Skip to content

Commit b4c9b1e

Browse files
committed
1 parent dfae175 commit b4c9b1e

File tree

903 files changed

+19720
-95865
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

903 files changed

+19720
-95865
lines changed

404.html

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -666,6 +666,8 @@ <h1>找不到页面</h1>
666666
<h2>最新</h2>
667667
<ul>
668668

669+
<li><a href="/blog/ztunnel-security-audit/">Istio 社区公布 ztunnel 安全审计结果,零信任通道通过严格考验</a></li>
670+
669671
<li><a href="/blog/what-are-ai-agents-step-by-step-guide-to-build-your-own/">什么是 AI Agent?简要介绍与构建指南</a></li>
670672

671673
<li><a href="/blog/a-gentle-introduction-to-llms-for-platform-engineers/">平台工程师的 LLM 入门指南</a></li>
@@ -684,8 +686,6 @@ <h2>最新</h2>
684686

685687
<li><a href="/blog/cilium-1-17-0-release-highlights/">Cilium v1.17.0 发布,新特性一览</a></li>
686688

687-
<li><a href="/blog/istio-visibility-troubleshooting/">Istio 可见性与故障排查:监控控制平面的关键指标</a></li>
688-
689689
</ul>
690690

691691

author/maninderjit-mani-bindra/index.xml

Lines changed: 459 additions & 5 deletions
Large diffs are not rendered by default.

author/云原生社区/index.html

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -321,7 +321,7 @@
321321
<meta property="twitter:image" content="https://cloudnativecn.com/author/%E4%BA%91%E5%8E%9F%E7%94%9F%E7%A4%BE%E5%8C%BA/avatar_hu160136486424020243.png" /><meta property="og:locale" content="zh" />
322322

323323

324-
<meta property="og:updated_time" content="2025-03-04T10:22:00&#43;08:00" />
324+
<meta property="og:updated_time" content="2025-04-21T10:31:26&#43;08:00" />
325325

326326

327327

@@ -733,6 +733,10 @@ <h3>云原生社区责任编辑</h3>
733733
<h3>最新</h3>
734734
<ul>
735735

736+
<li>
737+
<a href="/blog/ztunnel-security-audit/">Istio 社区公布 ztunnel 安全审计结果,零信任通道通过严格考验</a>
738+
</li>
739+
736740
<li>
737741
<a href="/blog/istio-1-25-release/">Istio 1.25.0 正式发布:全面增强 Ambient 模式与流量管理</a>
738742
</li>

author/云原生社区/index.xml

Lines changed: 25 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,13 +5,37 @@
55
<link>https://cloudnativecn.com/author/%E4%BA%91%E5%8E%9F%E7%94%9F%E7%A4%BE%E5%8C%BA/</link>
66
<atom:link href="https://cloudnativecn.com/author/%E4%BA%91%E5%8E%9F%E7%94%9F%E7%A4%BE%E5%8C%BA/index.xml" rel="self" type="application/rss+xml" />
77
<description>云原生社区</description>
8-
<generator>Wowchemy (https://wowchemy.com)</generator><language>zh</language><lastBuildDate>Tue, 04 Mar 2025 10:22:00 +0800</lastBuildDate>
8+
<generator>Wowchemy (https://wowchemy.com)</generator><language>zh</language><lastBuildDate>Mon, 21 Apr 2025 10:31:26 +0800</lastBuildDate>
99
<image>
1010
<url>https://cloudnativecn.com/author/%E4%BA%91%E5%8E%9F%E7%94%9F%E7%A4%BE%E5%8C%BA/avatar_hu160136486424020243.png</url>
1111
<title>云原生社区</title>
1212
<link>https://cloudnativecn.com/author/%E4%BA%91%E5%8E%9F%E7%94%9F%E7%A4%BE%E5%8C%BA/</link>
1313
</image>
1414

