apiVersion: v1 kind: Pod metadata: name: client namespace: istio-vt-t58-r2 labels: app: client annotations: sidecar.istio.io/inject: "true" spec: containers: - name: curl image: curlimages/curl:8.14.1 command: ["sleep", "infinity"] --- apiVersion: apps/v1 kind: Deployment metadata: name: echo namespace: istio-vt-t58-r2 labels: app: echo spec: replicas: 1 selector: matchLabels: app: echo template: metadata: labels: app: echo annotations: sidecar.istio.io/inject: "true" spec: containers: - name: echo image: mendhak/http-https-echo:37 env: - name: HTTP_PORT value: "8080" - name: HTTPS_PORT value: "8443" ports: - containerPort: 8080 - containerPort: 8443 --- apiVersion: v1 kind: Service metadata: name: echo namespace: istio-vt-t58-r2 spec: selector: app: echo ports: - name: http port: 80 targetPort: 8080 - name: https port: 443 targetPort: 8443 --- apiVersion: security.istio.io/v1 kind: PeerAuthentication metadata: name: strict-mtls namespace: istio-vt-t58-r2 spec: selector: matchLabels: app: echo mtls: mode: STRICT --- apiVersion: security.istio.io/v1 kind: AuthorizationPolicy metadata: name: allow-wrong-principal namespace: istio-vt-t58-r2 spec: selector: matchLabels: app: echo action: ALLOW rules: - from: - source: principals: ["cluster.local/ns/istio-vt-t58-r2/sa/nobody-such-account"]