Skip to content

Allow configurable trust domain in Istio identities #8661

@elevran

Description

@elevran

Describe the feature request
Allow use of configurable domain in Istio identities.

Describe alternatives you've considered
currently all identities are hard coded to use the cluster.local domain.

Additional context
#7849 has initial work in Citadel, but needs further work in other components:

  • add option support in Helm charts (incl istio-remote)
  • changes in istioctl to kube-inject verify_subject_alt_name (e.g., here)
  • change hard coded places, except tests
  • collect identity related items into a new package (e.g., security/pkg/identity) to avoid duplication

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions