What is the purpose of a VirtualService when defining an wildcard ServiceEntry in Istio?

Viewed 1538

The Istio documentation gives an example of configuring egress using a wildcard ServiceEntry here.

apiVersion: networking.istio.io/v1alpha3
kind: ServiceEntry
metadata:
  name: wikipedia
spec:
  hosts:
  - "*.wikipedia.org"
  ports:
  - number: 443
    name: tls
    protocol: TLS
---
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: wikipedia
spec:
  hosts:
  - "*.wikipedia.org"
  tls:
  - match:
    - port: 443
      sniHosts:
      - "*.wikipedia.org"
    route:
    - destination:
        host: "*.wikipedia.org"
        port:
          number: 443

What benefit/difference does the VirtualService give? If I remove the VirtualService nothing seems to be affected. I am using Istio 1.6.0

1 Answers

The VirtualService is not really doing anything, but if you take a look at this or this istio docs.

creating a VirtualService with a default route for every service, right from the start, is generally considered a best practice in Istio.

Virtual services play a key role in making Istio’s traffic management flexible and powerful. They do this by strongly decoupling where clients send their requests from the destination workloads that actually implement them. Virtual services also provide a rich way of specifying different traffic routing rules for sending traffic to those workloads.

Service Entry adds those wikipedia sites as an entry to istio internal service registry, so auto-discovered services in the mesh can route to these manually specified services.

Usually that's used to allow monitoring and other Istio features of external services from the start, when the Virtual Service would allow the proper routing of request.


Take a look at this istio documentation.

Service Entry makes sure your mesh knows about the service and can monitor it.

Using Istio ServiceEntry configurations, you can access any publicly accessible service from within your Istio cluster.

Virtual Service manage traffic to external services and controls traffic which go to the service, which in this case is all of it.


I would say the benefit is that, you can use istio routing rules, which can also be set for external services that are accessed using Service Entry configurations. In this example, you set a timeout rule on calls to the httpbin.org service.

Related