merge conflict
2019-07-18 14:07:46 -04:00
Martin Taillefer 5370eff22e
Improve control for auto-cherry picking to specific release branches. (#4674) 2019-07-18 09:53:00 -07:00
mergify[bot] 0ab449a961 remove duplicated row (#4676) (#4678)
(cherry picked from commit e155503f91)
2019-07-18 11:41:14 -04:00
Steven Dake c2a6805bee Document preference to using an NLB with gateways (#4677)
* Document preference to using an NLB with gateways

Gateways multicluster runs best with NLBs. Share this arcane bit of
information in the documentation.

* Address linting

* Address reviewer comments.

* Address reviewer comments
2019-07-18 11:21:59 -04:00
Frank Budinsky 215955d184 Gateway instruction correction (#4664) 2019-07-15 07:34:58 -07:00
mergify[bot] 1521380b30 Fix typo (#4668) (#4670)
(cherry picked from commit 3dd3265e82)
2019-07-15 09:34:02 -04:00
Vadim Eisenberg b2dd293b80 use role instead of clusterrole (#4665)
charts/gateways/templates/clusterrole.yaml -> charts/gateways/templates/role.yaml
charts/gateways/templates/clusterrolebinding.yaml -> charts/gateways/templates/rolebinding.yaml
2019-07-15 09:16:37 -04:00
Martin Taillefer c43550249a
Turn on mergify strict mode and add missing alias (#4666)
* Turn on mergify strict mode.

* Added missing alias for legacy bookmarks.
2019-07-13 05:09:19 -07:00
Frank Budinsky 74a1efe7ef Dest rule evaluation subtlety (#4653)
* Destination rule evaluationsubtlety

* resolve conflicts

* review comments

* tweak

* review comments

* Update content/docs/ops/traffic-management/troubleshooting/index.md

Co-Authored-By: Rigs Caballero <grca@google.com>
2019-07-11 18:26:49 +00:00
Frank Budinsky ad37eae5b5 Fix bad links (#4658) 2019-07-10 11:06:05 -07:00
WangChangyu 3cf6d5330e duplicate feature in traffic management section (#4651) 2019-07-10 15:42:56 +00:00
Adam Miller be5684e857 Add our first glossary entries for the documentation (#4644) 2019-07-10 08:30:12 -07:00
Vadim Eisenberg 24f9ca7046 Egress blog part 2 (#4232)
* add the second part of the series about secure egress traffic control in Istio (#4196)

* requirements for your system -> requirements for a system for egress traffic control

* add links from part 1 to part 2

* add istio-identity to .spelling

* add gateway and tls as keywords

Co-Authored-By: Rigs Caballero <grca@google.com>

* This is -> Welcome to, a new series -> our new series

Co-Authored-By: Rigs Caballero <grca@google.com>

* an egress traffic control system -> a secure control system for egress traffic

Co-Authored-By: Rigs Caballero <grca@google.com>

* for controlling egress traffic securely ->to securely control the egress traffic,  prevents the -> can help you prevent such

Co-Authored-By: Rigs Caballero <grca@google.com>

* Egress traffic control by Istio -> Secure control of egress traffic in Istio

Co-Authored-By: Rigs Caballero <grca@google.com>

* add bullets regarding security measures for Istio control plane

Co-Authored-By: Rigs Caballero <grca@google.com>

* you can securely monitor the traffic and define security policies on it -> you can securely monitor and define security policies for the traffic

Co-Authored-By: Rigs Caballero <grca@google.com>

* Possible attacks and their prevention -> Preventing possible attacks

Co-Authored-By: Rigs Caballero <grca@google.com>

* e.g. -> like, add a comma, split a sentence

Co-Authored-By: Rigs Caballero <grca@google.com>

* the -> said

Co-Authored-By: Rigs Caballero <grca@google.com>

* remove "for TLS traffic"

it is clear that it is TLS Traffic from TLS origination

Co-Authored-By: Rigs Caballero <grca@google.com>

* monitor SNI and the service account of the source pod -> monitor SNI and the service account of the source pod's TLS traffic

Co-Authored-By: Rigs Caballero <grca@google.com>

* L3 firewall -> an L3 firewall, remove parentheses, provided -> should be provided

* The L3 firewall can have -> you can configure the L3 firewall

Co-Authored-By: Rigs Caballero <grca@google.com>

* from pods only -> only allow. Remove "Note that"

