์ด ๋ฌธ์„œ์—์„œ๋Š” Gateway API + Istio์˜ ๊ธฐ๋ณธ ๊ฐœ๋…๊ณผ ์‹ค์ œ ์ ์šฉ์— ํ•„์š”ํ•œ ๊ตฌ์„ฑ ์š”์†Œ๋“ค์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.

Gateway API

Kubernetes SIG Network์—์„œ ๊ฐœ๋ฐœํ•œ ์ฐจ์„ธ๋Œ€ Ingress API๋กœ, L4/L7 ๋ผ์šฐํŒ…์„ ์œ„ํ•œ ๊ณต์‹ Kubernetes ํ”„๋กœ์ ํŠธ์ž…๋‹ˆ๋‹ค.
2023๋…„ ๋ง v1.0 GA ์ถœ์‹œ ์ดํ›„ ๋น ๋ฅด๊ฒŒ ์„ฑ์žฅํ•˜์—ฌ, ์ƒˆ๋กœ์šด ๋„คํŠธ์›Œํฌ ๊ตฌํ˜„์˜ ํ‘œ์ค€์œผ๋กœ ์ž๋ฆฌ์žก์•˜์Šต๋‹ˆ๋‹ค.

Gateway API์˜ ํ•ต์‹ฌ ์„ค๊ณ„ ์›์น™

  • ์—ญํ•  ๊ธฐ๋ฐ˜ (Role-oriented):
    • ๊ธฐ์กด Ingress๋Š” ํ•˜๋‚˜์˜ Ingress ๋ฆฌ์†Œ์Šค์— ๋ชจ๋“  ์„ค์ •์ด ์„ž์—ฌ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.
    • Gateway API๋Š” ์—ญํ• ๋ณ„๋กœ Gateway, HTTPRoute ๋“ฑ์˜ ๋ฆฌ์†Œ์Šค๋ฅผ ๋ถ„๋ฆฌํ•˜๊ณ , ๊ฐ ์—ญํ• ๋ณ„๋กœ ์ฑ…์ž„๊ณผ ๊ด€๋ฆฌ ๋ฒ”์œ„๋ฅผ ๋ช…ํ™•ํžˆ ๊ตฌ๋ถ„ํ•ฉ๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, DevOps Engineer๊ฐ€ GatewayClass์™€ Gateway๋ฅผ ๊ด€๋ฆฌํ•˜๋ฉฐ, ์ผ๋ฐ˜ Software Engineer๋Š” HTTPRoute๋งŒ ์‹ ๊ฒฝ ์“ธ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • ์ด์‹์„ฑ (Portable):
    • Istio, Cilium ๋“ฑ ๋‹ค์–‘ํ•œ ๊ตฌํ˜„์ฒด์—์„œ ๋™์ผํ•œ CRD๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • ํ‘œํ˜„๋ ฅ (Expressive): ํ—ค๋” ๋งค์นญ, ํŠธ๋ž˜ํ”ฝ ๊ฐ€์ค‘์น˜ ๋“ฑ ๊ณ ๊ธ‰ ๊ธฐ๋Šฅ์„ ๊ธฐ๋ณธ์œผ๋กœ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.
  • ํ™•์žฅ์„ฑ (Extensible):
    • ์ถ”๊ฐ€ ํŠน์ˆ˜/๊ณ ๊ธ‰ ๊ธฐ๋Šฅ์€ ๊ตฌํ˜„์ฒด๋ณ„๋กœ ๋ณ„๋„ CRD๋ฅผ ์ •์˜ํ•˜๋Š” ๋“ฑ ๊ตฌํ˜„์ฒด๋ณ„๋กœ ํ™•์žฅ์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.
    • ์˜ˆ๋ฅผ ๋“ค์–ด Istio์˜ VirtualService์™€ DestinationRule, NGINX Gateway Fabric์˜ ClientSettingsPolicy ๋“ฑ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

