Securing Egress Traffic with kgateway, Istio Ambient Mesh, and Kyverno: LFX Mentorship Blog#453
Conversation
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Outdated
Show resolved
Hide resolved
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
|
Made some changes, Let me know if we should change anything else! |
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
| kubectl apply --server-side -f https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.4.0/experimental-install.yaml | ||
| ``` | ||
| 4. Follow the [Get started guide](https://kgateway.dev/docs/latest/quickstart/) to install kgateway. | ||
| 5. Follow the [Sample app guide](https://kgateway.dev/docs/latest/install/sample-app/) to create a gateway proxy with an HTTP listener and deploy the httpbin sample app. |
There was a problem hiding this comment.
I think ServiceEntries aren't supported for agentgateway yet, so let's call out you can also use agentgateway for more advanced LLM routing use-cases. I guess we could also change the example in this blog to not use ollama (and use a simple httpbin example instead), then in the next blog use ollama with the AI Backend type and agentgateway.
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
content/blog/egress-traffic-with-kgateway-and-Istio-integration.md
Outdated
Show resolved
Hide resolved
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Outdated
Show resolved
Hide resolved
| [Demo](https://youtu.be/5PegECeu0v0) | ||
|
|
||
|
|
||
| {{< youtube 5PegECeu0v0 >}} |
There was a problem hiding this comment.
not sure if we typically mention other relevant blogs that people can explore??
There was a problem hiding this comment.
I think we can upload the video to the kgateway youtube! @linsun do you have permissions for the youtube account?
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Show resolved
Hide resolved
npolshakova
left a comment
There was a problem hiding this comment.
Blog looks great! Let's update the title and then I think it's good from my end!
| @@ -0,0 +1,462 @@ | |||
| --- | |||
| title: "Securing Egress Traffic with kgateway, Istio Ambient Mesh, and Kyverno: LFX Mentorship Blog" | |||
| toc: | |||
There was a problem hiding this comment.
I think this will need a publishDate to show up on the blog page! See this example:
artberger
left a comment
There was a problem hiding this comment.
Thanks for writing up your experiences. Overall, it looks good. Nina's comment about the publishDate needs to be addressed so that it shows up.
Style-wise, I left some non-blocking comments that would apply throughout. We typically prefer second-person you (not first-person we), active over passive verbs, and non-positional language (previous or following instead of above or below). But because this is a blog, we can be more flexible, so I will approve.
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Outdated
Show resolved
Hide resolved
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Outdated
Show resolved
Hide resolved
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Outdated
Show resolved
Hide resolved
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Outdated
Show resolved
Hide resolved
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Outdated
Show resolved
Hide resolved
...g/securing-egress-traffic-with-kgateway-istio-ambien-mesh-and-kyverno-lfx-mentorship-blog.md
Outdated
Show resolved
Hide resolved
eff4d92 to
a77fa58
Compare
a77fa58 to
35915f0
Compare
Signed-off-by: Aryan Parashar <aryanparashar24@gmail.com>
Description
This pull request adds a new Security blog post introducing the integration of
kgatewaywith Istio Ambient Mesh, focusing on managing egress traffic and the benefits of a sidecar-less data plane. The post outlines the architecture, advantages, and policy management capabilities ofkgatewaywithin Istio's ambient mesh environment.Change Logs
New blog post on Istio Ambient Mesh and kgateway:
content/blog/egress-traffic-with-kgateway-and-Istio-integration.mdwith an overview of Ambient Mesh, its separation of L4 and L7 layers, and howkgatewayintegrates as a pluggable waypoint for Istio.kgatewaysuch as shared observability and unified configuration.Summary
This blog post discusses the integration of kgateway with Istio, highlighting its benefits, features, and how it manages egress traffic effectively. It covers the differences between Layer 4 and Layer 7 authorization policies and provides insights into the advantages of using kgateway in various scenarios.