Skip to content

Istio certs ? #256

Description

@costinm

What would you like to be added

Few options:

  • expose the Istio CA gRPC interface, using the K8S JWT with istio-ca audience.
  • add an option to change the mount path for certs to the well-known path where istio-agent is looking for certs

Also it would be nice if the certs included the spiffe identity ( using a trust domain configured at install time),
and maybe an option to restrict the DNS names to NAME.NAMESPACE.SUFFIX - where the suffix is specified at install
time, namespace is the pod namespace - and name may be the only thing customized by the user (can default
the the service account name for example).

Why this is needed

  • Good to have options - Istio does have an integration with CertManager and I know autocert has a signer for cert manager, but more direct integration is providing more choices for users.
  • current mechanism of arbitrary names is fine for users with OPA or strict access, but a more strict naming would work for
    everyone else.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or requestneeds triageWaiting for discussion / prioritization by team

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions