istio:ambient-waypoint

Official

Secure L7 traffic with Istio Ambient Waypoints

Authorkagenti
Version1.0.0
Installs0

System Documentation

What problem does it solve?

This Skill simplifies the configuration of L7 AuthorizationPolicies in Istio Ambient mode, enabling fine-grained access control for services without sidecars.

Core Features & Use Cases

  • Waypoint Gateway Configuration: Define and deploy waypoint gateways for L7 traffic inspection.
  • Service Integration: Label services to direct traffic through configured waypoints.
  • AuthorizationPolicy with targetRefs: Implement path, method, and principal-based access controls using Istio's AuthorizationPolicy resource with targetRefs.
  • Use Case: Securely expose an MLflow service, allowing only the OTEL collector to POST traces to /v1/traces and the Kagenti UI to access all other endpoints.

Quick Start

Configure an Istio Ambient Waypoint for the 'mlflow' service in the 'kagenti-system' namespace to allow POST requests to '/v1/traces' from the 'otel-collector' service account.

Dependency Matrix

Required Modules

None required

Components

references

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: istio:ambient-waypoint
Download link: https://github.com/kagenti/kagenti/archive/main.zip#istio-ambient-waypoint

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.