Gateway API์˜ ์ฃผ์š” ๊ตฌ์„ฑ ์š”์†Œ

๋ฆฌ์†Œ์Šค๊ด€๋ฆฌ ์ฃผ์ฒด์„ค๋ช…
GatewayClassInfrastructure Provider์–ด๋–ค Gateway ๊ตฌํ˜„์ฒด(Istio, Cilium ๋“ฑ)๋ฅผ ์‚ฌ์šฉํ• ์ง€ ์ •์˜
GatewayDevOps EngineerํฌํŠธ, ๋„๋ฉ”์ธ, TLS ๋“ฑ ์ธํ”„๋ผ ์ˆ˜์ค€ ์„ค์ •
HTTPRouteSoftware Engineer์ž์‹ ์˜ ์•ฑ์œผ๋กœ ํŠธ๋ž˜ํ”ฝ์„ ๋ผ์šฐํŒ…ํ•˜๋Š” ๊ทœ์น™ ์ •์˜
GRPCRouteSoftware EngineergRPC ํŠธ๋ž˜ํ”ฝ์ด ํ•„์š”ํ•  ๊ฒฝ์šฐ
TCPRoute/UDPRouteSoftware EngineerL4 ํŠธ๋ž˜ํ”ฝ ์ฒ˜๋ฆฌ๊ฐ€ ํ•„์š”ํ•  ๊ฒฝ์šฐ (Alpha)

Ingress์™€์˜ ์ฐจ์ด์  (Gateway API๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ•˜๋Š” ์ด์œ )

ํ•ญ๋ชฉIngressGateway API
์—ญํ•  ๋ถ„๋ฆฌ๋‹จ์ผ ๋ฆฌ์†Œ์Šค์— ๋ชจ๋“  ์„ค์ • ํ˜ผ์žฌGatewayClass/Gateway/Route๋กœ ์ฑ…์ž„ ๋ถ„๋ฆฌ
ํ”„๋กœํ† ์ฝœHTTP, HTTPSHTTP, HTTPS, gRPC, TCP, UDP
๋ผ์šฐํŒ…๊ธฐ๋ณธ ๊ฒฝ๋กœ ๊ธฐ๋ฐ˜ํ—ค๋”, ๊ฐ€์ค‘์น˜, ๋ฉ”์„œ๋“œ ๋“ฑ ๊ณ ๊ธ‰ ๋ผ์šฐํŒ…
Canary ๋ฐฐํฌAnnotation ํ•„์š”weight ํ•„๋“œ๊ฐ€ ํ‘œ์ค€ ์ŠคํŽ™์ด๋ฏ€๋กœ ๋ฐ”๋กœ ํŠธ๋ž˜ํ”ฝ ๋ถ„๋ฐฐ ๊ฐ€๋Šฅ
์ด์‹์„ฑAnnotation์ด ๊ตฌํ˜„์ฒด๋งˆ๋‹ค ๋‹ค๋ฆ„ํ•ต์‹ฌ ๊ธฐ๋Šฅ์€ ํ‘œ์ค€ CRD, ๊ณ ๊ธ‰ ๊ธฐ๋Šฅ๋งŒ ์ถ”๊ฐ€ CRD ์ •์˜๋กœ ํ™•์žฅ
Cross-NS Route Attachment๋ฏธ์ง€์›๋‹ค๋ฅธ NS์˜ Gateway์— Route ์—ฐ๊ฒฐ ๊ฐ€๋Šฅ1
Cross-NS Backend Reference๋ฏธ์ง€์›๋‹ค๋ฅธ NS์˜ Service๋ฅผ backendRef๋กœ ์ฐธ์กฐ ๊ฐ€๋Šฅ2

Ingress ๊ฐœ๋ฐœ์€ Gateway API๋กœ ์ „ํ™˜๋˜์—ˆ์œผ๋ฉฐ, ๋‹น๋ถ„๊ฐ„ ๊ณต์กดํ•˜์ง€๋งŒ ์ ์ฐจ Deprecated ๋  ์˜ˆ์ •์ž…๋‹ˆ๋‹ค.3
์‹ ๊ทœ ํ”„๋กœ์ ํŠธ๋Š” ์ฒ˜์Œ๋ถ€ํ„ฐ Gateway API๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ๊ถŒ์žฅ๋ฉ๋‹ˆ๋‹ค.

Istio

Service Mesh๋ž€?

๋งˆ์ดํฌ๋กœ์„œ๋น„์Šค ํ™˜๊ฒฝ์—์„œ ์„œ๋น„์Šค ๊ฐ„ ํ†ต์‹ ์— ํ•„์š”ํ•œ ๊ณตํ†ต ๊ธฐ๋Šฅ์„ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ฝ”๋“œ ๋ณ€๊ฒฝ ์—†์ด ์ธํ”„๋ผ ๋ ˆ์ด์–ด์—์„œ ์ฒ˜๋ฆฌํ•ด์ฃผ๋Š” ๊ธฐ์ˆ ์ž…๋‹ˆ๋‹ค.

Service Mesh๊ฐ€ ์—†๋‹ค๋ฉด ๋‹ค์Œ์„ ์ง์ ‘ ๊ตฌํ˜„ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค:

๋ฌธ์ œ์ง์ ‘ ๊ตฌํ˜„ ์‹œ
์„œ๋น„์Šค ๊ฐ„ ์•”ํ˜ธํ™”๊ฐ ์•ฑ์— TLS ์„ค์ •, ์ธ์ฆ์„œ ๊ด€๋ฆฌ ์ฝ”๋“œ ์ถ”๊ฐ€
์žฌ์‹œ๋„/ํƒ€์ž„์•„์›ƒ/์„œํ‚ท๋ธŒ๋ ˆ์ด์ปค๊ฐ ์•ฑ์— Resilience ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ์ถ”๊ฐ€
ํŠธ๋ž˜ํ”ฝ ๊ด€์ธก๊ฐ ์•ฑ์— ๋ฉ”ํŠธ๋ฆญ/ํŠธ๋ ˆ์ด์‹ฑ SDK ์‚ฝ์ž…
์ ‘๊ทผ ์ œ์–ด๊ฐ ์•ฑ์— ์ธ์ฆ/์ธ๊ฐ€ ๋กœ์ง ๊ตฌํ˜„

์ด ๊ณผ์ •์—์„œ ์ค‘๋ณต ์ฝ”๋“œ, ์–ธ์–ด๋ณ„๋กœ ๋‹ค๋ฅธ ๊ตฌํ˜„, ์ผ๊ด€์„ฑ ์—†๋Š” ์ •์ฑ… ์ ์šฉ ๋“ฑ ์—ฌ๋Ÿฌ ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Service Mesh๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ์ด ๋ชจ๋“  ๊ฒƒ์„ ์•ฑ ์™ธ๋ถ€์—์„œ ์ผ๊ด€๋˜๊ฒŒ ์ฒ˜๋ฆฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Istio๋ž€?

Google, IBM, Lyft๊ฐ€ 2016๋…„ ์‹œ์ž‘ํ•œ ์˜คํ”ˆ์†Œ์Šค Service Mesh๋กœ, 2023๋…„ CNCF Graduated ํ”„๋กœ์ ํŠธ๊ฐ€ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ํ•ต์‹ฌ ๊ธฐ๋Šฅ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

  • ํŠธ๋ž˜ํ”ฝ ๊ด€๋ฆฌ: ์žฌ์‹œ๋„, ํƒ€์ž„์•„์›ƒ, ์„œํ‚ท๋ธŒ๋ ˆ์ด์ปค, ํŠธ๋ž˜ํ”ฝ ๋ถ„ํ•  ๋“ฑ
  • ๋ณด์•ˆ: mTLS ์•”ํ˜ธํ™”, ์ธ์ฆ/์ธ๊ฐ€, ์ •์ฑ… ์ผ๊ด€์„ฑ ์žˆ๋Š” ์ ์šฉ
  • ๊ด€์ธก์„ฑ: Grafana, Prometheus ๋“ฑ๊ณผ ์—ฐ๋™๋˜๋Š” ๋ฉ”ํŠธ๋ฆญ/ํŠธ๋ ˆ์ด์‹ฑ/๋กœ๊น…

๋‹ค๋ฅธ Service Mesh์™€์˜ ๋น„๊ต

ํ•ญ๋ชฉIstioLinkerdCilium Service Mesh
ํ”„๋ก์‹œEnvoy (L7 ํ’€์ŠคํŽ™)linkerd2-proxy (๊ฒฝ๋Ÿ‰)eBPF (์ปค๋„ ๋ ˆ๋ฒจ)
๊ธฐ๋Šฅ ๋ฒ”์œ„๊ฐ€์žฅ ํ’๋ถ€์‹ฌํ”Œํ•จ ์šฐ์„ ๋„คํŠธ์›Œํฌ ์„ฑ๋Šฅ ์šฐ์„ 
๋ณต์žก๋„๋†’์Œ๋‚ฎ์Œ์ค‘๊ฐ„
Ambient Mode์ง€์›๋ฏธ์ง€์›๊ธฐ๋ณธ์ด Sidecarless

Istio๋ฅผ ์„ ํƒํ•˜๋Š” ์ด์œ :

  • ๊ฐ€์žฅ ์„ฑ์ˆ™ํ•˜๊ณ  ๊ธฐ๋Šฅ์ด ํ’๋ถ€ํ•จ (CNCF Graduated)
  • ๋ฉ€ํ‹ฐํด๋Ÿฌ์Šคํ„ฐ, VM ์›Œํฌ๋กœ๋“œ ๋“ฑ ๋‹ค์–‘ํ•œ ํ™˜๊ฒฝ ์ง€์›
  • Ambient Mode๋กœ Sidecar ๋ฐฉ์‹์˜ ๋‹จ์  ํ•ด๊ฒฐ

Ambient Mode๋ž€?

๊ธฐ์กด Sidecar ๋ฐฉ์‹์˜ ๋‹จ์ ์„ ํ•ด๊ฒฐํ•œ ์ƒˆ๋กœ์šด ๋ฐ์ดํ„ฐ ํ”Œ๋ ˆ์ธ ์•„ํ‚คํ…์ฒ˜์ž…๋‹ˆ๋‹ค. 1.24 ๋ฒ„์ „์—์„œ Stable์ด ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. Pod๋งˆ๋‹ค Envoy sidecar๋ฅผ ์ฃผ์ž…ํ•˜๋Š” ๋Œ€์‹ , ๋…ธ๋“œ ๋ ˆ๋ฒจ L4 ํ”„๋ก์‹œ(ztunnel)์™€ ์„ ํƒ์  L7 ํ”„๋ก์‹œ(Waypoint)๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

์žฅ์ :

  • ๋‚ฎ์€ ๋ฆฌ์†Œ์Šค ์†Œ๋น„: ๋…ธ๋“œ๋‹น ํ•˜๋‚˜์˜ ztunnel๋กœ CPU/๋ฉ”๋ชจ๋ฆฌ ์ ˆ๊ฐ
  • ๊ฐ„์†Œํ™”๋œ ์šด์˜: Pod์™€ ๋…๋ฆฝ๋œ ํ”„๋ก์‹œ๋กœ ์šด์˜๋˜๋ฉฐ, ์—ญํ• ๊ณผ ์ƒ๋ช…์ฃผ๊ธฐ๋ฅผ ์™„์ „ํžˆ ๋ถ„๋ฆฌ
  • ์ ์ง„์  ๋„์ž… ๊ฐ€๋Šฅ: L4, L7 ํ”„๋ก์‹œ๋ฅผ ์„ ํƒ์ ์œผ๋กœ ์ถ”๊ฐ€ํ•˜์—ฌ ์ ์ง„์ ์œผ๋กœ ๋„์ž… ๊ฐ€๋Šฅ

Istio ์•„ํ‚คํ…์ฒ˜

Istio๋Š” ์ปจํŠธ๋กค ํ”Œ๋ ˆ์ธ๊ณผ ๋ฐ์ดํ„ฐ ํ”Œ๋ ˆ์ธ์œผ๋กœ ๊ตฌ์„ฑ๋ฉ๋‹ˆ๋‹ค.
์ปจํŠธ๋กค ํ”Œ๋ ˆ์ธ์€ ์ •์ฑ…๊ณผ ์„ค์ •์„ ๊ด€๋ฆฌํ•˜๊ณ  ๋ฐ์ดํ„ฐ ํ”Œ๋ ˆ์ธ์œผ๋กœ ์ „๋‹ฌํ•˜๋ฉฐ, istiod๊ฐ€ ๊ทธ ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค. ๋ฐ์ดํ„ฐ ํ”Œ๋ ˆ์ธ์€ ztunnel(L4)๊ณผ waypoint(L7)๋กœ ๊ตฌ์„ฑ๋˜๋ฉฐ, ์‹ค์ œ๋กœ ํŠธ๋ž˜ํ”ฝ์„ ์ฒ˜๋ฆฌํ•˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

flowchart TB
    subgraph ControlPlane["์ปจํŠธ๋กค ํ”Œ๋ ˆ์ธ"]
        istiod["istiod<br/>(์„ค์ • ๋ฐฐํฌ, ์ธ์ฆ์„œ ๊ด€๋ฆฌ, ์„œ๋น„์Šค ๋””์Šค์ปค๋ฒ„๋ฆฌ)"]
    end

    subgraph DataPlane["๋ฐ์ดํ„ฐ ํ”Œ๋ ˆ์ธ (Ambient Mode)"]
        ztunnel["ztunnel<br/>(L4: mTLS, ์ธ์ฆ/์ธ๊ฐ€)"]
        waypoint["Waypoint Proxy<br/>(L7: HTTP ์ •์ฑ…, ํ…”๋ ˆ๋ฉ”ํŠธ๋ฆฌ)"]
    end

    subgraph App["์• ํ”Œ๋ฆฌ์ผ€์ด์…˜"]
        pod1["Pod A"]
        pod2["Pod B"]
    end

    istiod -->|์„ค์ •/์ธ์ฆ์„œ ์ „๋‹ฌ| ztunnel
    istiod -->|์„ค์ •/์ธ์ฆ์„œ ์ „๋‹ฌ| waypoint
    pod1 <-->|ํŠธ๋ž˜ํ”ฝ| ztunnel
    pod2 <-->|ํŠธ๋ž˜ํ”ฝ| ztunnel
    ztunnel <-->|L7 ํ•„์š”์‹œ| waypoint

์ฃผ์š” CRD

CRD์šฉ๋„
VirtualServiceํŠธ๋ž˜ํ”ฝ ๋ผ์šฐํŒ… ๊ทœ์น™ (์žฌ์‹œ๋„, ํƒ€์ž„์•„์›ƒ, ํŠธ๋ž˜ํ”ฝ ๋ถ„ํ•  ๋“ฑ)
DestinationRule๋ฐฑ์—”๋“œ ์ •์ฑ… (๋กœ๋“œ๋ฐธ๋Ÿฐ์‹ฑ, ์„œํ‚ท๋ธŒ๋ ˆ์ด์ปค, ์—ฐ๊ฒฐ ํ’€ ์„ค์ • ๋“ฑ)
AuthorizationPolicy์ ‘๊ทผ ์ œ์–ด (์–ด๋–ค ์„œ๋น„์Šค๊ฐ€ ์–ด๋–ค ์„œ๋น„์Šค๋ฅผ ํ˜ธ์ถœํ•  ์ˆ˜ ์žˆ๋Š”์ง€)
PeerAuthenticationmTLS ๋ชจ๋“œ ์„ค์ • (STRICT, PERMISSIVE ๋“ฑ)
RequestAuthenticationJWT ๊ฒ€์ฆ ๋“ฑ ์š”์ฒญ ์ˆ˜์ค€ ์ธ์ฆ
EnvoyFilterEnvoy ์ €์ˆ˜์ค€ ์„ค์ • (์ตœํ›„์˜ ์ˆ˜๋‹จ, ์•„๋ž˜ ์ฐธ๊ณ )

VirtualService vs HTTPRoute

ํ•ญ๋ชฉHTTPRoute (Gateway API)VirtualService (Istio)
ํ‘œ์ค€ํ™”Kubernetes ํ‘œ์ค€Istio ์ „์šฉ
์ ์šฉ ๋ฒ”์œ„North-South (์™ธ๋ถ€โ†’๋‚ด๋ถ€)North-South + East-West (๋‚ด๋ถ€โ†”๋‚ด๋ถ€)
์ด์‹์„ฑ๋‹ค๋ฅธ ๊ตฌํ˜„์ฒด๋กœ ์ด๋™ ๊ฐ€๋ŠฅIstio์— ์ข…์†
๊ธฐ๋Šฅ๋ผ์šฐํŒ…, ํŠธ๋ž˜ํ”ฝ ๋ถ„ํ• , ํ—ค๋” ๋งค์นญHTTPRoute์˜ ๊ธฐ๋Šฅ + ์žฌ์‹œ๋„, ํƒ€์ž„์•„์›ƒ, fault injection ๋“ฑ

์š”์•ฝํ•˜๋ฉด ๊ธฐ๋Šฅ์ ์œผ๋กœ๋Š” VirtualService๊ฐ€ ๋” ํ’๋ถ€ํ•˜์ง€๋งŒ, ํ‘œ์ค€ํ™”๋‚˜ ๋‹ค๋ฅธ Gateway API ๊ตฌํ˜„์ฒด๋กœ ์ด์ „ ๊ณ„ํš์ด ์žˆ๋‹ค๋ฉด HTTPRoute๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ๋‚˜์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

EnvoyFilter ์‚ฌ์šฉ ์‹œ ์ฃผ์˜์‚ฌํ•ญ

EnvoyFilter๋Š” ํ‘œ์ค€ CRD๋กœ ํ‘œํ˜„ํ•  ์ˆ˜ ์—†๋Š” Envoy ์ €์ˆ˜์ค€ ์„ค์ •์ด ํ•„์š”ํ•  ๋•Œ ์ œํ•œ์ ์œผ๋กœ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

๋ถˆ๊ฐ€ํ”ผํ•˜๊ฒŒ ์‚ฌ์šฉํ•ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ:

์ƒํ™ฉ์˜ˆ์‹œ
์š”์ฒญ ๋ณธ๋ฌธ ํฌ๊ธฐ ์ œํ•œmax_request_bytes ์„ค์ •
์ปค์Šคํ…€ ํ—ค๋” ์กฐ์ž‘ํŠน์ • ์กฐ๊ฑด์—์„œ๋งŒ ํ—ค๋” ์ถ”๊ฐ€/์‚ญ์ œ
Rate LimitingEnvoy์˜ local/global rate limit ํ•„ํ„ฐ
Lua/WASM ํ”Œ๋Ÿฌ๊ทธ์ธ๋ณต์žกํ•œ ์š”์ฒญ/์‘๋‹ต ๋ณ€ํ™˜ ๋กœ์ง

์ฃผ์˜์‚ฌํ•ญ:

  • ๋ฒ„์ „ ํ˜ธํ™˜์„ฑ: Istio/Envoy ์—…๊ทธ๋ ˆ์ด๋“œ ์‹œ EnvoyFilter๊ฐ€ ๊นจ์งˆ ์ˆ˜ ์žˆ์Œ. ์—…๊ทธ๋ ˆ์ด๋“œ ํ›„ ๋ฐ˜๋“œ์‹œ ํ…Œ์ŠคํŠธ ํ•„์š”
  • Ambient Mode ์ œ์•ฝ: ztunnel์€ Envoy๊ฐ€ ์•„๋‹ˆ๋ฏ€๋กœ EnvoyFilter ์ ์šฉ ๋ถˆ๊ฐ€. Waypoint Proxy์—๋งŒ ์ ์šฉ ๊ฐ€๋Šฅ
  • ๋””๋ฒ„๊น… ์–ด๋ ค์›€: ํ‘œ์ค€ CRD์™€ EnvoyFilter๊ฐ€ ์„ž์ด๋ฉด ๋ฌธ์ œ ์ถ”์ ์ด ๋ณต์žกํ•ด์ง

Helm Charts

Chart์„ค๋ช…
istio-baseIstio CRD ๋ฐ ํด๋Ÿฌ์Šคํ„ฐ ๋ ˆ๋ฒจ ๋ฆฌ์†Œ์Šค ์„ค์น˜
istiod์ปจํŠธ๋กค ํ”Œ๋ ˆ์ธ (istiod) ์„ค์น˜
istio-cniCNI ํ”Œ๋Ÿฌ๊ทธ์ธ - Pod ๋„คํŠธ์›Œํฌ ์„ค์ • ๋‹ด๋‹น
ztunnelAmbient Mode L4 ํ”„๋ก์‹œ DaemonSet
istio-gatewayGateway ๊ตฌํ˜„์ฒด (์™ธ๋ถ€ ํŠธ๋ž˜ํ”ฝ ์ฒ˜๋ฆฌ ์‹œ ํ•„์š”)

Reference

Footnotes

  1. Cross-Namespace Routing โ†ฉ

  2. ReferenceGrant โ†ฉ

  3. Ingress NGINX Retirement: What You Need to Know โ†ฉ