Istio service mesh integration for Cloudera Data Warehouse on premises
Cloudera Data Warehouse on premises enables enrollment of Virtual Warehouse namespaces into an Istio service mesh to enforce mutual TLS (mTLS) communication across workload pods.
Service mesh behavior
Service mesh behavior is governed by the istio-mesh-mode property configured on the Cloudera Data Warehouse server.
Supported mesh modes
| Deployment mode (istio-mesh-mode) | Description | Support status |
|---|---|---|
"" (empty) |
Service mesh enrollment is disabled. This is the default setting. | Supported |
ambient |
In Istio ambient mode, traffic is transparently captured by the node-level ztunnel agent without injecting sidecar containers into workload pods. A per-namespace waypoint proxy is deployed for Layer 7 policy enforcement. | Supported |
sidecar |
Classic Istio sidecar injection. An Envoy proxy container is injected into every workload pod. | Supported for Hive, Impala, and Trino |
Both modes enforce STRICT mTLS (PeerAuthentication) across all
Virtual Warehouse services (Cloudera Data Warehouse, Hive, Impala, and
Trino). Metrics ports retain PERMISSIVE mTLS to allow Prometheus scraping from
outside the mesh.
