Intel Distribution of Istio
939

Created 7/14/2022
Updated 7/14/2022
Revision 1
Grafana Version >=8.3.1
Datasources
Prometheus

Istio uses Envoy as sidecar to handle secure connections and intercept traffic. Depending on use cases, when an Istio Ingress Gateway must handle a large number of incoming TLS and secure service-to-service connections through sidecar proxies, the load on Envoy increases. The potential performance depends on many factors, such as size of the cpuset on which Envoy is running, incoming traffic patterns, and key size. These factors can impact Envoy serving many new incoming TLS requests. To achieve performance improvements and accelerated handshakes, a new CryptoMb feature was introduced in Envoy 1.20 and Istio 1.14.

Prometheus data source includes Istiod and Envoy metric to visualize CryptoMb features. Grafana visualizes all important data of CryptoMb such as buckets utilization, envoy listener requests, envoy listener handshakes, current envoy TLS connections. In addition, the dashboard includes cpu and memory utilization graphs for Istio Ingress Gateway and Kubernetes Nodes. More info about cryptomb is in Istio documentation: https://istio.io/latest/docs/reference/config/istio.mesh.v1alpha1/#PrivateKeyProvider-CryptoMb

Export Dashboard
Download
Copy to Clipboard