{"id":30047615,"url":"https://github.com/tmax-cloud/install-istio","last_synced_at":"2026-03-09T10:33:43.951Z","repository":{"id":36978194,"uuid":"333616103","full_name":"tmax-cloud/install-istio","owner":"tmax-cloud","description":null,"archived":false,"fork":false,"pushed_at":"2023-07-18T02:45:04.000Z","size":876,"stargazers_count":1,"open_issues_count":0,"forks_count":5,"subscribers_count":3,"default_branch":"master","last_synced_at":"2025-08-07T09:57:02.504Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/tmax-cloud.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2021-01-28T01:58:32.000Z","updated_at":"2024-11-13T08:58:10.000Z","dependencies_parsed_at":"2022-08-08T18:31:18.013Z","dependency_job_id":null,"html_url":"https://github.com/tmax-cloud/install-istio","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/tmax-cloud/install-istio","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tmax-cloud%2Finstall-istio","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tmax-cloud%2Finstall-istio/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tmax-cloud%2Finstall-istio/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tmax-cloud%2Finstall-istio/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/tmax-cloud","download_url":"https://codeload.github.com/tmax-cloud/install-istio/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tmax-cloud%2Finstall-istio/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30291807,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-09T02:57:19.223Z","status":"ssl_error","status_checked_at":"2026-03-09T02:56:26.373Z","response_time":61,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2025-08-07T09:56:45.386Z","updated_at":"2026-03-09T10:33:43.896Z","avatar_url":"https://github.com/tmax-cloud.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"\n# Istio 설치 가이드\n\n## 구성 요소 및 버전\n* istiod ([docker.io/istio/pilot:1.5.1](https://hub.docker.com/layers/istio/pilot/1.5.1/images/sha256-818aecc1c73c53af9091ac1d4f500d9d7cec6d135d372d03cffab1addaff4ec0?context=explore))\n* istio-ingressgateway ([docker.io/istio/proxyv2:1.5.1](https://hub.docker.com/layers/istio/proxyv2/1.5.1/images/sha256-3ad9ee2b43b299e5e6d97aaea5ed47dbf3da9293733607d9b52f358313e852ae?context=explore))\n* istio-tracing ([docker.io/jaegertracing/all-in-one:1.16](https://hub.docker.com/layers/jaegertracing/all-in-one/1.16/images/sha256-738442983b772a5d413c8a2c44a5563956adaff224e5b38f52a959124dafc119?context=explore))\n* bookinfo example\n    * productpage([docker.io/istio/examples-bookinfo-productpage-v1:1.15.0](https://hub.docker.com/layers/istio/examples-bookinfo-productpage-v1/1.15.0/images/sha256-0a5eb4795952372251d51f72834bccb7ea01a67cb72fd9b58b757cca103b7524?context=explore))\n    * details([docker.io/istio/examples-bookinfo-details-v1:1.15.0](https://hub.docker.com/layers/istio/examples-bookinfo-details-v1/1.15.0/images/sha256-fce0bcbff0bed09116dacffca15695cd345e0c3788c15b0114a05f654ddecc17?context=explore))\n    * ratings([docker.io/istio/examples-bookinfo-ratings-v1:1.15.0](https://hub.docker.com/layers/istio/examples-bookinfo-ratings-v1/1.15.0/images/sha256-09b9d6958a13ad1a97377b7d5c2aa9e0372c008cdf5a44ce3e72fbd9660936cf?context=explore))\n    * reviews-v1([docker.io/istio/examples-bookinfo-reviews-v1:1.15.0](https://hub.docker.com/layers/istio/examples-bookinfo-reviews-v1/1.15.0/images/sha256-40e8aba77c1b46f37e820a60aa6948485d39e6f55f1492fa1f17383efd95511c?context=explore))\n    * reviews-v2([docker.io/istio/examples-bookinfo-reviews-v2:1.15.0](https://hub.docker.com/layers/istio/examples-bookinfo-reviews-v2/1.15.0/images/sha256-e86d247b7ac275eb681a7e9c869325762686ccf0b5cfb6bde100ff2c1f01ae2b?context=explore))\n    * reviews-v3([docker.io/istio/examples-bookinfo-reviews-v3:1.15.0](https://hub.docker.com/layers/istio/examples-bookinfo-reviews-v3/1.15.0/images/sha256-e454cab754cf9234e8b41d7c5e30f53a4c125d7d9443cb3ef2b2eb1c4bd1ec14?context=explore))\n\n## Prerequisites\n\n## 폐쇄망 설치 가이드\n설치를 진행하기 전 아래의 과정을 통해 필요한 이미지 및 yaml 파일을 준비한다.\n1. **폐쇄망에서 설치하는 경우** 사용하는 image repository에 istio 설치 시 필요한 이미지를 push한다. \n\n    * 작업 디렉토리 생성 및 환경 설정\n    ```bash\n    $ mkdir -p ~/istio-install\n    $ export ISTIO_HOME=~/istio-install\n    $ export ISTIO_VERSION=1.5.1\n    $ export JAEGER_VERSION=1.16\n    $ export REGISTRY=[IP:PORT]\n    $ cd $ISTIO_HOME\n    ```\n    * 외부 네트워크 통신이 가능한 환경에서 필요한 이미지를 다운받는다.\n    ```bash\n    $ sudo docker pull istio/pilot:${ISTIO_VERSION}\n    $ sudo docker save istio/pilot:${ISTIO_VERSION} \u003e istio-pilot_${ISTIO_VERSION}.tar\n    $ sudo docker pull istio/proxyv2:${ISTIO_VERSION}\n    $ sudo docker save istio/proxyv2:${ISTIO_VERSION} \u003e istio-proxyv2_${ISTIO_VERSION}.tar\n    $ sudo docker pull jaegertracing/all-in-one:${JAEGER_VERSION}\n    $ sudo docker save jaegertracing/all-in-one:${JAEGER_VERSION} \u003e jaeger_${JAEGER_VERSION}.tar\n    // bookinfo example images\n    $ sudo docker pull istio/examples-bookinfo-productpage-v1:1.15.0\n    $ sudo docker pull istio/examples-bookinfo-details-v1:1.15.0\n    $ sudo docker pull istio/examples-bookinfo-ratings-v1:1.15.0\n    $ sudo docker pull istio/examples-bookinfo-reviews-v1:1.15.0\n    $ sudo docker pull istio/examples-bookinfo-reviews-v2:1.15.0\n    $ sudo docker pull istio/examples-bookinfo-reviews-v3:1.15.0\n    $ sudo docker save istio/examples-bookinfo-productpage-v1:1.15.0 \u003e productpage.tar\n    $ sudo docker save istio/examples-bookinfo-details-v1:1.15.0 \u003e details.tar\n    $ sudo docker save istio/examples-bookinfo-ratings-v1:1.15.0 \u003e ratings.tar\n    $ sudo docker save istio/examples-bookinfo-reviews-v1:1.15.0 \u003e reviews-v1.tar\n    $ sudo docker save istio/examples-bookinfo-reviews-v2:1.15.0 \u003e reviews-v2.tar\n    $ sudo docker save istio/examples-bookinfo-reviews-v3:1.15.0 \u003e reviews-v3.tar\n    ```\n    * install yaml을 다운로드한다.\n    ```bash\n    $ wget https://raw.githubusercontent.com/tmax-cloud/install-istio/master/yaml/1.istio-base.yaml\n    $ wget https://raw.githubusercontent.com/tmax-cloud/install-istio/master/yaml/2.istio-tracing.yaml\n    $ wget https://raw.githubusercontent.com/tmax-cloud/install-istio/master/yaml/3.istio-core.yaml\n    $ wget https://raw.githubusercontent.com/tmax-cloud/install-istio/master/yaml/4.istio-ingressgateway.yaml\n    $ wget https://raw.githubusercontent.com/tmax-cloud/install-istio/master/yaml/5.istio-metric.yaml\n    $ wget https://raw.githubusercontent.com/tmax-cloud/install-istio/master/yaml/bookinfo.yaml\n    ```\n  \n2. 위의 과정에서 생성한 tar 파일들을 폐쇄망 환경으로 이동시킨 뒤 사용하려는 registry에 이미지를 push한다.\n    ```bash\n    $ sudo docker load \u003c istio-pilot_${ISTIO_VERSION}.tar\n    $ sudo docker load \u003c istio-proxyv2_${ISTIO_VERSION}.tar\n    $ sudo docker load \u003c jaeger_${JAEGER_VERSION}.tar\n    $ sudo docker load \u003c productpage.tar\n    $ sudo docker load \u003c details.tar\n    $ sudo docker load \u003c ratings.tar\n    $ sudo docker load \u003c reviews-v1.tar\n    $ sudo docker load \u003c reviews-v2.tar\n    $ sudo docker load \u003c reviews-v3.tar\n    \n    $ sudo docker tag istio/pilot:${ISTIO_VERSION} ${REGISTRY}/istio/pilot:${ISTIO_VERSION}\n    $ sudo docker tag istio/proxyv2:${ISTIO_VERSION} ${REGISTRY}/istio/proxyv2:${ISTIO_VERSION}\n    $ sudo docker tag jaegertracing/all-in-one:${JAEGER_VERSION} ${REGISTRY}/jaegertracing/all-in-one:${JAEGER_VERSION}\n    $ sudo docker tag istio/examples-bookinfo-productpage-v1:1.15.0 ${REGISTRY}/istio/examples-bookinfo-productpage-v1:1.15.0\n    $ sudo docker tag istio/examples-bookinfo-details-v1:1.15.0 ${REGISTRY}/istio/examples-bookinfo-details-v1:1.15.0\n    $ sudo docker tag istio/examples-bookinfo-ratings-v1:1.15.0 ${REGISTRY}/istio/examples-bookinfo-ratings-v1:1.15.0\n    $ sudo docker tag istio/examples-bookinfo-reviews-v1:1.15.0 ${REGISTRY}/istio/examples-bookinfo-reviews-v1:1.15.0\n    $ sudo docker tag istio/examples-bookinfo-reviews-v2:1.15.0 ${REGISTRY}/istio/examples-bookinfo-reviews-v2:1.15.0\n    $ sudo docker tag istio/examples-bookinfo-reviews-v3:1.15.0 ${REGISTRY}/istio/examples-bookinfo-reviews-v3:1.15.0\n    \n    $ sudo docker push ${REGISTRY}/istio/pilot:${ISTIO_VERSION}\n    $ sudo docker push ${REGISTRY}/istio/proxyv2:${ISTIO_VERSION}\n    $ sudo docker push ${REGISTRY}/jaegertracing/all-in-one:${JAEGER_VERSION}\n    $ sudo docker push ${REGISTRY}/istio/examples-bookinfo-productpage-v1:1.15.0\n    $ sudo docker push ${REGISTRY}/istio/examples-bookinfo-details-v1:1.15.0\n    $ sudo docker push ${REGISTRY}/istio/examples-bookinfo-ratings-v1:1.15.0\n    $ sudo docker push ${REGISTRY}/istio/examples-bookinfo-reviews-v1:1.15.0\n    $ sudo docker push ${REGISTRY}/istio/examples-bookinfo-reviews-v2:1.15.0\n    $ sudo docker push ${REGISTRY}/istio/examples-bookinfo-reviews-v3:1.15.0\n    ```\n\n\n## Install Steps\n0. [istio yaml 수정](#step0-istio-yaml-%EC%88%98%EC%A0%95)\n1. [istio namespace 및 customresourcedefinition 생성](#step-1-istio-namespace-%EB%B0%8F-customresourcedefinition-%EC%83%9D%EC%84%B1)\n2. [istio-tracing 설치](#step-2-istio-tracing-%EC%84%A4%EC%B9%98)\n3. [istiod 설치](#step-3-istiod-%EC%84%A4%EC%B9%98)\n4. [istio-ingressgateway 설치](#step-4-istio-ingressgateway-%EC%84%A4%EC%B9%98)\n5. [istio metric prometheus에 등록](#step-5-istio-metric-prometheus%EC%97%90-%EB%93%B1%EB%A1%9D)\n6. [bookinfo 예제](#step-6-bookinfo-%EC%98%88%EC%A0%9C)\n\n\n## Step0. istio yaml 수정\n* 목적 : `istio yaml에 이미지 registry, 버전 정보를 수정`\n* 생성 순서 : \n    * 아래의 command를 수정하여 사용하고자 하는 image 버전 정보를 수정한다.\n\t```bash\n\t$ sed -i 's/{jaeger_version}/'${JAEGER_VERSION}'/g' 2.istio-tracing.yaml\n\t$ sed -i 's/{istio_version}/'${ISTIO_VERSION}'/g' 3.istio-core.yaml\n\t$ sed -i 's/{istio_version}/'${ISTIO_VERSION}'/g' 4.istio-ingressgateway.yaml\n\t```\n* 비고 :\n    * `폐쇄망에서 설치를 진행하여 별도의 image registry를 사용하는 경우 registry 정보를 추가로 설정해준다.`\n\t```bash\n\t$ sed -i 's/docker.io\\/jaegertracing\\/all-in-one/'${REGISTRY}'\\/jaegertracing\\/all-in-one/g' 2.istio-tracing.yaml\n\t$ sed -i 's/docker.io\\/istio/'${REGISTRY}'\\/istio/g' 3.istio-core.yaml\n\t$ sed -i 's/docker.io\\/istio\\/proxyv2/'${REGISTRY}'\\/istio\\/proxyv2/g' 4.istio-ingressgateway.yaml\n\t$ sed -i 's/docker.io/'${REGISTRY}'/g' bookinfo.yaml\n\t```\n\n## Step 1. istio namespace 및 customresourcedefinition 생성\n* 목적 : `istio system namespace, clusterrole, clusterrolebinding, serviceaccount, customresourcedefinition 생성`\n* 생성 순서 : [1.istio-base.yaml](yaml/1.istio-base.yaml) 실행 `ex) kubectl apply -f 1.istio-base.yaml`\n\n## Step 2. istio-tracing 설치\n* 목적 : `tracing component jaeger 설치`\n* 생성 순서 : [2.istio-tracing.yaml](yaml/2.istio-tracing.yaml) 실행\n* 비고 : \n    * jaeger ui에 접속하기 위한 서비스를 [원하는 타입](yaml/2.istio-tracing.yaml#L245)으로 변경할 수 있다.\n    * istio-tracing pod가 running임을 확인한 뒤 http://$JAEGER_URL/api/jaeger/search 에 접속해 정상 동작을 확인한다.\n    * hypercloud console 과 연동을 위해 jeager default QUERY_BASE_PATH를 수정하였다.\n\t\n![image](figure/jaeger-ui.png)\n\n## Step 3. istiod 설치\n* 목적 : `istio core component 설치(istiod deployment, sidecar configmap, mutatingwebhookconfiguration...)`\n* 생성 순서 : [3.istio-core.yaml](yaml/3.istio-core.yaml) 실행\n* 비고 : \n    * [istio라는 이름의 configmap](yaml/3.istio-core.yaml#L403)을 수정하여 설정을 변경할 수 있다. 관련 설정은 [istio mesh config](https://istio.io/docs/reference/config/istio.mesh.v1alpha1/#MeshConfig)를 참고한다.\n        * access log format을 변경하고 싶은 경우 [mesh.accessLogFormat](yaml/3.istio-core.yaml#L468)을 원하는 format으로 변경한다.\n        * tracing sampling rate을 변경하고 싶은 경우 [value.traceSampling](yaml/3.istio-core.yaml#L459)을 원하는 값으로 변경한다.\n\n## Step 4. istio-ingressgateway 설치\n* 목적 : `istio ingressgateway 설치`\n* 생성 순서 : [4.istio-ingressgateway.yaml](yaml/4.istio-ingressgateway.yaml) 실행\n\n## Step 5. istio metric prometheus에 등록\n* 목적 : `istio metric을 수집하기 위한 podmonitor 생성`\n* 생성 순서 : [5.istio-metric.yaml](yaml/5.istio-metric.yaml) 실행\n* 비고 : \n    * http://$PROMETHEUS_URL/graph 에 접속해 'envoy_'로 시작하는 istio 관련 metric이 수집되었는지 확인한다.\n    * 만약 istio 관련 metric이 수집되지 않을 경우, Prometheus의 권한설정 문제일 수 있다. [prometheus-clusterRole.yaml](https://github.com/tmax-cloud/install-prometheus/tree/main/manifest/manifests/prometheus-clusterRole.yaml)을 적용하거나 Prometheus를 최신 버전으로 설치한다.\n\n\n## Step 6. bookinfo 예제\n* 목적 : `istio 설치 검증을 위한 bookinfo 예제`\n* 생성 순서 : [bookinfo.yaml](yaml/bookinfo.yaml) 실행\n* 비고 : \n    * bookinfo 예제 배포\n        * application에 접속하기 위해 [service productpage의 타입](yaml/bookinfo.yaml#L278)을 NodePort/LoadBalancer로 변경한다.\n        * bookinfo 예제를 배포할 namespace에 istio-injected=enabled label을 추가한 뒤, bookinfo 예제를 배포한다. \n        ```bash\n        $ kubectl label namespace $YOUR_NAMESPACE istio-injection=enabled\n        $ kubectl apply -f bookinfo.yaml -n $YOUR_NAMESPACE\n        ```\n    * http://$PRODUCTPAGE_URL/productpage 에 접속해 정상적으로 배포되었는지 확인한 뒤, kiali dashboard(http://$KIALI_URL/kiali)에 접속해 아래 그림과 같이 서비스간에 관계를 표현해주는 그래프가 나오는지 확인한다.\n\t\n![image](figure/bookinfo-example.png)\n\n\n## 인증서 갱신 가이드\n\n1. 인증서 갱신을 위한 스크립트 파일을 다운로드 하고 권한을 설정해준다.\n    ```bash\n    $ wget https://raw.githubusercontent.com/istio/tools/release-1.8/bin/root-transition.sh\n    $ chmod +x root-transition.sh\n    ```\n2. 인증서 만료일을 확인한다.\n    ```bash\n    $ ./root-transition.sh check-root\n    ```\n3. 스크립트 파일을 이용하여 인증서를 갱신한다(10년 갱신).\n    ```bash\n    $ ./root-transition.sh root-transition\n    ```\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftmax-cloud%2Finstall-istio","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftmax-cloud%2Finstall-istio","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftmax-cloud%2Finstall-istio/lists"}