Skip to content

How To Utilize Network Policy with Ambient? #51586

Answered by howardjohn
jsievenpiper asked this question in Q&A
Discussion options

You must be logged in to vote

For future readers, on slack we found:

  • Kiali error was an excessive logging; fixed in istio/ztunnel#1144
  • Grafana-agent to kiali was due to STRICT mode without grafana-agent in the mesh. Fixed by adding it into the mesh https://blog.howardjohn.info/posts/securing-prometheus/
  • Remaining case (not either of the logs in the original post, but other issues) were around port-level NetPol. Istio tunnels the traffic over port 15008, so the netpol applies on that port rather than the original port.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@howardjohn
Comment options

Answer selected by jsievenpiper
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants