istio
1meshConfig:
2defaultConfig:
3proxyMetadata:
4ISTIO_META_ENABLE_HBONE: "true"
5global:
6platform: openshift
7cni:
8ambient:
9enabled: true
10cniBinDir: /var/lib/cni/bin
11cniConfDir: /etc/cni/multus/net.d
12chained: false
13cniConfFileName: "istio-cni.conf"
14excludeNamespaces:
15- kube-system
16logLevel: info
17privileged: true
18provider: "multus"
19pilot:
20cni:
21enabled: true
22provider: "multus"
23variant: distroless
24env:
25# Setup more secure default that is off in 'default' only for backwards compatibility
26VERIFY_CERTIFICATE_AT_CLIENT: "true"
27ENABLE_AUTO_SNI: "true"
28
29PILOT_ENABLE_HBONE: "true"
30CA_TRUSTED_NODE_ACCOUNTS: "istio-system/ztunnel,kube-system/ztunnel"
31PILOT_ENABLE_AMBIENT_CONTROLLERS: "true"
32PILOT_ENABLE_AMBIENT_WAYPOINTS: "true"
33variant: distroless
34seLinuxOptions:
35type: spc_t