add trust domain to meshconfig#697
Conversation
|
@wattli: changing LGTM is restricted to assignees, and only istio/api repo collaborators may be assigned issues. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
/cc @diemtvu for api owner approval. |
| bool enable_sds_token_mount = 23; | ||
|
|
||
| // The trust domain corresponds to the trust root of a system. | ||
| // Refer to https://github.com/spiffe/spiffe/blob/master/standards/SPIFFE-ID.md#21-trust-domain |
There was a problem hiding this comment.
What's the expected behavior if this is not set?
There was a problem hiding this comment.
add comment // Fallback to old identity format(without trust domain) if not set.
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: diemtvu, quanjielin, wattli The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
istio/istio#9035
later pilot needs to read meshconfig.trustdomain to construct secure naming