You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Multicluster has been one of the most requested ambient features — and as of Istio 1.27, it's now available.
9
+
Multicluster has been one of the most requested ambient features — and as of Istio 1.27, it is available in alpha status!
10
10
We sought to capture the benefits and avoid the complications of multicluster architectures using the same modular design that ambient users love.
11
11
While still in alpha, this release delivers the core functionality of a multicluster mesh and lays the groundwork for a full feature set in upcoming releases.
12
12
13
-
## Multicluster's Many Benefits (and Challenges)
13
+
## The Power & Complexity of Multicluster
14
14
15
-
Multicluster architectures increase outage resilience, shrink the blast radii,
15
+
Multicluster architectures increase outage resilience, shrink your blast radius,
16
16
ease adoption of data residence policies, and simplify cost tracking.
17
-
That said, integrating multiple clusters poses connectivity, security, and operation hurdles.
17
+
That said, connecting multiple clusters poses connectivity, security, and operational challenges.
18
18
19
19
In a single Kubernetes cluster, every pod can directly connect to another pod via a unique pod IP or service VIP.
20
20
We lose these guarantees when we start thinking of multicluster architectures.
21
21
IP address spaces of different clusters might overlap.
22
-
Even if they didn't, nodes in one cluster would not know how to route traffic from one cluster to another.
22
+
Even if they didn't, nodes in one cluster may not know how to route traffic from one cluster to another (depending on how the underlying infrastructure is configured)
23
23
24
24
Establishing cross-cluster connectivity also presents security challenges.
25
25
Cross-cluster connectivity means that pod-to-pod traffic can leave cluster boundaries -- and that pods may accept connections from outside the cluster.
@@ -36,7 +36,7 @@ securely connect clusters using the same lightweight, modular architecture.
36
36
### East-West Gateways
37
37
38
38
Each cluster deploys an east-west gateway with a globally routable IP that acts as an entrypoint for cross-cluster communication.
39
-
The east-west gateways are configured using GatewayAPI and controlled by istiod.
39
+
The east-west gateways are configured using Gateway API and controlled by istiod.
40
40
A ztunnel communicates across clusters by connecting to the remote cluster's east-west gateway and sending the destination service FQDN.
41
41
The east-west gateway will then forward the connection to a cluster-local pod of its choosing.
42
42
As such, overlapping IP spaces are of no concern because we never directly address a pod in a remote cluster.
0 commit comments