Ambient mode validation

Verify that Database Catalogs and Virtual Warehouses namespaces reflect ambient mode labels and ensure proper deployment and configuration of related components.

  1. Verify that Database Catalogs and Virtual Warehouses namespaces reflect ambient mode labels:
    
    kubectl get namespace <vw-namespace> --show-labels | grep istio
                        

    Expected labels:

    
    istio.io/dataplane-mode=ambient
    istio.io/use-waypoint=waypoint-proxy
                        
  2. Confirm the ztunnel DaemonSet is active across all cluster nodes in the istio-system namespace:
    
    kubectl get daemonset ztunnel -n istio-system
    kubectl get pods -n istio-system -l app=ztunnel -o wide
                        
  3. Verify the waypoint proxy deployment and programming status:
    
    kubectl get deployment waypoint-proxy -n <vw-namespace>
    kubectl get gateway waypoint-proxy -n <vw-namespace>
                        

    Programmed=True indicates the Layer 7 waypoint proxy is active.

    Programmed=False indicates the waypoint pod is not running. Check PodSecurity policies or ReplicaSet events through:

    
    kubectl describe rs -n <vw-namespace> -l gateway.networking.k8s.io/gateway-name=waypoint-proxy
                        
  4. Ensure workload pods do not contain sidecar proxy containers:
    
    kubectl get pods -n <vw-namespace> -o jsonpath='{range .items[*]}{.metadata.name}{"\t"}{range .spec.containers[*]}{.name}{" "}{end}{"\n"}{end}'