Skip to content

Commit 02f9d8d

Browse files
committed
1 parent 37d4855 commit 02f9d8d

File tree

868 files changed

+97878
-13923
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

868 files changed

+97878
-13923
lines changed

404.html

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -754,6 +754,8 @@ <h1>找不到页面</h1>
754754
<h2>最新</h2>
755755
<ul>
756756

757+
<li><a href="/blog/istio-1-25-release/">Istio 1.25.0 正式发布:全面增强 Ambient 模式与流量管理</a></li>
758+
757759
<li><a href="/blog/envoy-gateway-1-3-release-highlights/">Envoy Gateway 1.3 发布:增强安全性、流量管理和运维能力</a></li>
758760

759761
<li><a href="/blog/cilium-1-17-0-release-highlights/">Cilium v1.17.0 发布,新特性一览</a></li>
@@ -772,8 +774,6 @@ <h2>最新</h2>
772774

773775
<li><a href="/blog/migrating-from-aws-app-mesh-to-amazon-ecs-service-connect/">AWS 宣布将停用 App Mesh,鼓励用户迁移至 Amazon ECS Service Connect</a></li>
774776

775-
<li><a href="/blog/istio-aws-private-ca/">如何将 Istio 与 AWS 私有证书颁发机构(Private CA)无缝集成</a></li>
776-
777777
</ul>
778778

779779

author/christina-の-j-老闆/index.xml

Lines changed: 5 additions & 303 deletions
Large diffs are not rendered by default.

author/maninderjit-mani-bindra/index.xml

Lines changed: 459 additions & 5 deletions
Large diffs are not rendered by default.

author/云原生社区/index.html

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -321,7 +321,7 @@
321321
<meta property="twitter:image" content="https://cloudnativecn.com/author/%E4%BA%91%E5%8E%9F%E7%94%9F%E7%A4%BE%E5%8C%BA/avatar_hu160136486424020243.png" /><meta property="og:locale" content="zh" />
322322

323323

324-
<meta property="og:updated_time" content="2025-02-05T15:22:42&#43;08:00" />
324+
<meta property="og:updated_time" content="2025-03-04T10:22:00&#43;08:00" />
325325

326326

327327

@@ -821,6 +821,10 @@ <h3>云原生社区责任编辑</h3>
821821
<h3>最新</h3>
822822
<ul>
823823

824+
<li>
825+
<a href="/blog/istio-1-25-release/">Istio 1.25.0 正式发布:全面增强 Ambient 模式与流量管理</a>
826+
</li>
827+
824828
<li>
825829
<a href="/blog/cilium-1-17-0-release-highlights/">Cilium v1.17.0 发布,新特性一览</a>
826830
</li>

author/云原生社区/index.xml

Lines changed: 40 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,13 +5,52 @@
55
<link>https://cloudnativecn.com/author/%E4%BA%91%E5%8E%9F%E7%94%9F%E7%A4%BE%E5%8C%BA/</link>
66
<atom:link href="https://cloudnativecn.com/author/%E4%BA%91%E5%8E%9F%E7%94%9F%E7%A4%BE%E5%8C%BA/index.xml" rel="self" type="application/rss+xml" />
77
<description>云原生社区</description>
8-
<generator>Wowchemy (https://wowchemy.com)</generator><language>zh</language><lastBuildDate>Wed, 05 Feb 2025 15:22:42 +0800</lastBuildDate>
8+
<generator>Wowchemy (https://wowchemy.com)</generator><language>zh</language><lastBuildDate>Tue, 04 Mar 2025 10:22:00 +0800</lastBuildDate>
99
<image>
1010
<url>https://cloudnativecn.com/author/%E4%BA%91%E5%8E%9F%E7%94%9F%E7%A4%BE%E5%8C%BA/avatar_hu160136486424020243.png</url>
1111
<title>云原生社区</title>
1212
<link>https://cloudnativecn.com/author/%E4%BA%91%E5%8E%9F%E7%94%9F%E7%A4%BE%E5%8C%BA/</link>
1313
</image>
1414

15+
<item>
16+
<title>Istio 1.25.0 正式发布:全面增强 Ambient 模式与流量管理</title>
17+
<link>https://cloudnativecn.com/blog/istio-1-25-release/</link>
18+
<pubDate>Tue, 04 Mar 2025 10:22:00 +0800</pubDate>
19+
<guid>https://cloudnativecn.com/blog/istio-1-25-release/</guid>
20+
<description>&lt;p&gt;Istio 1.25.0 现已正式发布,并全面支持 Kubernetes &lt;code&gt;1.29&lt;/code&gt;&lt;code&gt;1.32&lt;/code&gt; 版本。此次更新带来了多个关键改进,特别是在 Ambient 模式、流量管理和 DNS 代理等方面。你可以在 &lt;a href=&#34;https://istio.io/latest/news/releases/1.25.x/announcing-1.25/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Istio 官网&lt;/a&gt;查看详情。&lt;/p&gt;
21+
&lt;h2 id=&#34;主要更新亮点&#34;&gt;主要更新亮点&lt;/h2&gt;
22+
&lt;h3 id=&#34;1-默认启用-dns-代理增强-ambient-模式支持&#34;&gt;1. 默认启用 DNS 代理,增强 Ambient 模式支持&lt;/h3&gt;
23+
&lt;p&gt;Istio 传统上依赖 HTTP 头进行流量路由。然而,在 Ambient 模式下,ztunnel 仅能处理四层(L4)流量,而无法访问 HTTP 头部信息。因此,DNS 代理对于解析 &lt;code&gt;ServiceEntry&lt;/code&gt; 地址至关重要,尤其是在&lt;a href=&#34;https://github.com/istio/istio/wiki/Troubleshooting-Istio-Ambient#scenario-ztunnel-is-not-sending-egress-traffic-to-waypoints&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;发送出口流量到 Waypoint&lt;/a&gt; 的场景下。&lt;/p&gt;
24+
&lt;p&gt;在 Istio 1.25 版本中,Ambient 模式默认开启 DNS 代理,并支持工作负载通过注解选择退出该功能。更多信息请参考&lt;a href=&#34;https://istio.io/latest/news/releases/1.25.x/announcing-1.25/upgrade-notes/#ambient-mode-dns-capture-on-by-default&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;升级说明&lt;/a&gt;&lt;/p&gt;
25+
&lt;h3 id=&#34;2-waypoint-代理支持默认拒绝策略default-deny&#34;&gt;2. Waypoint 代理支持默认拒绝策略(default deny)&lt;/h3&gt;
26+
&lt;p&gt;在 Sidecar 模式下,授权策略(Authorization Policy)通常通过 &lt;code&gt;selector&lt;/code&gt; 绑定到特定工作负载。在 Ambient 模式中,原先 &lt;code&gt;selector&lt;/code&gt; 绑定的策略仅在 ztunnel 层执行,而 Waypoint 代理则使用 &lt;code&gt;targetRef&lt;/code&gt; 进行绑定。这可能导致某些情况下,默认被拒绝访问某个端点的工作负载,能够通过连接到 Waypoint 绕过该限制。&lt;/p&gt;
27+
&lt;p&gt;Istio 1.25 版本增加了对 &lt;code&gt;GatewayClass&lt;/code&gt;&lt;code&gt;Gateway&lt;/code&gt; 目标策略的支持,使管理员能够在 &lt;code&gt;istio-waypoint&lt;/code&gt; 级别定义策略,从而适用于所有 Waypoint 实例。&lt;/p&gt;
28+
&lt;h3 id=&#34;3-增强区域zonal路由能力&#34;&gt;3. 增强区域(Zonal)路由能力&lt;/h3&gt;
29+
&lt;p&gt;跨区域(zone)和跨地域(region)的流量控制对于企业级用户至关重要,尤其是出于可靠性、性能和成本的考虑。Istio 1.25 版本增强了区域路由能力,提供了更简单的流量控制选项:&lt;/p&gt;
30+
&lt;ul&gt;
31+
&lt;li&gt;&lt;strong&gt;全面支持 Kubernetes 原生流量分发机制&lt;/strong&gt;,提供更简洁的接口以保持流量本地化。&lt;/li&gt;
32+
&lt;li&gt;&lt;strong&gt;增强 Istio 本地负载均衡(Locality Load Balancing)&lt;/strong&gt;,适用于更复杂的流量分发场景。&lt;/li&gt;
33+
&lt;li&gt;&lt;strong&gt;在 Ambient 模式下,ztunnel 现支持 &lt;code&gt;source_zone&lt;/code&gt;&lt;code&gt;source_region&lt;/code&gt;&lt;code&gt;destination_zone&lt;/code&gt;&lt;code&gt;destination_region&lt;/code&gt; 额外指标&lt;/strong&gt;,使跨区域流量的可观测性更清晰。&lt;/li&gt;
34+
&lt;/ul&gt;
35+
&lt;h3 id=&#34;4-其他新增特性与优化&#34;&gt;4. 其他新增特性与优化&lt;/h3&gt;
36+
&lt;ul&gt;
37+
&lt;li&gt;&lt;strong&gt;新增支持虚拟接口流量转发&lt;/strong&gt;:允许工作负载指定一组虚拟接口,使其入站流量被视为出站流量。这对于 KubeVirt、VMs 及 Docker-in-Docker 场景尤为重要。&lt;/li&gt;
38+
&lt;li&gt;&lt;strong&gt;istio-cni DaemonSet 支持原地升级&lt;/strong&gt;:升级 &lt;code&gt;istio-cni&lt;/code&gt; DaemonSet 时,不再需要对节点进行 Cordon 操作,以防止新创建的 Pod 逃避 Ambient 模式的流量捕获。&lt;/li&gt;
39+
&lt;/ul&gt;
40+
&lt;h2 id=&#34;兼容性与升级指南&#34;&gt;兼容性与升级指南&lt;/h2&gt;
41+
&lt;p&gt;如果你计划从 Istio 1.24.x 升级至 Istio 1.25.x,请注意以下关键变更:&lt;/p&gt;
42+
&lt;ol&gt;
43+
&lt;li&gt;&lt;strong&gt;Ambient 模式的 Pod 需要手动重启或启用 &lt;code&gt;istio-cni&lt;/code&gt; 规则同步&lt;/strong&gt;,以确保 DNS 代理正常生效。&lt;/li&gt;
44+
&lt;li&gt;&lt;strong&gt;DNS 代理默认启用&lt;/strong&gt;,若有特殊需求,可在 Pod 级别使用 &lt;code&gt;ambient.istio.io/dns-capture=false&lt;/code&gt; 注解选择退出。&lt;/li&gt;
45+
&lt;li&gt;&lt;strong&gt;Grafana 监控面板升级至 7.2 以上版本&lt;/strong&gt;,以支持新的指标展示。&lt;/li&gt;
46+
&lt;li&gt;&lt;strong&gt;移除 OpenCensus 支持&lt;/strong&gt;,建议迁移至 OpenTelemetry。&lt;/li&gt;
47+
&lt;/ol&gt;
48+
&lt;p&gt;更多升级细节请参考&lt;a href=&#34;https://istio.io/latest/news/releases/1.25.x/announcing-1.25/upgrade-notes/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;官方升级说明&lt;/a&gt;&lt;/p&gt;
49+
&lt;h2 id=&#34;结语&#34;&gt;结语&lt;/h2&gt;
50+
&lt;p&gt;Istio 1.25 版本在 Ambient 模式、流量管理、DNS 代理等多个方面进行了重要增强,进一步优化了服务网格的可用性和易用性。&lt;/p&gt;
51+
</description>
52+
</item>
53+
1554
<item>
1655
<title>Cilium v1.17.0 发布,新特性一览</title>
1756
<link>https://cloudnativecn.com/blog/cilium-1-17-0-release-highlights/</link>

blog/201905-servicemesh-development-trend/index.html

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -322,7 +322,7 @@
322322
content="2019-05-28T07:15:43&#43;08:00"
323323
/>
324324

325-
<meta property="article:modified_time" content="2025-02-06T17:02:10&#43;08:00">
325+
<meta property="article:modified_time" content="2025-03-04T10:47:55&#43;08:00">
326326

327327

328328

@@ -351,7 +351,7 @@
351351
"headline": "Service Mesh 发展趋势:云原生中流砥柱",
352352

353353
"datePublished": "2019-05-28T07:15:43+08:00",
354-
"dateModified": "2025-02-06T17:02:10+08:00",
354+
"dateModified": "2025-03-04T10:47:55+08:00",
355355

356356
"author": {
357357
"@type": "Person",

blog/201909-build-full-micro-service-platform-by-spring-boot-with-kubernetes/index.html

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -322,7 +322,7 @@
322322
content="2019-09-02T07:15:43&#43;08:00"
323323
/>
324324

325-
<meta property="article:modified_time" content="2025-02-06T17:02:10&#43;08:00">
325+
<meta property="article:modified_time" content="2025-03-04T10:47:55&#43;08:00">
326326

327327

328328

@@ -351,7 +351,7 @@
351351
"headline": "使用 spring boot+kubernetes 构建完整微服务平台",
352352

353353
"datePublished": "2019-09-02T07:15:43+08:00",
354-
"dateModified": "2025-02-06T17:02:10+08:00",
354+
"dateModified": "2025-03-04T10:47:55+08:00",
355355

356356
"author": {
357357
"@type": "Person",

blog/202002-network-service-mesh/index.html

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -322,7 +322,7 @@
322322
content="2020-02-15T10:57:00&#43;08:00"
323323
/>
324324

325-
<meta property="article:modified_time" content="2025-02-06T17:02:10&#43;08:00">
325+
<meta property="article:modified_time" content="2025-03-04T10:47:55&#43;08:00">
326326

327327

328328

@@ -351,7 +351,7 @@
351351
"headline": "NFV 走向云原生时代:Network Service Mesh 项目介绍",
352352

353353
"datePublished": "2020-02-15T10:57:00+08:00",
354-
"dateModified": "2025-02-06T17:02:10+08:00",
354+
"dateModified": "2025-03-04T10:47:55+08:00",
355355

356356
"author": {
357357
"@type": "Person",

blog/202003-gitops-progressive-delivery-with-asm/index.html

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -322,7 +322,7 @@
322322
content="2020-03-19T14:08:21&#43;08:00"
323323
/>
324324

325-
<meta property="article:modified_time" content="2025-02-06T17:02:10&#43;08:00">
325+
<meta property="article:modified_time" content="2025-03-04T10:47:55&#43;08:00">
326326

327327

328328

@@ -351,7 +351,7 @@
351351
"headline": "使用托管服务网格实现应用在多集群中的 GitOps 全自动化渐进式发布",
352352

353353
"datePublished": "2020-03-19T14:08:21+08:00",
354-
"dateModified": "2025-02-06T17:02:10+08:00",
354+
"dateModified": "2025-03-04T10:47:55+08:00",
355355

356356
"author": {
357357
"@type": "Person",

blog/202003-k8s-scheduling-framework/index.html

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -322,7 +322,7 @@
322322
content="2020-03-16T07:16:13&#43;08:00"
323323
/>
324324

325-
<meta property="article:modified_time" content="2025-02-06T17:02:10&#43;08:00">
325+
<meta property="article:modified_time" content="2025-03-04T10:47:55&#43;08:00">
326326

327327

328328

@@ -351,7 +351,7 @@
351351
"headline": "浅谈 Kubernetes Scheduling-Framework 插件的实现",
352352

353353
"datePublished": "2020-03-16T07:16:13+08:00",
354-
"dateModified": "2025-02-06T17:02:10+08:00",
354+
"dateModified": "2025-03-04T10:47:55+08:00",
355355

356356
"author": {
357357
"@type": "Person",

0 commit comments

Comments
 (0)