Configuring Istio service mesh
Review the prerequisites and step-by-step procedure required to configure and enable Istio service mesh modes for Cloudera Data Warehouse environments using the Cloudera Data Warehouse server ConfigMap.
- Ensure gateway API functionality is enabled (
gateway-api-enabled: true). - Verify that an operational Istio control plane is installed by your platform
team in the
istio-systemnamespace with theistiodservice active, as Cloudera Data Warehouse does not install Istio directly. - If using ambient mesh, verify that the
ztunnelDaemonSet is running on all cluster nodes in theistio-systemnamespace to provide layer 4 mTLS capture. Ensuregateways.seccompProfile.typeis set toRuntimeDefaultin theistiodHelm chart values to comply with restricted PodSecurity admission standards. - If using sidecar mesh, ensure Istio is configured for native sidecar injection
(using init containers with
restartPolicy=Always) and that theistiodwebhook recognizes theistio-injection: enablednamespace label. Note that ifenablePrometheusMergeis set toTruein theistio meshConfig, port conflicts can occur with application metrics ports. - If using sidecar mode with an external MySQL database for the Hive Metastore,
ensure the database administrator configures
max_connect_errors = 100000(or higher) under[mysqld]inmy.cnf.
