🎯 LESSON OBJECTIVE__HTMLTAG_68___
- ✅ Configure Istio Gateway for external traffic__HTMLTAG_71___
- ✅ TLS termination with cert-manager (Let's Encrypt)
- ✅ Multi-domain hosting
- ✅ CORS, WebSocket, gRPC support
- ✅ Kubernetes Gateway API (future)
PART 1: ISTIO GATEWAY
External Traffic Flow:
┌──────────────┐
Internet ──────► │ MetalLB │
│ LoadBalancer │
└──────┬───────┘
│
┌──────▼───────┐
│ Istio │
│ Ingress │
│ Gateway │ ← Gateway CRD
└──────┬───────┘
│
┌───────────┼───────────┐
│ │ │
┌──────▼──┐ ┌──────▼──┐ ┌─────▼───┐
│ api. │ │ web. │ │ admin. │
│ app.com│ │ app.com │ │ app.com │
└─────────┘ └─────────┘ └─────────┘
(VirtualService routing per host)
1.1. Basic Gateway
# gateway.yaml: apiVersion: networking.istio.io/v1 kind: Gateway metadata: name: main-gateway namespace: istio-system spec: selector: istio: ingressgateway # Matches Istio ingress gateway pods servers: # HTTPS (port 443): - port: number: 443 name: https protocol: HTTPS tls: mode: SIMPLE credentialName: main-tls-cert # K8s Secret (cert-manager) hosts: - "api.myapp.com" - "web.myapp.com" - "admin.myapp.com"# HTTP → HTTPS redirect: - port: number: 80 name: http protocol: HTTP tls: httpsRedirect: true hosts: - "api.myapp.com" - "web.myapp.com" - "admin.myapp.com"
1.2. VirtualService for Gateway
# vs-api.yaml: apiVersion: networking.istio.io/v1 kind: VirtualService metadata: name: api-routes namespace: default spec: hosts: - "api.myapp.com" gateways: - istio-system/main-gateway http: - match: - uri: prefix: /api/v1/orders route: - destination: host: order-service port: number: 8080 corsPolicy: allowOrigins: - exact: "https://web.myapp.com" allowMethods: - GET - POST - PUT - DELETE allowHeaders: - Authorization - Content-Type maxAge: "24h"- match: - uri: prefix: /api/v1/payments route: - destination: host: payment-service port: number: 8080 - match: - uri: prefix: /api/v1/users route: - destination: host: user-service port: number: 8080
vs-web.yaml:
apiVersion: networking.istio.io/v1 kind: VirtualService metadata: name: web-routes namespace: default spec: hosts: - "web.myapp.com" gateways: - istio-system/main-gateway http: - route: - destination: host: frontend port: number: 3000
PART 2: TLS WITH CERT-MANAGER
2.1. Install cert-manager
# Install cert-manager: helm repo add jetstack https://charts.jetstack.io helm repo update
helm install cert-manager jetstack/cert-manager
--namespace cert-manager
--create-namespace
--set crds.enabled=true
--set prometheus.enabled=true
2.2. ClusterIssuer (Let's Encrypt)
# cluster-issuer.yaml:
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: letsencrypt-prod
spec:
acme:
server: https://acme-v02.api.letsencrypt.org/directory
email: [email protected]
privateKeySecretRef:
name: letsencrypt-prod-key
solvers:
- http01:
ingress:
class: istio
---
# Self-signed CA (for internal services):
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: cluster-ca-issuer
spec:
selfSigned: {}
2.3. Certificate for Gateway
# certificate.yaml:
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: main-tls-cert
namespace: istio-system # Same namespace as Gateway
spec:
secretName: main-tls-cert # Referenced in Gateway credentialName
issuerRef:
name: letsencrypt-prod
kind: ClusterIssuer
commonName: myapp.com
dnsNames:
- "api.myapp.com"
- "web.myapp.com"
- "admin.myapp.com"
- "*.myapp.com" # Wildcard
duration: 2160h # 90 days
renewBefore: 360h # Renew 15 days before expiry
# Verify certificate:
kubectl -n istio-system get certificate
# NAME READY SECRET AGE
# main-tls-cert True main-tls-cert 5m
kubectl -n istio-system describe certificate main-tls-cert
# Status: True
# Not After: 2024-xx-xx
PART 3: WEBSOCKET & gRPC
3.1. WebSocket Support
# WebSocket qua Istio Gateway:
apiVersion: networking.istio.io/v1
kind: VirtualService
metadata:
name: websocket-routes
namespace: default
spec:
hosts:
- "ws.myapp.com"
gateways:
- istio-system/main-gateway
http:
- match:
- uri:
prefix: /ws
headers:
upgrade:
exact: websocket
route:
- destination:
host: notification-service
port:
number: 8080
timeout: 0s # No timeout for WebSocket
3.2. gRPC Support
# gRPC routing:
apiVersion: networking.istio.io/v1
kind: Gateway
metadata:
name: grpc-gateway
namespace: istio-system
spec:
selector:
istio: ingressgateway
servers:
- port:
number: 443
name: grpc-tls
protocol: HTTPS
tls:
mode: SIMPLE
credentialName: grpc-tls-cert
hosts:
- "grpc.myapp.com"
---
apiVersion: networking.istio.io/v1
kind: VirtualService
metadata:
name: grpc-routes
spec:
hosts:
- "grpc.myapp.com"
gateways:
- istio-system/grpc-gateway
http:
- match:
- uri:
prefix: /order.OrderService
route:
- destination:
host: order-grpc-service
port:
number: 50051
PART 4: KUBERNETES GATEWAY API (FUTURE)
# Gateway API (replacing Ingress & Istio Gateway):
# More standardized, portable across mesh implementations
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: main-gateway
namespace: default
spec:
gatewayClassName: istio # Istio implementation
listeners:
- name: https
port: 443
protocol: HTTPS
tls:
mode: Terminate
certificateRefs:
- name: main-tls-cert
allowedRoutes:
namespaces:
from: All
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: api-routes
spec:
parentRefs:
- name: main-gateway
hostnames:
- "api.myapp.com"
rules:
- matches:
- path:
type: PathPrefix
value: /api/v1/orders
backendRefs:
- name: order-service
port: 8080
💡 KEY TAKEAWAYS
- Gateway: Entry point for external traffic, TLS termination
- VirtualService: Route traffic from Gateway → backend services
- cert-manager: Auto-provision & renew TLS certificates
- Multi-domain: Single Gateway, multiple VirtualServices
- Gateway API: Future standard, replacing both Ingress and Istio Gateway
🎯 EXERCISES
Exercise 1: Production Gateway
- Configure Gateway with TLS (cert-manager)
- Route 3 domains to different services__HTMLTAG_141___
- Test HTTPS redirect
Exercise 2: CORS & Security Headers__HTMLTAG_146___
- Configure CORS policy for API
- Add security headers (HSTS, CSP, X-Frame-Options)
📚 NEXT POST
In Lesson 27: Istio Security — AuthorizationPolicy and RequestAuthentication, we will configure security policies, JWT validation, and network segmentation.