Istio now supports wildcard ServiceEntry with DYNAMIC_DNS resolution, enabling sidecar proxies to route HTTPS egress traffic to wildcard domains (e.g., *.wikipedia.org, *.amazonaws.com) without requiring a dedicated egress gateway. Previously, this required a complex setup involving an egress gateway acting as an SNI forward
Table of contents
OverviewWhy wildcard HTTPS egress is difficultSNI routing via Egress GatewayWildcard ServiceEntry with DYNAMIC_DNS resolutionOther use casesConclusionReferencesSort: