istio
21 строка · 1.0 Кб
1apiVersion: release-notes/v2
2kind: bug-fix
3area: traffic-management
4issue:
5- 35733
6releaseNotes:
7- |
8**Fixed** an issue causing mTLS errors for traffic on port 22, by including port 22 in iptables by default.
9
10upgradeNotes:
11- title: Port 22 iptables capture changes
12content: |
13In previous versions, port 22 was excluded from iptables capture. This mitigates risk of getting locked out of a VM
14when using Istio on VMs. This configuration was hardcoded into the iptables logic, meaning there was no way to
15capture traffic on port 22.
16
17The iptables logic now no longer has special logic on port 22. Instead, the `istioctl x workload entry configure`
18command will automatically configure `ISTIO_LOCAL_EXCLUDE_PORTS` to include port 22. This means that VM users will
19continue to have port 22 excluded, while Kubernetes users will have port 22 included now.
20
21If this behavior is undesirable, the port can be explicitly opted out in Kubernetes with the `traffic.sidecar.istio.io/excludeInboundPorts` annotation.