| # Set enableTracing to false to disable request tracing. |
| enableTracing: true |
| # This is the ingress service name, update if you used a different name |
| ingressService: istio-ingress |
| # |
| defaultConfig: |
| # NOTE: If you change any values in this section, make sure to make |
| # the same changes in start up args in istio-ingress pods. |
| # |
| # TCP connection timeout between Envoy & the application, and between Envoys. |
| connectTimeout: 1s |
| # |
| ### ADVANCED SETTINGS ############# |
| # Where should envoy's configuration be stored in the istio-proxy container |
| configPath: "/etc/istio/proxy" |
| binaryPath: "/usr/local/bin/envoy" |
| # The pseudo service name used for Envoy. |
| serviceCluster: istio-proxy |
| # These settings that determine how long an old Envoy |
| # process should be kept alive after an occasional reload. |
| drainDuration: 2s |
| parentShutdownDuration: 3s |
| # |
| # The mode used to redirect inbound connections to Envoy. This setting |
| # has no effect on outbound traffic: iptables REDIRECT is always used for |
| # outbound connections. |
| # If "REDIRECT", use iptables REDIRECT to NAT and redirect to Envoy. |
| # The "REDIRECT" mode loses source addresses during redirection. |
| # If "TPROXY", use iptables TPROXY to redirect to Envoy. |
| # The "TPROXY" mode preserves both the source and destination IP |
| # addresses and ports, so that they can be used for advanced filtering |
| # and manipulation. |
| # The "TPROXY" mode also configures the sidecar to run with the |
| # CAP_NET_ADMIN capability, which is required to use TPROXY. |
| #interceptionMode: REDIRECT |
| # |
| # Port where Envoy listens (on local host) for admin commands |
| # You can exec into the istio-proxy container in a pod and |
| # curl the admin port (curl http://localhost:15000/) to obtain |
| # diagnostic information from Envoy. See |
| # https://lyft.github.io/envoy/docs/operations/admin.html |
| # for more details |
| proxyAdminPort: 15000 |
| # |
| # Zipkin trace collector |
| zipkinAddress: "" |
| # |
| # Statsd metrics collector converts statsd metrics into Prometheus metrics. |
| statsdUdpAddress: "" |
| # |
| # Mutual TLS authentication between sidecars and istio control plane. |
| controlPlaneAuthPolicy: NONE |
| # |
| # Address where istio Pilot service is running |
| discoveryAddress: istio-pilot:15007 |