Ambient mode validation
Verify that Database Catalogs and Virtual Warehouses namespaces reflect ambient mode labels and ensure proper deployment and configuration of related components.
-
Verify that Database Catalogs and Virtual Warehouses namespaces reflect ambient mode labels:
kubectl get namespace <vw-namespace> --show-labels | grep istioExpected labels:
istio.io/dataplane-mode=ambient istio.io/use-waypoint=waypoint-proxy -
Confirm the ztunnel DaemonSet is active across all cluster nodes in the istio-system namespace:
kubectl get daemonset ztunnel -n istio-system kubectl get pods -n istio-system -l app=ztunnel -o wide -
Verify the waypoint proxy deployment and programming status:
kubectl get deployment waypoint-proxy -n <vw-namespace> kubectl get gateway waypoint-proxy -n <vw-namespace>Programmed=Trueindicates the Layer 7 waypoint proxy is active.Programmed=Falseindicates the waypoint pod is not running. Check PodSecurity policies or ReplicaSet events through:kubectl describe rs -n <vw-namespace> -l gateway.networking.k8s.io/gateway-name=waypoint-proxy -
Ensure workload pods do not contain sidecar proxy containers:
kubectl get pods -n <vw-namespace> -o jsonpath='{range .items[*]}{.metadata.name}{"\t"}{range .spec.containers[*]}{.name}{" "}{end}{"\n"}{end}'
