Workload Group

WorkloadGroup describes a collection of workload instances. It provides a specification that the workload instances can use to bootstrap their proxies, including the metadata and identity. It is only intended to be used with non-k8s workloads like Virtual Machines, and is meant to mimic the existing sidecar injection and deployment specification model used for Kubernetes workloads to bootstrap Istio proxies.

The following example declares a workload group representing a collection of workloads that will be registered under reviews in namespace bookinfo. The set of labels will be associated with each workload instance during the bootstrap process, and the ports 3550 and 8080 will be associated with the workload group and use service account default. app.kubernetes.io/version is just an arbitrary example of a label.

  1. apiVersion: networking.istio.io/v1alpha3
  2. kind: WorkloadGroup
  3. metadata:
  4. name: reviews
  5. namespace: bookinfo
  6. spec:
  7. metadata:
  8. labels:
  9. app.kubernetes.io/name: reviews
  10. app.kubernetes.io/version: "1.3.4"
  11. template:
  12. ports:
  13. grpc: 3550
  14. http: 8080
  15. serviceAccount: default
  16. probe:
  17. initialDelaySeconds: 5
  18. timeoutSeconds: 3
  19. periodSeconds: 4
  20. successThreshold: 3
  21. failureThreshold: 3
  22. httpGet:
  23. path: /foo/bar
  24. host: 127.0.0.1
  25. port: 3100
  26. scheme: HTTPS
  27. httpHeaders:
  28. - name: Lit-Header
  29. value: Im-The-Best
  1. apiVersion: networking.istio.io/v1beta1
  2. kind: WorkloadGroup
  3. metadata:
  4. name: reviews
  5. namespace: bookinfo
  6. spec:
  7. metadata:
  8. labels:
  9. app.kubernetes.io/name: reviews
  10. app.kubernetes.io/version: "1.3.4"
  11. template:
  12. ports:
  13. grpc: 3550
  14. http: 8080
  15. serviceAccount: default
  16. probe:
  17. initialDelaySeconds: 5
  18. timeoutSeconds: 3
  19. periodSeconds: 4
  20. successThreshold: 3
  21. failureThreshold: 3
  22. httpGet:
  23. path: /foo/bar
  24. host: 127.0.0.1
  25. port: 3100
  26. scheme: HTTPS
  27. httpHeaders:
  28. - name: Lit-Header
  29. value: Im-The-Best

WorkloadGroup

WorkloadGroup enables specifying the properties of a single workload for bootstrap and provides a template for WorkloadEntry, similar to how Deployment specifies properties of workloads via Pod templates. A WorkloadGroup can have more than one WorkloadEntry. WorkloadGroup has no relationship to resources which control service registry like ServiceEntry and as such doesn’t configure host name for these workloads.

FieldTypeDescriptionRequired
metadataObjectMeta

Metadata that will be used for all corresponding WorkloadEntries. User labels for a workload group should be set here in metadata rather than in template.

No
templateWorkloadEntry

Template to be used for the generation of WorkloadEntry resources that belong to this WorkloadGroup. Please note that address and labels fields should not be set in the template, and an empty serviceAccount should default to default. The workload identities (mTLS certificates) will be bootstrapped using the specified service account’s token. Workload entries in this group will be in the same namespace as the workload group, and inherit the labels and annotations from the above metadata field.

Yes
probeReadinessProbe

ReadinessProbe describes the configuration the user must provide for healthchecking on their workload. This configuration mirrors K8S in both syntax and logic for the most part.

No

ReadinessProbe

FieldTypeDescriptionRequired
initialDelaySecondsint32

Number of seconds after the container has started before readiness probes are initiated.

No
timeoutSecondsint32

Number of seconds after which the probe times out. Defaults to 1 second. Minimum value is 1 second.

No
periodSecondsint32

How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is 1 second.

No
successThresholdint32

Minimum consecutive successes for the probe to be considered successful after having failed. Defaults to 1 second.

No
failureThresholdint32

Minimum consecutive failures for the probe to be considered failed after having succeeded. Defaults to 3 seconds.

No
httpGetHTTPHealthCheckConfig (oneof)

httpGet is performed to a given endpoint and the status/able to connect determines health.

No
tcpSocketTCPHealthCheckConfig (oneof)

Health is determined by if the proxy is able to connect.

No
execExecHealthCheckConfig (oneof)

Health is determined by how the command that is executed exited.

No

HTTPHealthCheckConfig

FieldTypeDescriptionRequired
pathstring

Path to access on the HTTP server.

No
portuint32

Port on which the endpoint lives.

Yes
hoststring

Host name to connect to, defaults to the pod IP. You probably want to set “Host” in httpHeaders instead.

No
schemestring

HTTP or HTTPS, defaults to HTTP

No
httpHeadersHTTPHeader[]

Headers the proxy will pass on to make the request. Allows repeated headers.

No

HTTPHeader

FieldTypeDescriptionRequired
namestring

The header field name

No
valuestring

The header field value

No

TCPHealthCheckConfig

FieldTypeDescriptionRequired
hoststring

Host to connect to, defaults to localhost

No
portuint32

Port of host

Yes

ExecHealthCheckConfig

FieldTypeDescriptionRequired
commandstring[]

Command to run. Exit status of 0 is treated as live/healthy and non-zero is unhealthy.

No

WorkloadGroup.ObjectMeta

ObjectMeta describes metadata that will be attached to a WorkloadEntry. It is a subset of the supported Kubernetes metadata.

FieldTypeDescriptionRequired
labelsmap<string, string>

Labels to attach

No
annotationsmap<string, string>

Annotations to attach

No