mirror of https://github.com/istio/istio.io.git
218 lines
6.9 KiB
HTML
218 lines
6.9 KiB
HTML
---
|
|
WARNING: THIS IS AN AUTO-GENERATED FILE, DO NOT EDIT. PLEASE MODIFY THE ORIGINAL SOURCE IN THE 'https://github.com/istio/api' REPO
|
|
source_repo: https://github.com/istio/api
|
|
title: Resource Labels
|
|
description: Resource labels used by Istio.
|
|
location: https://istio.io/docs/reference/config/labels/
|
|
weight: 60
|
|
---
|
|
|
|
<p>
|
|
This page presents the various resource <a href="https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/">labels</a> that
|
|
Istio supports to control its behavior.
|
|
</p>
|
|
<h2 id="IoIstioRev">istio.io/rev</h2>
|
|
<table class="annotations">
|
|
<tbody>
|
|
<tr>
|
|
<th>Name</th>
|
|
<td><code>istio.io/rev</code></td>
|
|
</tr>
|
|
<tr>
|
|
<th>Feature Status</th>
|
|
<td>Alpha</td>
|
|
</tr>
|
|
<tr>
|
|
<th>Resource Types</th>
|
|
<td>[Namespace]</td>
|
|
</tr>
|
|
<tr>
|
|
<th>Description</th>
|
|
<td><p>Istio control plane revision associated with the resource; e.g. <code>canary</code></p>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
<h2 id="NetworkingGatewayPort">networking.istio.io/gatewayPort</h2>
|
|
<table class="annotations">
|
|
<tbody>
|
|
<tr>
|
|
<th>Name</th>
|
|
<td><code>networking.istio.io/gatewayPort</code></td>
|
|
</tr>
|
|
<tr>
|
|
<th>Feature Status</th>
|
|
<td>Alpha</td>
|
|
</tr>
|
|
<tr>
|
|
<th>Resource Types</th>
|
|
<td>[Service]</td>
|
|
</tr>
|
|
<tr>
|
|
<th>Description</th>
|
|
<td><p>IstioGatewayPortLabel overrides the default 15443 value to use for a multi-network gateway’s port</p>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
<h2 id="ServiceCanonicalName">service.istio.io/canonical-name</h2>
|
|
<table class="annotations">
|
|
<tbody>
|
|
<tr>
|
|
<th>Name</th>
|
|
<td><code>service.istio.io/canonical-name</code></td>
|
|
</tr>
|
|
<tr>
|
|
<th>Feature Status</th>
|
|
<td>Alpha</td>
|
|
</tr>
|
|
<tr>
|
|
<th>Resource Types</th>
|
|
<td>[Pod]</td>
|
|
</tr>
|
|
<tr>
|
|
<th>Description</th>
|
|
<td><p>The name of the canonical service a workload belongs to</p>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
<h2 id="ServiceCanonicalRevision">service.istio.io/canonical-revision</h2>
|
|
<table class="annotations">
|
|
<tbody>
|
|
<tr>
|
|
<th>Name</th>
|
|
<td><code>service.istio.io/canonical-revision</code></td>
|
|
</tr>
|
|
<tr>
|
|
<th>Feature Status</th>
|
|
<td>Alpha</td>
|
|
</tr>
|
|
<tr>
|
|
<th>Resource Types</th>
|
|
<td>[Pod]</td>
|
|
</tr>
|
|
<tr>
|
|
<th>Description</th>
|
|
<td><p>The name of a revision within a canonical service that the workload belongs to</p>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
<h2 id="SidecarInject">sidecar.istio.io/inject</h2>
|
|
<table class="annotations">
|
|
<tbody>
|
|
<tr>
|
|
<th>Name</th>
|
|
<td><code>sidecar.istio.io/inject</code></td>
|
|
</tr>
|
|
<tr>
|
|
<th>Feature Status</th>
|
|
<td>Beta</td>
|
|
</tr>
|
|
<tr>
|
|
<th>Resource Types</th>
|
|
<td>[Pod]</td>
|
|
</tr>
|
|
<tr>
|
|
<th>Description</th>
|
|
<td><p>Specifies whether or not an Envoy sidecar should be automatically injected into the workload.</p>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
<h2 id="TopologyCluster">topology.istio.io/cluster</h2>
|
|
<table class="annotations">
|
|
<tbody>
|
|
<tr>
|
|
<th>Name</th>
|
|
<td><code>topology.istio.io/cluster</code></td>
|
|
</tr>
|
|
<tr>
|
|
<th>Feature Status</th>
|
|
<td>Alpha</td>
|
|
</tr>
|
|
<tr>
|
|
<th>Resource Types</th>
|
|
<td>[Pod]</td>
|
|
</tr>
|
|
<tr>
|
|
<th>Description</th>
|
|
<td><p>This label is applied to a workload internally that identifies the Kubernetes cluster containing the workload. The cluster ID is specified during Istio installation for each cluster via <code>values.global.multiCluster.clusterName</code>. It should be noted that this is only used internally within Istio and is not an actual label on workload pods. If a pod contains this label, it will be overridden by Istio internally with the cluster ID specified during Istio installation. This label provides a way to select workloads by cluster when using DestinationRules. For example, a service owner could create a DestinationRule containing a subset per cluster and then use these subsets to control traffic flow to each cluster independently.</p>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
<h2 id="TopologyNetwork">topology.istio.io/network</h2>
|
|
<table class="annotations">
|
|
<tbody>
|
|
<tr>
|
|
<th>Name</th>
|
|
<td><code>topology.istio.io/network</code></td>
|
|
</tr>
|
|
<tr>
|
|
<th>Feature Status</th>
|
|
<td>Beta</td>
|
|
</tr>
|
|
<tr>
|
|
<th>Resource Types</th>
|
|
<td>[Namespace Pod Service]</td>
|
|
</tr>
|
|
<tr>
|
|
<th>Description</th>
|
|
<td><p>A label used to identify the network for one or more pods. This is used
|
|
internally by Istio to group pods resident in the same L3 domain/network.
|
|
Istio assumes that pods in the same network are directly reachable from
|
|
one another. When pods are in different networks, an Istio Gateway
|
|
(e.g. east-west gateway) is typically used to establish connectivity
|
|
(with AUTO_PASSTHROUGH mode). This label can be applied to the following
|
|
resources to help automate Istio’s multi-network configuration.</p>
|
|
|
|
<ul>
|
|
<li><p>Istio System Namespace: Applying this label to the system namespace
|
|
establishes a default network for pods managed by the control plane.
|
|
This is typically configured during control plane installation using an
|
|
admin-specified value.</p></li>
|
|
|
|
<li><p>Pod: Applying this label to a pod allows overriding the default network
|
|
on a per-pod basis. This is typically applied to the pod via webhook
|
|
injection, but can also be manually specified on the pod by the service
|
|
owner. The Istio installation in each cluster configures webhook injection
|
|
using an admin-specified value.</p></li>
|
|
|
|
<li><p>Gateway Service: Applying this label to the Service for an Istio Gateway,
|
|
indicates that Istio should use this service as the gateway for the
|
|
network, when configuring cross-network traffic. Istio will configure
|
|
pods residing outside of the network to access the Gateway service
|
|
via <code>spec.externalIPs</code>, <code>status.loadBalancer.ingress[].ip</code>, or in the case
|
|
of a NodePort service, the Node’s address. The label is configured when
|
|
installing the gateway (e.g. east-west gateway) and should match either
|
|
the default network for the control plane (as specified by the Istio System
|
|
Namespace label) or the network of the targeted pods.</p></li>
|
|
</ul>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
<h2 id="TopologySubzone">topology.istio.io/subzone</h2>
|
|
<table class="annotations">
|
|
<tbody>
|
|
<tr>
|
|
<th>Name</th>
|
|
<td><code>topology.istio.io/subzone</code></td>
|
|
</tr>
|
|
<tr>
|
|
<th>Feature Status</th>
|
|
<td>Beta</td>
|
|
</tr>
|
|
<tr>
|
|
<th>Resource Types</th>
|
|
<td>[Node]</td>
|
|
</tr>
|
|
<tr>
|
|
<th>Description</th>
|
|
<td><p>User-provided node label for identifying the locality subzone of a workload. This allows admins to specify a more granular level of locality than what is offered by default with Kubernetes regions and zones.</p>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table> |