Uploaded image for project: 'OpenShift Service Mesh'
  1. OpenShift Service Mesh
  2. OSSM-2338

Federation deployment does not need router mode sni-dnat


    • Icon: Task Task
    • Resolution: Done
    • Icon: Undefined Undefined
    • OSSM 2.2.5, OSSM 2.3.1
    • OSSM 2.1.0
    • Maistra
    • None
    • Sprint 61

      In our documentation we create ingress and egress gateways for federated traffic with "routerMode: sni-dnat", but we don't use AUTO_PASSTHROUGH mode to route traffic, between federated meshes, so it never was needed. What's more, environment variable "ISTIO_META_ROUTER_MODE" is ignored since Istio 1.11, look at this PR: https://github.com/istio/istio/pull/33129.

      We should remove this setting from the documentation, samples and tests.

      We use AUTO_PASSTHROUGH when Mesh.Spec.Security.AllowDirectInbound is set in ServiceMeshPeer. It will not work as a comment says, but it's better to not change it in maistra-2.1.

            jewertow@redhat.com Jacek Ewertowski
            jewertow@redhat.com Jacek Ewertowski
            0 Vote for this issue
            2 Start watching this issue
