Skip to content
You are viewing the documentation for Solo Enterprise for Istio, formerly known as Gloo Mesh (OSS APIs).

For the complete documentation index, see llms.txt. Markdown versions of all docs pages are available by appending .md to any docs URL.

Istiod environment variables

Page as Markdown

Review the environment variables that you can set on the istiod control plane to configure features and behavior.

The istiod control plane reads the following environment variables at startup. You can use these variables to configure features and tune performance behavior.

Solo

These environment variables are specific to Solo Enterprise for Istio and are not available in upstream Istio.

VariableTypeDefaultDescription
ENABLE_AMBIENT_ENVOYFILTERbooltrueIf true, ambient waypoints will support EnvoyFilter API.
ENABLE_AMBIENT_ENVOY_MULTI_NETWORKboolfalseIf enabled, ambient multi-network mode will work for Envoy based data-planes (Sidecar, Gateway, Waypoint).
ENABLE_PEERING_DISCOVERYboolfalseIf enabled, cross-cluster service discovery will be done via peering.
ENABLE_WAYPOINT_INTEROPboolfalseIf true, sidecars will short-circuit all processing and connect directly to a waypoint if the destination service has a waypoint.

Ambient

VariableTypeDefaultDescription
AMBIENT_ENABLE_MULTI_NETWORKboolfalseIf true, the multi-network functionality will be enabled.
AMBIENT_ENABLE_STATUSbooltrueIf enabled, status messages for ambient mode will be written to resources. Currently, this does not do leader election, so may be unsafe to enable with multiple replicas.
ENABLE_INGRESS_WAYPOINT_ROUTINGbooltrueIf true, Gateways will call service waypoints if the ‘istio.io/ingress-use-waypoint’ label set on the Service.
ENABLE_LAYERED_WAYPOINT_AUTHORIZATION_POLICIESboolfalseIf enabled, selector based authorization policies will be enforced as L4 policies in front of the waypoint.
PILOT_AUTO_ALLOW_WAYPOINT_POLICYboolfalseIf enabled, zTunnel will receive synthetic authorization policies for each workload ALLOW the Waypoint’s identity. Unless other ALLOW policies are created, this effectively denies traffic that doesn’t go through the waypoint.
PILOT_ENABLE_AMBIENTboolfalseIf enabled, ambient mode can be used. Individual flags configure fine grained enablement; this must be enabled for any ambient functionality.
PILOT_ENABLE_AMBIENT_WAYPOINTSbooltrueIf enabled, controllers required for ambient will run. This is required to run ambient mesh.
PILOT_ENABLE_SENDING_HBONEbooltrueIf enabled, HBONE will be allowed when sending to destinations.
PILOT_ENABLE_SIDECAR_LISTENING_HBONEbooltrueIf enabled, HBONE support can be configured for proxies.
PILOT_PREFER_SENDING_HBONEboolfalseIf enabled, HBONE will be preferred when sending to destinations.

