New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add istio and sds values to GatewayParameters #9402
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
npolshakova
added
the
work in progress
signals bulldozer to keep pr open (don't auto-merge)
label
Apr 25, 2024
github-actions
bot
added
the
keep pr updated
signals bulldozer to keep pr up to date with base branch
label
Apr 25, 2024
jenshu
reviewed
Apr 30, 2024
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
some API comments
npolshakova
changed the title
Add istio and sds values to GatewayParams
Add istio and sds values to GatewayParameters
May 1, 2024
jbohanon
reviewed
May 16, 2024
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looking good!
projects/gateway2/helm/gloo-gateway/templates/gateway/proxy-deployment.yaml
Show resolved
Hide resolved
sam-heilbron
previously approved these changes
May 17, 2024
jbohanon
previously approved these changes
May 20, 2024
projects/gateway2/helm/gloo-gateway/templates/gateway/proxy-deployment.yaml
Show resolved
Hide resolved
projects/gateway2/helm/gloo-gateway/templates/gateway/proxy-deployment.yaml
Show resolved
Hide resolved
jenshu
reviewed
May 20, 2024
projects/gateway2/helm/gloo-gateway/templates/gateway/proxy-deployment.yaml
Show resolved
Hide resolved
projects/gateway2/helm/gloo-gateway/templates/gateway/proxy-deployment.yaml
Show resolved
Hide resolved
jbohanon
previously approved these changes
May 20, 2024
jbohanon
approved these changes
May 20, 2024
jenshu
approved these changes
May 20, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Currently, the istio integration helm value is still set as an env and passed around. A user sets istioSDS.enabled which then configures the GG_EXPERIMENTAL_ISTIO_MTLS_SDS_ENABLED env on the gloo control plane deployment.
The gateway v2 deployer then uses the IstioValues which are filled by the env values on the control plane deployment to inject the istio-proxy and sds sidecars.
Other than istioSDS.enabled none of the other Istio integration or SDS helm values are supported for the Gloo Gateway deployer. This is a current limitation in the k8s Gateway deployer and has caused issues related to running the Istio integration with gloo-ee.
Example GatewayParameters with all config set:
Example GatewayParameters config that only sets sds with default values:
Example GatewayParameters config that sets Istio integration with default values:
Relies on timeout override for pod matches assertion added in #9463
Code changes
Notes for reviewers
Once #9493 goes in, the old
IstioSDS
field in the deployer and env value that is set whenglobal.istioSDS.enabled=true
is set in the helm chart can be removed.I opened a separate issue to confirming the gloomtls behavior and convert the old gloomtls regression test into the new framework: https://github.com/solo-io/solo-projects/issues/6210
Design discussion: https://docs.google.com/document/d/1oF8KpoIEEcux_R8fBrLkdKF0NaonINVedhdCHMuf2bg/edit?usp=sharing
Checklist: