Sidecar mode validation

Verify that Istio sidecar injection is enabled on target namespaces and confirm that Envoy proxy containers (istio-proxy) are injected and actively proxying mTLS traffic across workload pods.

  1. Confirm the sidecar injection label is present:
    
    kubectl get namespace <vw-namespace> --show-labels | grep istio
                        

    Expected label: istio-injection=enabled

  2. Verify that workload pods contain the native istio-proxy init container:
    
    kubectl get pods -n <vw-namespace> -o jsonpath='{range .items[*]}{.metadata.name}{"\t"}{range .spec.initContainers[*]}{.name}({.restartPolicy}) {end}{"\n"}{end}' | grep istio-proxy
                        

    Native sidecars display as istio-proxy(Always).

  3. Confirm inter-pod connections pass through Envoy:
    
    kubectl exec -n <vw-namespace> <pod> -c istio-proxy -- pilot-agent request GET /stats | grep ssl