Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support pluggable waypoint #47967

Closed
linsun opened this issue Nov 21, 2023 · 11 comments
Closed

Support pluggable waypoint #47967

linsun opened this issue Nov 21, 2023 · 11 comments
Assignees
Labels
area/ambient Issues related to ambient mesh kind/enhancement

Comments

@linsun
Copy link
Member

linsun commented Nov 21, 2023

Describe the feature request

A design from @louiscryan is being socialized in next week's ambient WG meeting on how vendors can plug its own waypoint with what contracts.

Opening this issue to start some tasks for it. Immediate tasks after discussing with @ilrudie:

  1. Ensure our istio waypoint object has proper address to inform ztunnel the waypoint service addr: A status field on the Gateway resource identifying the Waypoint endpoints using GatewayStatus.Addresses
  2. Allow user to deploy its custom waypoint and being recognized as its custom waypoints. Provide a sample custom waypoint type for testing.
  • Need consensus if istio-waypoint is the default Istio waypoint impl and anything waypoint means custom waypoint.
  1. For istiod/ztunnel - able to detect the custom waypoint and use its address to configure ztunnel via xDS to the waypoint's address to when the destination has a waypoint.

@ilrudie feel free to add anything i missed.

Affected product area (please put an X in all that apply)

[ x ] Ambient
[ ] Docs
[ ] Dual Stack
[ ] Installation
[ ] Networking
[ ] Performance and Scalability
[ ] Extensions and Telemetry
[ ] Security
[ ] Test and Release
[ ] User Experience
[ ] Developer Infrastructure

Affected features (please put an X in all that apply)

[ ] Multi Cluster
[ ] Virtual Machine
[ ] Multi Control Plane

Additional context

@istio-policy-bot istio-policy-bot added area/ambient Issues related to ambient mesh kind/enhancement labels Nov 21, 2023
@ilrudie
Copy link
Contributor

ilrudie commented Nov 22, 2023

Right now we have some requirements for how our own waypoint controller communicates readiness with the ambient controllers. Depending on how folks feel this should probably be included in any formalized specification because if these rules are followed waypoint configuration in zt can be done only after the waypoint is ready to handle traffic which makes adding L7 less disruptive. It additionally includes some requirements about not removing addresses since this is the readiness mechanism right now. As 3rd party waypoint become a formalized thing we may want to track this readiness internally rather than relying on proper 3rd party controller status updates but we can also think about formalizing the requirements and non-conformant waypoint controllers are the vendor/3rd party's problem.

gateway.Status.Addresses should only be populated once the Waypoint's deployment has at least 1 ready pod, it should never be removed after going ready

We also at present require that this field be populated by something which can be parsed into an IPv4 or IPv6 address. This is a subset of the K8s Gateway API spec's valid addresses so it may be something we want to consider relaxing as we iterate on 3rd party interoperations.

@ilrudie
Copy link
Contributor

ilrudie commented Nov 22, 2023

Re: able to detect waypoint, 2 options come to mind

  1. gateway class name in a specific format, waypoint- prefix for instance
  2. presence of a label on the gateways.gateway... resource, ambient.istio.io/waypoint: "true" or something along these lines

@ilrudie
Copy link
Contributor

ilrudie commented Nov 27, 2023

Implementable items

  • Discovery of gateways which are being used as waypoints
  • Status on gateways (possibly need to begin looking for "programmed: instead of just addresses)
  • Status on policy resources

@linsun
Copy link
Member Author

linsun commented Nov 28, 2023

Opened an API PR for discussion: istio/api#3005

@linsun
Copy link
Member Author

linsun commented Dec 1, 2023

Potential idea - create some conformance tests.

Or check small tasks in the community.

@ilrudie
Copy link
Contributor

ilrudie commented Dec 5, 2023

istio/api#3014 opened to track WI for policy status enhancements

@linsun
Copy link
Member Author

linsun commented Dec 8, 2023

Working on a PR to add the status and condition for APIs.

@linsun
Copy link
Member Author

linsun commented Dec 15, 2023

Need to sync with Louis and agree on scope for L4 beta.

@ilrudie
Copy link
Contributor

ilrudie commented Dec 15, 2023

Related : https://docs.google.com/document/d/1EDnk9cyji8GtpK7tF6czqiStd7UTujoIhhBUi1XYAQM/edit#heading=h.stll71jzvhaf

Nailing this down would help with the logic for what goes into status.

@istio-policy-bot istio-policy-bot added the lifecycle/stale Indicates a PR or issue hasn't been manipulated by an Istio team member for a while label Jun 13, 2024
@istio-policy-bot istio-policy-bot added the lifecycle/automatically-closed Indicates a PR or issue that has been closed automatically. label Jun 28, 2024
@ilrudie
Copy link
Contributor

ilrudie commented Jun 28, 2024

not stale

@ilrudie ilrudie reopened this Jun 28, 2024
@istio-policy-bot istio-policy-bot removed the lifecycle/stale Indicates a PR or issue hasn't been manipulated by an Istio team member for a while label Jun 28, 2024
@ilrudie ilrudie removed the lifecycle/automatically-closed Indicates a PR or issue that has been closed automatically. label Jun 28, 2024
@howardjohn
Copy link
Member

I think this is done and tested in TestSimpleHTTPSandwich

@howardjohn howardjohn closed this as not planned Won't fix, can't repro, duplicate, stale Sep 9, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/ambient Issues related to ambient mesh kind/enhancement
Projects
Status: Done
Development

No branches or pull requests

4 participants