Istio - default ssl certificate to work with Azure Front Door

Viewed 459

For nginx ingress, there is a way to define default-ssl-certificate with --default-ssl-certificate flag.

Ref: https://kubernetes.github.io/ingress-nginx/user-guide/tls/#default-ssl-certificate

How can I do the same for istio?

I have assigned tls.credentialName in istio gateway. But, it's not the same as nginx-ingress default-ssl-certificate.

istio_gateway.yaml

---
apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
name: SERVICE_GATEWAY
spec:
  selector:
    istio: ingressgateway # Use Istio default gateway implementation
  servers:
  - port:
      name: SERVICE_NAME-http-80
      number: 80
      protocol: HTTP
    hosts:
    - "SERVICE_DNS"
  - port:
      name: SERVICE_NAME-https-443
      number: 443
      protocol: HTTPS
    tls:
      credentialName: SERVICE_CRT
      mode: SIMPLE
      minProtocolVersion: TLSV1_2
    hosts:
    - "SERVICE_DNS"

VirtualService:

---
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: SERVICE_NAME
spec:
  hosts:
  - SERVICE_DNS
  gateways:
  - SERVICE_GATEWAY
  http:
  - match:
    - uri:
        prefix: /
    route:
    - destination:
        port:
          number: SERVICE_PORT
        host: "SERVICE_NAME.default.svc.cluster.local"

This setup is working for nginx-ingress: https://ssbkang.com/2020/08/17/end-to-end-tls-for-azure-front-door-and-azure-kubernetes-service/ I want to do the same thing with istio.

0 Answers
Related