istio.io/content/blog/2019
Vadim Eisenberg 24f9ca7046 Egress blog part 2 (#4232)
* add the second part of the series about secure egress traffic control in Istio (#4196)

* requirements for your system -> requirements for a system for egress traffic control

* add links from part 1 to part 2

* add istio-identity to .spelling

* add gateway and tls as keywords

Co-Authored-By: Rigs Caballero <grca@google.com>

* This is -> Welcome to, a new series -> our new series

Co-Authored-By: Rigs Caballero <grca@google.com>

* an egress traffic control system -> a secure control system for egress traffic

Co-Authored-By: Rigs Caballero <grca@google.com>

* for controlling egress traffic securely ->to securely control the egress traffic,  prevents the -> can help you prevent such

Co-Authored-By: Rigs Caballero <grca@google.com>

* Egress traffic control by Istio -> Secure control of egress traffic in Istio

Co-Authored-By: Rigs Caballero <grca@google.com>

* add bullets regarding security measures for Istio control plane

Co-Authored-By: Rigs Caballero <grca@google.com>

* you can securely monitor the traffic and define security policies on it -> you can securely monitor and define security policies for the traffic

Co-Authored-By: Rigs Caballero <grca@google.com>

* Possible attacks and their prevention -> Preventing possible attacks

Co-Authored-By: Rigs Caballero <grca@google.com>

* e.g. -> like, add a comma, split a sentence

Co-Authored-By: Rigs Caballero <grca@google.com>

* the -> said

Co-Authored-By: Rigs Caballero <grca@google.com>

* remove "for TLS traffic"

it is clear that it is TLS Traffic from TLS origination

Co-Authored-By: Rigs Caballero <grca@google.com>

* monitor SNI and the service account of the source pod -> monitor SNI and the service account of the source pod's TLS traffic

Co-Authored-By: Rigs Caballero <grca@google.com>

* L3 firewall -> an L3 firewall, remove parentheses, provided -> should be provided

* The L3 firewall can have -> you can configure the L3 firewall

Co-Authored-By: Rigs Caballero <grca@google.com>

* from pods only -> only allow. Remove "Note that"

Co-Authored-By: Rigs Caballero <grca@google.com>

* move the diagram right after its introduction

* remove parentheses

Co-Authored-By: Rigs Caballero <grca@google.com>

* emphasize the label (A, B)

Co-Authored-By: Rigs Caballero <grca@google.com>

* policy with regard -> policies as they regard

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about a compromised pod

Co-Authored-By: Rigs Caballero <grca@google.com>

* traffic must be monitored -> traffic is monitored

Co-Authored-By: Rigs Caballero <grca@google.com>

* Note that application A is allowed -> since application A is allowed

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about monitoring access of the compromised version of the application

Co-Authored-By: Rigs Caballero <grca@google.com>

* split the sentence about detecting suspicious traffic

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence about thwarting the second goal of the attackers

Co-Authored-By: Rigs Caballero <grca@google.com>

* Istio must enforce -> enforces, forbids access of application A -> forbids application A from accessing

Co-Authored-By: Rigs Caballero <grca@google.com>

* Rewrite the sentence "let's see which attacks"

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence "I hope that"

Co-Authored-By: Rigs Caballero <grca@google.com>

* in the next blog post -> in the next part

Co-Authored-By: Rigs Caballero <grca@google.com>

* remove mentioning wildcard domains

* rewrite the "Secure control of egress traffic in Istio" section

* remove a leftover from suggested changes

* as they regard to egress traffic -> for egress traffic

* convert security policies into bullets

* make the labels (A,B) bold

* remove the sentences about thwarting the second goal

* rewrite the paragraph about which goals of the attackers can be thwarted

* remove a leftover from the previous changes

* such attacks -> the attacks

* rewrite the section about preventing the attacks

* secure egress traffic control -> secure control of egress traffic

* sending HTTP traffic -> sending unencrypted HTTP traffic

* define security policies -> enforce security policies

* change the publish date to July 9

* formatting

Co-Authored-By: Rigs Caballero <grca@google.com>

* Kubernetes Network Policies -> Kubernetes network policies

Co-Authored-By: Rigs Caballero <grca@google.com>

* [an example for Kubernetes Network Policies configuration] -> an example of the [Kubernetes Network Policies configuration]

Co-Authored-By: Rigs Caballero <grca@google.com>

* use proper capitalization and punctuation for bullet 1

Co-Authored-By: Rigs Caballero <grca@google.com>

* use proper capitalization and punctuation for bullet 2

Co-Authored-By: Rigs Caballero <grca@google.com>

* use proper capitalization and punctuation for bullet 3

Co-Authored-By: Rigs Caballero <grca@google.com>

* use proper capitalization and punctuation for bullet 4

Co-Authored-By: Rigs Caballero <grca@google.com>

* check -> verify,  access the destination, mongo1, access mongo1

Co-Authored-By: Rigs Caballero <grca@google.com>

* You can thwart the third goal -> to stop attackers from

Co-Authored-By: Rigs Caballero <grca@google.com>

* remove mentioning anomaly detection

Co-Authored-By: Rigs Caballero <grca@google.com>

* Provide context instead of "after all"

Co-Authored-By: Rigs Caballero <grca@google.com>

* split a long line

Co-Authored-By: Rigs Caballero <grca@google.com>

* connect two sentences

Co-Authored-By: Rigs Caballero <grca@google.com>

* First -> Next

Co-Authored-By: Rigs Caballero <grca@google.com>

* use - instead of * for bulleted lists

* make the first attacker's goal a bullet

Co-Authored-By: Rigs Caballero <grca@google.com>

* make the first attacker's goal a bullet

the previous commit was related to the third goal

Co-Authored-By: Rigs Caballero <grca@google.com>

* make the second attacker's goal a bullet

Co-Authored-By: Rigs Caballero <grca@google.com>

* fix indentation

Co-Authored-By: Rigs Caballero <grca@google.com>

* make the reference to prevention of the first goal a bullet

Co-Authored-By: Rigs Caballero <grca@google.com>

* make the reference to prevention of the second goal a bullet

Co-Authored-By: Rigs Caballero <grca@google.com>

* rephrase the sentence about applying additional security measures

Co-Authored-By: Rigs Caballero <grca@google.com>

* remove leftover from a previous change

Co-Authored-By: Rigs Caballero <grca@google.com>

* that will enforce -> to enforce

Co-Authored-By: Rigs Caballero <grca@google.com>

* split long lines

* rewrite the part about increasing security of the control plane pods

* fix indentation

* fix indentation and remove a leftover from a previous change

* extend the bold font from a single word to a phrase

* rewrite the prevention of the straightforward access and the attacks

* add conclusion after the attacks part

* control planes pods -> control plane pods

* control plane -> Istio control plane

* is able to access it indistinguishable -> is indistinguishable

Co-Authored-By: Rigs Caballero <grca@google.com>

* rewrite the sentence "The choice would mainly depend on"

Co-Authored-By: Rigs Caballero <grca@google.com>

* insure -> ensure

Co-Authored-By: Rigs Caballero <grca@google.com>

* update the publish date to 10-th of July
2019-07-10 15:20:37 +00:00
..
announcing-1.0-eol Announcement for upcoming 1.0 end of support (#4197) (#4214) 2019-05-24 13:48:00 +00:00
announcing-1.0-eol-final 1.0 eol final announcement. (#4431) 2019-06-14 21:30:13 -07:00
announcing-1.0.6 Site improvements. (#4015) 2019-04-22 09:12:18 -07:00
announcing-1.0.7 Site improvements. (#4015) 2019-04-22 09:12:18 -07:00
announcing-1.0.8 1.0.8 release notes (#4278) 2019-06-07 09:01:49 -07:00
announcing-1.0.9 Draft release notes for 1.0.9 and 1.1.10. (#4566) 2019-06-28 14:39:39 -07:00
announcing-1.1 Cleanup multicluster doc (#4638) 2019-07-10 06:59:50 -07:00
announcing-1.1.1 Site improvements. (#4015) 2019-04-22 09:12:18 -07:00
announcing-1.1.2 Site improvements. (#4015) 2019-04-22 09:12:18 -07:00
announcing-1.1.3 Site improvements. (#4015) 2019-04-22 09:12:18 -07:00
announcing-1.1.4 1.1.4 release notes. (#4028) 2019-04-24 13:25:31 -07:00
announcing-1.1.5 Release notes for 1.1.5 (#4088) (#4217) 2019-05-24 13:58:31 +00:00
announcing-1.1.6 1.1.6 release notes (#4113) (#4216) 2019-05-24 13:59:15 +00:00
announcing-1.1.7 1.1.7 release notes (#4165) (#4215) 2019-05-24 13:59:55 +00:00
announcing-1.1.8 1.1.8 release notes (#4276) 2019-06-07 07:41:49 -07:00
announcing-1.1.9 1.1.9 release notes. (#4430) 2019-06-17 15:19:28 -07:00
announcing-1.1.10 Draft release notes for 1.0.9 and 1.1.10. (#4566) 2019-06-28 14:39:39 -07:00
announcing-1.1.11 Draft 1.1.11 release notes. (#4633) 2019-07-03 12:54:49 -04:00
announcing-1.2 Istio 1.2 announcement blog post (#4468) 2019-06-18 17:45:33 -07:00
announcing-discuss.istio.io No need for weights in blog posts, they auto-sort by publication date. (#3241) 2019-02-12 13:52:09 -08:00
appswitch No need for weights in blog posts, they auto-sort by publication date. (#3241) 2019-02-12 13:52:09 -08:00
custom-ingress-gateway Fix broken links (#3636) 2019-03-11 22:05:18 -07:00
cve-2019-12243 Security update. (#4233) 2019-05-28 10:22:16 -07:00
cve-2019-12995 Remove consecutive blank line. (#4587) 2019-06-29 03:35:06 -07:00
data-plane-setup Fix accidentally merged trailing space (#4578) 2019-06-28 16:52:50 -04:00
egress-performance [ImgBot] Optimize images (#3629) 2019-03-11 13:54:39 -07:00
egress-traffic-control-in-istio-part-1 Egress blog part 2 (#4232) 2019-07-10 15:20:37 +00:00
egress-traffic-control-in-istio-part-2 Egress blog part 2 (#4232) 2019-07-10 15:20:37 +00:00
istio1.1_perf Update publication dates. 2019-03-18 20:52:00 -07:00
multicluster-version-routing Cleanup multicluster doc (#4638) 2019-07-10 06:59:50 -07:00
performance-best-practices Clarifies latency measurement section for Istio 1.2 (#4649) 2019-07-09 18:30:35 +00:00
root-transition Move root-transition to docs/ to follow others (#4412) 2019-06-14 10:59:35 -07:00
sail-the-blog No need for weights in blog posts, they auto-sort by publication date. (#3241) 2019-02-12 13:52:09 -08:00
_index.md Switch to discuss.istio.io (#3071) 2019-01-10 07:11:00 -08:00