由于应用服务网格CSM格控制面部署在租户的云容器引擎集群上,开通过程中会主集群安装CRD,部署相关控制面服务等,如果您在自己的云容器引擎集群上已经安装了相同的资源,可能导致资源冲突,需要您确认是否可以删除当前云容器引擎集群上的冲突资源是否可以删除,确认删除冲突资源后再重新开通服务网格。
服务网格CSM安装过程中需要新增的CRD如下:
authorizationpolicies.security.istio.io
customproxyconfigs.networking.istio.io
destinationrules.networking.istio.io
envoyfilters.networking.istio.io
gateways.networking.istio.io
istiooperators.install.istio.io
localratelimiters.networking.istio.io
peerauthentications.security.istio.io
proxyconfigs.networking.istio.io
requestauthentications.security.istio.io
serviceentries.networking.istio.io
sidecars.networking.istio.io
telemetries.telemetry.istio.io
trafficlabels.networking.istio.io
virtualservices.networking.istio.io
wasmplugins.extensions.istio.io
workloadentries.networking.istio.io
workloadgroups.networking.istio.io
新增资源部署如下:
apiVersion | Kind | Namespace | Name |
---|---|---|---|
apps/v1 | Deployment | istio-system | istio-eastwestgateway |
networking.istio.io/v1alpha3 | Gateway | istio-system | istiod-gateway |
networking.istio.io/v1alpha3 | VirtualService | istio-system | istiod-vs |
rbac.authorization.k8s.io/v1 | ClusterRole | istio-system | istio-eastwestgateway-sds |
rbac.authorization.k8s.io/v1 | ClusterRoleBinding | istio-system | istio-eastwestgateway-sds |
v1 | Service | istio-system | istio-eastwestgateway |
v1 | ServiceAccount | istio-system | istio-eastwestgateway-service-account |
rbac.authorization.k8s.io/v1 | ClusterRole | istio-system | istio-operator |
rbac.authorization.k8s.io/v1 | ClusterRoleBinding | istio-system | istio-operator |
install.istio.io/v1alpha1 | IstioOperator | istio-system | istiocontrolplane |
apps/v1 | Deployment | istio-system | istio-operator |
v1 | Service | istio-system | istio-operator |
v1 | ServiceAccount | istio-system | istio-operator |
v1 | Endpoints | opa-istio | admission-controller |
v1 | Service | opa-istio | admission-controller |
admissionregistration.k8s.io/v1 | MutatingWebhookConfiguration | 无 | opa-istio-admission-controller |