Kubernetes Cluster Service Mesh Profile
Properties
A certificate_authority
block as defined below. When this property is specified, key_vault_secrets_provider
is also required to be set. This configuration allows you to bring your own root certificate and keys for Istio CA in the Istio-based service mesh add-on for Azure Kubernetes Service.
Is Istio External Ingress Gateway enabled?
Is Istio Internal Ingress Gateway enabled?
Specify 1 or 2 Istio control plane revisions for managing minor upgrades using the canary upgrade process. For example, create the resource with revisions
set to ["asm-1-20"]
, or leave it empty (the revisions
will only be known after apply). To start the canary upgrade, change revisions
to ["asm-1-20", "asm-1-21"]
. To roll back the canary upgrade, revert to ["asm-1-20"]
. To confirm the upgrade, change to ["asm-1-21"]
.