15+
<item>
16+
<title>Istio 社区公布 ztunnel 安全审计结果,零信任通道通过严格考验</title>
17+
<link>https://cloudnativecn.com/blog/ztunnel-security-audit/</link>
18+
<pubDate>Mon, 21 Apr 2025 10:31:26 +0800</pubDate>
19+
<guid>https://cloudnativecn.com/blog/ztunnel-security-audit/</guid>
20+
<description>&lt;p&gt;近日,Istio 项目安全工作组正式发布了其 Ambient 模式核心组件 &lt;a href=&#34;https://istio.io/latest/blog/2025/ztunnel-security-assessment/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;ztunnel 的安全审计报告&lt;/a&gt;,结果令人振奋:&lt;strong&gt;代码未发现任何漏洞,审计结果为“高度可信”&lt;/strong&gt;&lt;/p&gt;
21+
&lt;p&gt;ztunnel 是 Istio 在 Ambient 模式下用于构建零信任网络的新型轻量级数据平面组件,由 Rust 编写,旨在提供更高性能、更易部署的 L4 连接安全能力。此前,Istio 已展示了 ztunnel 在性能方面的卓越表现,&lt;strong&gt;其 TCP 吞吐量甚至超过内核级方案 IPsec 和 WireGuard&lt;/strong&gt;,并在过去四个版本中性能提升高达 75%。而本次安全审计,则进一步印证了其在安全性方面的可用性与稳定性。&lt;/p&gt;
22+
&lt;h2 id=&#34;三方审计机构确认代码安全可靠&#34;&gt;三方审计机构确认代码安全可靠&lt;/h2&gt;
23+
&lt;p&gt;此次审计由知名安全公司 &lt;a href=&#34;https://www.trailofbits.com/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Trail of Bits&lt;/a&gt; 执行,审计内容覆盖了 ztunnel 的 L4 授权、TLS 传输安全、证书管理、入站代理等关键路径。值得注意的是,此次审计聚焦于 Ambient 模式中新引入的 Rust 代码,并未重复审查已接受过多次审计的 Envoy 本体部分。&lt;/p&gt;
24+
&lt;p&gt;审计报告明确指出:&lt;strong&gt;“ztunnel 代码结构良好,未发现任何漏洞。”&lt;/strong&gt; 三项审计意见中,仅有一项中等级别问题,其他为信息类建议,且均与依赖项管理和测试策略相关。&lt;/p&gt;
25+
&lt;p&gt;本次审计工作由 &lt;a href=&#34;https://www.cncf.io/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;CNCF 基金会&lt;/a&gt; 提供资助,&lt;a href=&#34;https://ostif.org/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;OSTIF&lt;/a&gt; 协调执行。这也体现出 Istio 社区在安全方面的开放态度和持续投入。&lt;/p&gt;
26+
&lt;h2 id=&#34;安全建议与改进措施&#34;&gt;安全建议与改进措施&lt;/h2&gt;
27+
&lt;h3 id=&#34;引入自动化依赖管理工具&#34;&gt;引入自动化依赖管理工具&lt;/h3&gt;
28+
&lt;p&gt;审计期间,ztunnel 的依赖项中存在三项已知安全通报的库版本,尽管不会直接触发漏洞,但社区仍采取主动响应,&lt;strong&gt;引入 GitHub Dependabot 自动更新依赖项&lt;/strong&gt;,并替换了两项维护状态不佳的 Rust crates。&lt;/p&gt;
29+
&lt;h3 id=&#34;加强异常路径测试覆盖&#34;&gt;加强异常路径测试覆盖&lt;/h3&gt;
30+
&lt;p&gt;Trail of Bits 指出部分异常处理路径未涵盖在现有测试中。Istio 社区回应称,这些路径多为非关键逻辑,如日志行为或性能路径,&lt;strong&gt;将通过 mutation testing 与新型测试机制持续完善测试覆盖&lt;/strong&gt;&lt;/p&gt;
31+
&lt;h3 id=&#34;自研-header-解析器提升健壮性&#34;&gt;自研 Header 解析器提升健壮性&lt;/h3&gt;
32+
&lt;p&gt;ztunnel 原先使用的 HTTP &lt;code&gt;Forwarded&lt;/code&gt; header 解析库未经过 fuzz 测试。社区为此 &lt;strong&gt;专门开发了定制化解析器,并引入 fuzzing 测试机制&lt;/strong&gt;,确保 Header 解析的安全性与稳定性。&lt;/p&gt;
33+
&lt;h2 id=&#34;云原生服务网格迈入更安全的未来&#34;&gt;云原生服务网格迈入更安全的未来&lt;/h2&gt;
34+
&lt;p&gt;ztunnel 是 Istio 社区拥抱 Rust 安全生态、构建可插拔数据面架构的重要一步。其简化的部署模式、卓越的性能表现,以及经受审计验证的安全性,正在为 Istio Ambient 模式铺设坚实的技术基础。&lt;/p&gt;
35+
&lt;p&gt;随着社区对零信任架构、性能优化、安全可观测等维度的持续打磨,&lt;strong&gt;ztunnel 将成为 Kubernetes 云原生网络中值得信赖的通用安全入口组件&lt;/strong&gt;&lt;/p&gt;
36+
</description>
37+
</item>
38+
1539
<item>
1640
<title>Istio 1.25.0 正式发布:全面增强 Ambient 模式与流量管理</title>
1741
<link>https://cloudnativecn.com/blog/istio-1-25-release/</link>

authors/index.html

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -688,6 +688,9 @@ <h1></h1>
688688

689689

690690

691+
<li><a href="https://cloudnativecn.com/author/%E4%BA%91%E5%8E%9F%E7%94%9F%E7%A4%BE%E5%8C%BA/">云原生社区</a></li>
692+
693+
691694
<li><a href="https://cloudnativecn.com/author/maximilian-vogel/">Maximilian Vogel</a></li>
692695

693696

@@ -703,9 +706,6 @@ <h1></h1>
703706
<li><a href="https://cloudnativecn.com/author/kensei-nakada/">Kensei Nakada</a></li>
704707

705708

706-
<li><a href="https://cloudnativecn.com/author/%E4%BA%91%E5%8E%9F%E7%94%9F%E7%A4%BE%E5%8C%BA/">云原生社区</a></li>
707-
708-
709709
<li><a href="https://cloudnativecn.com/author/ric-hincapie/">Ric Hincapié</a></li>
710710

711711

blog/201905-servicemesh-development-trend/index.html

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -322,7 +322,7 @@
322322
content="2019-05-28T07:15:43&#43;08:00"
323323
/>
324324

325-
<meta property="article:modified_time" content="2025-04-18T02:30:13&#43;00:00">
325+
<meta property="article:modified_time" content="2025-04-21T10:51:03&#43;08:00">
326326

327327

328328

@@ -351,7 +351,7 @@
351351
"headline": "Service Mesh 发展趋势:云原生中流砥柱",
352352

353353
"datePublished": "2019-05-28T07:15:43+08:00",
354-
"dateModified": "2025-04-18T02:30:13Z",
354+
"dateModified": "2025-04-21T10:51:03+08:00",
355355

356356
"author": {
357357
"@type": "Person",

blog/201909-build-full-micro-service-platform-by-spring-boot-with-kubernetes/index.html

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -322,7 +322,7 @@
322322
content="2019-09-02T07:15:43&#43;08:00"
323323
/>
324324

325-
<meta property="article:modified_time" content="2025-04-18T02:30:13&#43;00:00">
325+
<meta property="article:modified_time" content="2025-04-21T10:51:03&#43;08:00">
326326

327327

328328

@@ -351,7 +351,7 @@
351351
"headline": "使用 spring boot+kubernetes 构建完整微服务平台",
352352

353353
"datePublished": "2019-09-02T07:15:43+08:00",
354-
"dateModified": "2025-04-18T02:30:13Z",
354+
"dateModified": "2025-04-21T10:51:03+08:00",
355355

356356
"author": {
357357
"@type": "Person",

blog/202002-network-service-mesh/index.html

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -322,7 +322,7 @@
322322
content="2020-02-15T10:57:00&#43;08:00"
323323
/>
324324

325-
<meta property="article:modified_time" content="2025-04-18T02:30:13&#43;00:00">
325+
<meta property="article:modified_time" content="2025-04-21T10:51:03&#43;08:00">
326326

327327

328328

@@ -351,7 +351,7 @@
351351
"headline": "NFV 走向云原生时代:Network Service Mesh 项目介绍",
352352

353353
"datePublished": "2020-02-15T10:57:00+08:00",
354-
"dateModified": "2025-04-18T02:30:13Z",
354+
"dateModified": "2025-04-21T10:51:03+08:00",
355355

356356
"author": {
357357
"@type": "Person",

blog/202003-gitops-progressive-delivery-with-asm/index.html

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -322,7 +322,7 @@
322322
content="2020-03-19T14:08:21&#43;08:00"
323323
/>
324324

325-
<meta property="article:modified_time" content="2025-04-18T02:30:13&#43;00:00">
325+
<meta property="article:modified_time" content="2025-04-21T10:51:03&#43;08:00">
326326

327327

328328

@@ -351,7 +351,7 @@
351351
"headline": "使用托管服务网格实现应用在多集群中的 GitOps 全自动化渐进式发布",
352352

353353
"datePublished": "2020-03-19T14:08:21+08:00",
354-
"dateModified": "2025-04-18T02:30:13Z",
354+
"dateModified": "2025-04-21T10:51:03+08:00",
355355

356356
"author": {
357357
"@type": "Person",

blog/202003-k8s-scheduling-framework/index.html

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -322,7 +322,7 @@
322322
content="2020-03-16T07:16:13&#43;08:00"
323323
/>
324324

325-
<meta property="article:modified_time" content="2025-04-18T02:30:13&#43;00:00">
325+
<meta property="article:modified_time" content="2025-04-21T10:51:03&#43;08:00">
326326

327327

328328

@@ -351,7 +351,7 @@
351351
"headline": "浅谈 Kubernetes Scheduling-Framework 插件的实现",
352352

353353
"datePublished": "2020-03-16T07:16:13+08:00",
354-
"dateModified": "2025-04-18T02:30:13Z",
354+
"dateModified": "2025-04-21T10:51:03+08:00",
355355

356356
"author": {
357357
"@type": "Person",

0 commit comments

Comments
 (0)