Deny-by-default network access control at the service level using Istio AuthorizationPolicy resources.
Deny-by-default network access control at the service level using Istio AuthorizationPolicy resources.
AuthorizationPolicy is like a firewall at the service level. By default, Istio allows all traffic. Adding any AuthorizationPolicy enables deny-by-default for that workload. Policies can allow/deny by source, namespace, path, method, or header.
Key takeaways
Related concepts
Explore topics that connect to this one.
Ready to see how this works in the cloud?
Switch to Career Paths for structured paths (e.g. Developer, DevOps) and provider-specific lessons.
View role-based pathsSign in to track your progress and mark lessons complete.
Questions? Discuss in the community or start a thread below.
Join DiscordSign in to start or join a thread.