Configuring Istio service mesh

Review the prerequisites and step-by-step procedure required to configure and enable Istio service mesh modes for Cloudera Data Warehouse environments using the Cloudera Data Warehouse server ConfigMap.

  • Ensure gateway API functionality is enabled (gateway-api-enabled: true).
  • Verify that an operational Istio control plane is installed by your platform team in the istio-system namespace with the istiod service active, as Cloudera Data Warehouse does not install Istio directly.
  • If using ambient mesh, verify that the ztunnel DaemonSet is running on all cluster nodes in the istio-system namespace to provide layer 4 mTLS capture. Ensure gateways.seccompProfile.type is set to RuntimeDefault in the istiod Helm chart values to comply with restricted PodSecurity admission standards.
  • If using sidecar mesh, ensure Istio is configured for native sidecar injection (using init containers with restartPolicy=Always) and that the istiod webhook recognizes the istio-injection: enabled namespace label. Note that if enablePrometheusMerge is set to True in the istio meshConfig, port conflicts can occur with application metrics ports.
  • If using sidecar mode with an external MySQL database for the Hive Metastore, ensure the database administrator configures max_connect_errors = 100000 (or higher) under [mysqld] in my.cnf.
  1. Edit the Cloudera Data Warehouse release ConfigMap in your Cloudera namespace:
    
    kubectl edit configmap cdp-release-dwx-edwsyaml -n <cdp-namespace>
  2. In the edws.yaml key, update the mesh mode property:
    istio-mesh-mode: "ambient"
  3. Restart the Cloudera Data Warehouse server and worker deployments to apply the configuration:
    
    kubectl rollout restart deployment cdp-release-dwx-server -n <cdp-namespace>
    kubectl rollout restart deployment cdp-release-dwx-worker -n <cdp-namespace>
  4. Confirm rollout completion:
    kubectl rollout status deployment cdp-release-dwx-server -n <cdp-namespace>
    kubectl rollout status deployment cdp-release-dwx-worker -n <cdp-namespace>
  5. Rebuild all existing Database Catalogs and Virtual Warehouses using the Rebuild button in the Cloudera Data Warehouse UI.