Istio now supports wildcard ServiceEntry with DYNAMIC_DNS resolution, enabling sidecar proxies to route HTTPS egress traffic to wildcard domains (e.g., *.wikipedia.org, *.amazonaws.com) without requiring a dedicated egress gateway. Previously, this required a complex setup involving an egress gateway acting as an SNI forward

5m read timeFrom istio.io
Post cover image
Table of contents
OverviewWhy wildcard HTTPS egress is difficultSNI routing via Egress GatewayWildcard ServiceEntry with DYNAMIC_DNS resolutionOther use casesConclusionReferences

Sort: