Keith Mattix II
Keith Mattix II
First, upgrade your istioctl version so that it'll be compatible with recent versions. Then run: `istioctl pc log POD_NAME --level debug`
@kyessenov do you need some help picking this back up?
Multiple outbound ports is tricky due to our iptables rules....are you saying the sidecar isn't reusing/pooling connections to the same 5-tuple?
Are you injecting sidecars in your application or your MQ instances? Do you have logs you can share?
Are your clients connecting through an istio ingress gateway? What's the request flow?
> My recommendation is to rationalize the extension ordering in a consistent way, that is not tied to the current inadequate Istio implementation I agree with this, but is it...
I am also happy to help if more hands are needed :)
I can probably tackle/repurpose the L4 authZ policy doc. It may also be helpful to have a doc about how to reason about authorization generally in Ambient
You should be able to use `networkGateway` in the gateway helm chart to configure an eastwest gateway