- Sort Score
- Result 10 results
- Languages All
Results 21 - 30 of 66 for ca (0.13 sec)
-
manifests/charts/gateways/istio-ingress/files/profile-openshift-ambient.yaml
env: PILOT_ENABLE_AMBIENT: "true" # Allow sidecars/ingress to send/receive HBONE. This is required for interop. PILOT_ENABLE_SENDING_HBONE: "true" PILOT_ENABLE_SIDECAR_LISTENING_HBONE: "true" CA_TRUSTED_NODE_ACCOUNTS: "istio-system/ztunnel,kube-system/ztunnel" platform: openshift variant: distroless seLinuxOptions:
Others - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Sat May 04 01:17:57 GMT 2024 - 955 bytes - Viewed (0) -
manifests/charts/ztunnel/files/profile-openshift-ambient.yaml
env: PILOT_ENABLE_AMBIENT: "true" # Allow sidecars/ingress to send/receive HBONE. This is required for interop. PILOT_ENABLE_SENDING_HBONE: "true" PILOT_ENABLE_SIDECAR_LISTENING_HBONE: "true" CA_TRUSTED_NODE_ACCOUNTS: "istio-system/ztunnel,kube-system/ztunnel" platform: openshift variant: distroless seLinuxOptions:
Others - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Sat May 04 01:17:57 GMT 2024 - 955 bytes - Viewed (0) -
manifests/charts/istio-control/istio-discovery/templates/clusterrole.yaml
resources: ["ingresses/status"] verbs: ["*"] # required for CA's namespace controller - apiGroups: [""] resources: ["configmaps"] verbs: ["create", "get", "list", "watch", "update"] # Istiod and bootstrap. {{- $omitCertProvidersForClusterRole := list "istiod" "custom" "none"}} {{- if or .Values.pilot.env.EXTERNAL_CA (not (has .Values.global.pilotCertProvider $omitCertProvidersForClusterRole)) }}
Others - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Fri Apr 12 16:44:32 GMT 2024 - 5.7K bytes - Viewed (0) -
manifests/charts/istiod-remote/files/injection-template.yaml
{{- if eq .Values.global.pilotCertProvider "istiod" }} - name: istiod-ca-cert configMap: name: istio-ca-root-cert {{- end }} {{- if eq .Values.global.pilotCertProvider "kubernetes" }} - name: kube-ca-cert configMap: name: kube-root-ca.crt {{- end }} {{- if .Values.global.mountMtlsCerts }}
Others - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Fri Apr 26 16:51:17 GMT 2024 - 23.7K bytes - Viewed (0) -
manifests/charts/istio-control/istio-discovery/files/injection-template.yaml
{{- if eq .Values.global.pilotCertProvider "istiod" }} - name: istiod-ca-cert configMap: name: istio-ca-root-cert {{- end }} {{- if eq .Values.global.pilotCertProvider "kubernetes" }} - name: kube-ca-cert configMap: name: kube-root-ca.crt {{- end }} {{- if .Values.global.mountMtlsCerts }}
Others - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Fri Apr 26 16:51:17 GMT 2024 - 23.7K bytes - Viewed (1) -
istioctl/pkg/workload/workload_test.go
"istio.io/istio/istioctl/pkg/cli" "istio.io/istio/pilot/test/util" "istio.io/istio/pkg/config/constants" "istio.io/istio/pkg/kube" "istio.io/istio/pkg/test/util/assert" ) var fakeCACert = []byte("fake-CA-cert") var ( defaultYAML = `apiVersion: networking.istio.io/v1alpha3 kind: WorkloadGroup metadata: name: foo namespace: bar spec: metadata: {} template: serviceAccount: default `
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Wed Mar 27 16:59:05 GMT 2024 - 14.6K bytes - Viewed (0) -
operator/cmd/mesh/testdata/manifest-generate/data-snapshot.tar.gz
and the aud field of such JWT. See RFC 7519, section 4.1.3. # When a CSR is sent from Istio Agent to the CA (e.g. Istiod), this aud is to make sure the # JWT is intended for the CA. token: aud: istio-ca sts: # The service port used by Security Token Service (STS) server to handle token exchange requests. # Setting this port to a non-zero value enables STS server. servicePort: 0 # The name of the CA for workload certificates. # For example, when caName=GkeWorkloadCertifica, GKE workload certificates...
Others - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Wed Jan 10 05:10:03 GMT 2024 - 198.1K bytes - Viewed (1) -
istioctl/pkg/writer/ztunnel/configdump/configdump.go
func (c *ConfigWriter) PrintVersionSummary() error { // TODO return nil } // PrintPodRootCAFromDynamicSecretDump prints just pod's root ca from dynamic secret config dump to the ConfigWriter stdout func (c *ConfigWriter) PrintPodRootCAFromDynamicSecretDump() (string, error) { // TODO return "", nil } func (c *ConfigWriter) tabwriter() *tabwriter.Writer {
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Tue Apr 23 21:30:30 GMT 2024 - 2.8K bytes - Viewed (0) -
manifests/charts/istiod-remote/templates/crd-all.gen.yaml
certificates. type: string insecureSkipVerify: description: '`insecureSkipVerify` specifies whether the proxy should skip verifying the CA signature
Others - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Mon Apr 22 20:20:47 GMT 2024 - 606.1K bytes - Viewed (0) -
manifests/charts/gateway/files/profile-ambient.yaml
meshConfig: defaultConfig: proxyMetadata: ISTIO_META_ENABLE_HBONE: "true" global: variant: distroless pilot: env: PILOT_ENABLE_AMBIENT: "true" CA_TRUSTED_NODE_ACCOUNTS: "istio-system/ztunnel,kube-system/ztunnel" cni: ambient: enabled: true # Ztunnel doesn't use a namespace, so everything here is mostly for ztunnel
Others - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Thu Apr 18 19:09:43 GMT 2024 - 683 bytes - Viewed (0)