tl;dr Can Istio do proxy resolution at mesh level? I want to be able to avoid defining HTTPS_PROXY in my service container.
Here is the setup:
- My enterprise has an AKS cluster
- In the AKS cluster we have Istio up and running.
- Kubernetes Version 1.22.6
- Istio Version 1.14.1
- My service is running inside AKS and my pod has sidecar injection enabled.
SCENARIO:
- My service needs to access two external services -
www.google.comandsecured.my-enterprise.com. secured.my-enterprise.comis a service that is running in a private network on enterprise premises, NOT on Azure Cloud.- The only way to access
secured.my-enterprise.comis to specify an HTTPS_PROXY which points toproxy.enterprise-proxy.svc.cluster.local. - This proxy (running inside AKS) knows how to get requests from AKS to on-premise infrastructure, navigating all the fancy network peering.
- I dont however need the HTTPS_PROXY to access
www.google.com. - Currently I am solving this problem the usual way - with NO_PROXY .google.com.
What I would like to be able to do:
- Define a Virtual Service / Service Entry for host:
www.google.comand egress out of AKS. - Define a Virtual Service / Service Entry for host:
secured.my-enterprise.com, definingproxy.enterprise-proxy.svc.cluster.localas the HTTPS_PROXY to use for it, and egress out of AKS.
What would I achieve with this? My service does not have to manage a NO_PROXY based on what it needs to do, and the service mesh can handle figuring out how to reach an external resource.
Is there something in the Istio toolset that can help me achieve this?
I have gone through Service Entry documentation and can't for the life of me understand how to add a proxy into the mix :)
Thanks!!
PS: Created a topic for this on discuss.istio.io as well