Co-Authored-By: Rigs Caballero <grca@google.com>

* move the diagram right after its introduction

* remove parentheses

Co-Authored-By: Rigs Caballero <grca@google.com>

* emphasize the label (A, B)

Co-Authored-By: Rigs Caballero <grca@google.com>

* policy with regard -> policies as they regard

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about a compromised pod

Co-Authored-By: Rigs Caballero <grca@google.com>

* traffic must be monitored -> traffic is monitored

Co-Authored-By: Rigs Caballero <grca@google.com>

* Note that application A is allowed -> since application A is allowed

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about monitoring access of the compromised version of the application

Co-Authored-By: Rigs Caballero <grca@google.com>

* split the sentence about detecting suspicious traffic

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about thwarting the second goal of the attackers

Co-Authored-By: Rigs Caballero <grca@google.com>

* Istio must enforce -> enforces, forbids access of application A -> forbids application A from accessing

Co-Authored-By: Rigs Caballero <grca@google.com>

* Rewrite the sentence "let's see which attacks"

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence "I hope that"

Co-Authored-By: Rigs Caballero <grca@google.com>

* in the next blog post -> in the next part

Co-Authored-By: Rigs Caballero <grca@google.com>

* remove mentioning wildcard domains

* rewrite the "Secure control of egress traffic in Istio" section

* remove a leftover from suggested changes

* as they regard to egress traffic -> for egress traffic

* convert security policies into bullets

* make the labels (A,B) bold

* remove the sentences about thwarting the second goal

* rewrite the paragraph about which goals of the attackers can be thwarted

* remove a leftover from the previous changes

* such attacks -> the attacks

* rewrite the section about preventing the attacks

* secure egress traffic control -> secure control of egress traffic

* sending HTTP traffic -> sending unencrypted HTTP traffic

* define security policies -> enforce security policies

* change the publish date to July 9

* formatting

Co-Authored-By: Rigs Caballero <grca@google.com>

* Kubernetes Network Policies -> Kubernetes network policies

Co-Authored-By: Rigs Caballero <grca@google.com>

* [an example for Kubernetes Network Policies configuration] -> an example of the [Kubernetes Network Policies configuration]

Co-Authored-By: Rigs Caballero <grca@google.com>

* use proper capitalization and punctuation for bullet 1

Co-Authored-By: Rigs Caballero <grca@google.com>

* use proper capitalization and punctuation for bullet 2

Co-Authored-By: Rigs Caballero <grca@google.com>

* use proper capitalization and punctuation for bullet 3

Co-Authored-By: Rigs Caballero <grca@google.com>

* use proper capitalization and punctuation for bullet 4

Co-Authored-By: Rigs Caballero <grca@google.com>

* check -> verify,  access the destination, mongo1, access mongo1

Co-Authored-By: Rigs Caballero <grca@google.com>

* You can thwart the third goal -> to stop attackers from

Co-Authored-By: Rigs Caballero <grca@google.com>

* remove mentioning anomaly detection

Co-Authored-By: Rigs Caballero <grca@google.com>

* Provide context instead of "after all"

Co-Authored-By: Rigs Caballero <grca@google.com>

* split a long line

Co-Authored-By: Rigs Caballero <grca@google.com>

* connect two sentences

Co-Authored-By: Rigs Caballero <grca@google.com>

* First -> Next

Co-Authored-By: Rigs Caballero <grca@google.com>

* use - instead of * for bulleted lists

* make the first attacker's goal a bullet

Co-Authored-By: Rigs Caballero <grca@google.com>

* make the first attacker's goal a bullet

the previous commit was related to the third goal

Co-Authored-By: Rigs Caballero <grca@google.com>

* make the second attacker's goal a bullet

Co-Authored-By: Rigs Caballero <grca@google.com>

* fix indentation

Co-Authored-By: Rigs Caballero <grca@google.com>

* make the reference to prevention of the first goal a bullet

Co-Authored-By: Rigs Caballero <grca@google.com>

* make the reference to prevention of the second goal a bullet

Co-Authored-By: Rigs Caballero <grca@google.com>

* rephrase the sentence about applying additional security measures

Co-Authored-By: Rigs Caballero <grca@google.com>

* remove leftover from a previous change

Co-Authored-By: Rigs Caballero <grca@google.com>

* that will enforce -> to enforce

Co-Authored-By: Rigs Caballero <grca@google.com>

* split long lines

* rewrite the part about increasing security of the control plane pods

* fix indentation

* fix indentation and remove a leftover from a previous change

* extend the bold font from a single word to a phrase

* rewrite the prevention of the straightforward access and the attacks

* add conclusion after the attacks part

* control planes pods -> control plane pods

* control plane -> Istio control plane

* is able to access it indistinguishable -> is indistinguishable

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence "The choice would mainly depend on"

Co-Authored-By: Rigs Caballero <grca@google.com>

* insure -> ensure

Co-Authored-By: Rigs Caballero <grca@google.com>

* update the publish date to 10-th of July
2019-07-10 15:20:37 +00:00
Jian Zeng 2625f059ed doc(concepts): fix indentation (#4647) 2019-07-10 15:19:58 +00:00
Frank Budinsky 07d53225d3 Cleanup multicluster doc (#4638) 2019-07-10 06:59:50 -07:00
Megan O'Keefe 7d9cf41c86 Clarifies latency measurement section for Istio 1.2 (#4649) 2019-07-09 18:30:35 +00:00
Frank Budinsky 07ee8481e8 More traffic management corrections (#4636) 2019-07-09 10:44:45 -07:00
Vadim Eisenberg 9e03700cb0 though -> through (#4645) 2019-07-09 14:19:33 +00:00
Megan O'Keefe 5cb1d42de3 Adds blog post: performance benchmarking best practices (#4635)
* adds blog post

* Linter revisions

* Fix links

* Remove link to github file line number

* Provides clarity on Mixer v2

* list authors alphabetically

* Resolve comments

* Typo fix

* Apply suggestions from code review

Co-Authored-By: Rigs Caballero <grca@google.com>

* Linter update

* linter fix

* Update all github permalinks

* Add RBAC link

* list latencies in increasing order

* update name listing

* remove Note next to warning icon

* Clarify no mixer settings

* update summary punctuation
2019-07-08 17:30:07 +00:00
Jonh Wendell 98f93f40ae Show the URL for the Mixer self-monitoring endpoint (#4639)
* Show the URL for the Mixer self-monitoring endpoint

So that the user does not have to guess.

* Update content/docs/ops/telemetry/missing-metrics/index.md

Co-Authored-By: Frank Budinsky <frankb@ca.ibm.com>
2019-07-08 12:19:46 -04:00
mergify[bot] 46a133d21e error in the jsonpath selector (#4640) (#4641)
the old jsonpath selector doesn't work because it produce the pod name value to be incorrect
update it to the right jsonpath selector that produces the right pod name

(cherry picked from commit 0ad4e0a687)
2019-07-08 11:39:53 -04:00
mtail 664bcb81af Remove extraneous linefeed that was leading to extra whitespace in the HTML. 2019-07-05 04:31:34 -07:00
Joshua Blatt 49981eebc4 Draft 1.1.11 release notes. (#4633) 2019-07-03 12:54:49 -04:00
Nik Skoufis bb8af722b2 Add clarification on behaviour in absence of policy (#4354)
* Add clarification on behaviour in absence of policy

* Content fixes for clarity

* Remove example manifest in favor of explanation

The example manifest was confusing because it wasn't technically valid
if applied to a cluster. This removes it in favor of just spelling out
that both origin and transport auth are disabled.
2019-07-03 10:59:00 -04:00
Nik Skoufis 942c6e9d86 Add clarity to transport auth section, inc new mode param (#4356)
* Add clarity to transport auth section, inc new mode param

Arguably the wording here before was incorrect, because the mtls
parameter does have an argument, the mode parameter. This documents
STRICT and PERMISSIVE modes, as well as discussing the equivalence
between STRICT mode and omission of the mode key. It also adds clarity
as to what happens when the section is omitted.

* Fix typos

* Reword omission of tls mode for clarity

* Link to reference docs with equivalence tip

* Remove speculative paragraph

* Link directly to mtls modes reference

* Unbreak line to fix html

* Remove list inside tip

This seems to cause issues with html generation from Hugo
2019-07-03 10:50:21 -04:00
Ta-Ching Chen f47aa85001 Fix doc broken link (#4627) 2019-07-03 14:34:44 +00:00