Update ServiceEntries for Istio 1.1
This commit is contained in:
parent
a0a9852afe
commit
032486e96a
3 changed files with 47 additions and 6 deletions
30
istio-manifests/whitelist-egress-google-metadata.yaml
Normal file
30
istio-manifests/whitelist-egress-google-metadata.yaml
Normal file
|
@ -0,0 +1,30 @@
|
||||||
|
# Copyright 2018 Google LLC
|
||||||
|
#
|
||||||
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
|
# you may not use this file except in compliance with the License.
|
||||||
|
# You may obtain a copy of the License at
|
||||||
|
#
|
||||||
|
# http://www.apache.org/licenses/LICENSE-2.0
|
||||||
|
#
|
||||||
|
# Unless required by applicable law or agreed to in writing, software
|
||||||
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||||
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
|
# See the License for the specific language governing permissions and
|
||||||
|
# limitations under the License.
|
||||||
|
|
||||||
|
apiVersion: networking.istio.io/v1alpha3
|
||||||
|
kind: ServiceEntry
|
||||||
|
metadata:
|
||||||
|
name: whitelist-egress-google-metadata
|
||||||
|
spec:
|
||||||
|
hosts:
|
||||||
|
- metadata.google.internal
|
||||||
|
addresses:
|
||||||
|
- 169.254.169.254 # GCE metadata server
|
||||||
|
ports:
|
||||||
|
- number: 80
|
||||||
|
name: http
|
||||||
|
protocol: HTTP
|
||||||
|
- number: 443
|
||||||
|
name: https
|
||||||
|
protocol: HTTPS
|
|
@ -18,9 +18,6 @@ metadata:
|
||||||
name: whitelist-egress-googleapis
|
name: whitelist-egress-googleapis
|
||||||
spec:
|
spec:
|
||||||
hosts:
|
hosts:
|
||||||
- "169.254.169.254" # GCE metadata server
|
|
||||||
- "metadata.google" # GCE metadata server
|
|
||||||
- "metadata.google.internal" # GCE metadata server
|
|
||||||
- "accounts.google.com" # Used to get token
|
- "accounts.google.com" # Used to get token
|
||||||
- "*.googleapis.com"
|
- "*.googleapis.com"
|
||||||
ports:
|
ports:
|
||||||
|
|
|
@ -82,9 +82,6 @@ metadata:
|
||||||
name: whitelist-egress-googleapis
|
name: whitelist-egress-googleapis
|
||||||
spec:
|
spec:
|
||||||
hosts:
|
hosts:
|
||||||
- "169.254.169.254" # GCE metadata server
|
|
||||||
- "metadata.google" # GCE metadata server
|
|
||||||
- "metadata.google.internal" # GCE metadata server
|
|
||||||
- "accounts.google.com" # Used to get token
|
- "accounts.google.com" # Used to get token
|
||||||
- "*.googleapis.com"
|
- "*.googleapis.com"
|
||||||
ports:
|
ports:
|
||||||
|
@ -95,3 +92,20 @@ spec:
|
||||||
protocol: HTTPS
|
protocol: HTTPS
|
||||||
name: https
|
name: https
|
||||||
---
|
---
|
||||||
|
apiVersion: networking.istio.io/v1alpha3
|
||||||
|
kind: ServiceEntry
|
||||||
|
metadata:
|
||||||
|
name: whitelist-egress-google-metadata
|
||||||
|
spec:
|
||||||
|
hosts:
|
||||||
|
- metadata.google.internal
|
||||||
|
addresses:
|
||||||
|
- 169.254.169.254 # GCE metadata server
|
||||||
|
ports:
|
||||||
|
- number: 80
|
||||||
|
name: http
|
||||||
|
protocol: HTTP
|
||||||
|
- number: 443
|
||||||
|
name: https
|
||||||
|
protocol: HTTPS
|
||||||
|
---
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue