Istio service mesh integration for Cloudera Data Warehouse on premises

Cloudera Data Warehouse on premises enables enrollment of Virtual Warehouse namespaces into an Istio service mesh to enforce mutual TLS (mTLS) communication across workload pods.

Service mesh behavior

Service mesh behavior is governed by the istio-mesh-mode property configured on the Cloudera Data Warehouse server.

Supported mesh modes

Deployment mode (istio-mesh-mode) Description Support status
"" (empty) Service mesh enrollment is disabled. This is the default setting. Supported
ambient In Istio ambient mode, traffic is transparently captured by the node-level ztunnel agent without injecting sidecar containers into workload pods. A per-namespace waypoint proxy is deployed for Layer 7 policy enforcement. Supported
sidecar Classic Istio sidecar injection. An Envoy proxy container is injected into every workload pod. Supported for Hive, Impala, and Trino

Both modes enforce STRICT mTLS (PeerAuthentication) across all Virtual Warehouse services (Cloudera Data Warehouse, Hive, Impala, and Trino). Metrics ports retain PERMISSIVE mTLS to allow Prometheus scraping from outside the mesh.