Experimental

VariableTypeDefaultDescription
BYPASS_OVERLOAD_MANAGER_FOR_STATIC_LISTENERSbooltrueIf enabled, overload manager will not be applied to static listeners
ENABLE_100_CONTINUE_HEADERSbooltrueIf enabled, istiod will proxy 100-continue headers as is
ENABLE_DEFERRED_STATS_CREATIONbooltrueIf enabled, Istio will lazily initialize a subset of the stats
ENABLE_ENHANCED_DESTINATIONRULE_MERGEbooltrueIf enabled, Istio merge destinationrules considering their exportTo fields, they will be kept as independent rules if the exportTos are not equal.
ENABLE_HCM_INTERNAL_NETWORKSboolfalseIf enable, endpoints defined in mesh networks will be configured as internal addresses in Http Connection Manager
ENABLE_LEADER_ELECTIONbooltrueIf enabled (default), starts a leader election client and gains leadership before executing controllers. If false, it assumes that only one instance of istiod is running and skips leader election.
ENABLE_LOCALITY_WEIGHTED_LB_CONFIGboolfalseIf enabled, always set LocalityWeightedLbConfig for a cluster, otherwise only apply it when locality lb is specified by DestinationRule for a service
ENABLE_MCS_AUTO_EXPORTboolfalseIf enabled, istiod will automatically generate Kubernetes Multi-Cluster Services (MCS) ServiceExport resources for every service in the mesh. Services defined to be cluster-local in MeshConfig are excluded.
ENABLE_MCS_CLUSTER_LOCALboolfalseIf enabled, istiod will treat the host <svc>.<namespace>.svc.cluster.local as defined by the Kubernetes Multi-Cluster Services (MCS) spec. In this mode, requests to cluster.local will be routed to only those endpoints residing within the same cluster as the client. Requires that both ENABLE_MCS_SERVICE_DISCOVERY and ENABLE_MCS_HOST also be enabled.
ENABLE_MCS_HOSTboolfalseIf enabled, istiod will configure a Kubernetes Multi-Cluster Services (MCS) host (..svc.clusterset.local) for each service exported (via ServiceExport) in at least one cluster. Clients must, however, be able to successfully lookup these DNS hosts. That means that either Istio DNS interception must be enabled or an MCS controller must be used. Requires that ENABLE_MCS_SERVICE_DISCOVERY also be enabled.
ENABLE_MCS_SERVICE_DISCOVERYboolfalseIf enabled, istiod will enable Kubernetes Multi-Cluster Services (MCS) service discovery mode. In this mode, service endpoints in a cluster will only be discoverable within the same cluster unless explicitly exported via ServiceExport.
ENABLE_NATIVE_SIDECARSboolfalseIf set, used Kubernetes native Sidecar container support. Requires SidecarContainer feature flag.
ENABLE_TLS_ON_SIDECAR_INGRESSboolfalseIf enabled, the TLS configuration on Sidecar.ingress will take effect
ISTIO_DELTA_XDSbooltrueIf enabled, pilot will only send the delta configs as opposed to the state of the world configuration on a Resource Request. While this feature uses the delta xds api, it may still occasionally send unchanged configurations instead of just the actual deltas.
ISTIO_DUAL_STACKboolfalseIf true, Istio will enable the Dual Stack feature.
MCS_API_GROUPstring"multicluster.x-k8s.io"The group to be used for the Kubernetes Multi-Cluster Services (MCS) API.
MCS_API_VERSIONstring"v1alpha1"The version to be used for the Kubernetes Multi-Cluster Services (MCS) API.
PILOT_ALLOW_SIDECAR_SERVICE_INBOUND_LISTENER_MERGEboolfalseIf set, it allows creating inbound listeners for service ports and sidecar ingress listeners
PILOT_ANALYSIS_INTERVALduration10sIf analysis is enabled, pilot will run istio analyzers using this value as interval in seconds Istio Resources
PILOT_DRAINING_LABELstring"istio.io/draining"If not empty, endpoints with the label value present will be sent with status DRAINING.
PILOT_ENABLE_ALPHA_GATEWAY_APIboolfalseIf this is set to true, support for alpha APIs in the Kubernetes gateway-api (github.com/kubernetes-sigs/gateway-api) will be enabled. In addition to this being enabled, the gateway-api CRDs need to be installed.
PILOT_ENABLE_ANALYSISboolfalseIf enabled, pilot will run istio analyzers and write analysis errors to the Status field of any Istio Resources
PILOT_ENABLE_GATEWAY_APIbooltrueIf this is set to true, support for Kubernetes gateway-api (github.com/kubernetes-sigs/gateway-api) will be enabled. In addition to this being enabled, the gateway-api CRDs need to be installed.
PILOT_ENABLE_GATEWAY_API_DEPLOYMENT_CONTROLLERbooltrueIf this is set to true, gateway-api resources will automatically provision in cluster deployment, services, etc
PILOT_ENABLE_GATEWAY_API_GATEWAYCLASS_CONTROLLERbooltrueIf this is set to true, istiod will create and manage its default GatewayClasses
PILOT_ENABLE_GATEWAY_API_STATUSbooltrueIf this is set to true, gateway-api resources will have status written to them
PILOT_ENABLE_PERSISTENT_SESSION_FILTERboolfalseIf enabled, Istiod sets up persistent session filter for listeners, if services have ‘PILOT_PERSISTENT_SESSION_LABEL’ set.
PILOT_ENABLE_QUIC_LISTENERSboolfalseIf true, QUIC listeners will be generated wherever there are listeners terminating TLS on gateways if the gateway service exposes a UDP port with the same number (for example 443/TCP and 443/UDP)
PILOT_FILTER_GATEWAY_CLUSTER_CONFIGboolfalseIf enabled, Pilot will send only clusters that referenced in gateway virtual services attached to gateway
PILOT_PERSISTENT_SESSION_HEADER_LABELstring"istio.io/persistent-session-header"If not empty, services with this label will use header based persistent sessions
PILOT_PERSISTENT_SESSION_LABELstring"istio.io/persistent-session"If not empty, services with this label will use cookie based persistent sessions
PILOT_SEND_UNHEALTHY_ENDPOINTSboolfalseIf enabled, Pilot will include unhealthy endpoints in EDS pushes and even if they are sent Envoy does not use them for load balancing. To avoid, sending traffic to non ready endpoints, enabling this flag, disables panic threshold in Envoy i.e. Envoy does not load balance requests to unhealthy/non-ready hosts even if the percentage of healthy hosts fall below minimum health percentage(panic threshold).
PILOT_UNIFIED_SIDECAR_SCOPEbooltrueIf true, unified SidecarScope creation will be used. This is only intended as a temporary feature flag for backwards compatibility.

Pilot

VariableTypeDefaultDescription
CLUSTER_IDstringconstants.DefaultClusterNameDefines the cluster and service registry that this Istiod instance belongs to
DEBUG_ENDPOINT_AUTH_ALLOWED_NAMESPACESstring""Comma separated list of namespaces to allow access to debug endpoints. Only used if ENABLE_DEBUG_ENDPOINT_AUTH is enabled. The system namespaceis always authorized.
ENABLE_CA_SERVERbooltrueIf this is set to false, will not create CA server in istiod.
ENABLE_CLUSTER_TRUST_BUNDLE_APIboolfalseIf enabled, uses the ClusterTrustBundle API instead of ConfigMaps to store the root certificate in the cluster.
ENABLE_DEBUG_ENDPOINT_AUTHbooltrueEnforce namespace-based authorization on debug endpoints. Non-system namespaces restricted to config_dump/ndsz/edsz for same-namespace proxies only.
ENABLE_DEBUG_ON_HTTPbooltrueIf this is set to false, the debug interface will not be enabled, recommended for production
ENABLE_GATEWAY_API_MANUAL_DEPLOYMENTbooltrueIf true, allows users to bind Gateway API resources to existing gateway deployments.
ENABLE_INBOUND_RETRY_POLICYbooltrueIf true, enables retry policy for inbound routes which automatically retries requests that were reset before it reaches the service.
ENABLE_MULTICLUSTER_HEADLESSbooltrueIf true, the DNS name table for a headless service will resolve to same-network endpoints in any cluster.
ENABLE_PROXY_FIND_POD_BY_IPbooltrueIf enabled, the pod controller will allow find pods matching proxies by IP if it fails to find them by name.
ENABLE_SELECTOR_BASED_K8S_GATEWAY_POLICYbooltrueIf disabled, Gateway API gateways will ignore workloadSelector policies, onlyapplying policies that select the gateway with a targetRef.
ENABLE_VTPROTOBUFbooltrueIf true, will use optimized vtprotobuf based marshaling. Requires a build with -tags=vtprotobuf.
EXCLUDE_UNSAFE_503_FROM_DEFAULT_RETRYbooltrueIf true, excludes unsafe retry on 503 from default retry policy.
EXTERNAL_ISTIODboolfalseIf this is set to true, one Istiod will control remote clusters including CA.
INJECTION_WEBHOOK_CONFIG_NAMEstring"istio-sidecar-injector"Name of the mutatingwebhookconfiguration to patch, if istioctl is not used.
ISTIOD_CUSTOM_HOSTstring""Custom host name of istiod that istiod signs the server cert. Multiple custom host names are supported, and multiple values are separated by commas.
ISTIO_AGENT_ENABLE_WASM_REMOTE_LOAD_CONVERSIONbooltrueIf enabled, Istio agent will intercept ECDS resource update, downloads Wasm module, and replaces Wasm module remote load with downloaded local module file.
ISTIO_ENABLE_IPV4_OUTBOUND_LISTENER_FOR_IPV6_CLUSTERSboolfalseIf true, pilot will configure an additional IPv4 listener for outbound traffic in IPv6 only clusters, e.g. AWS EKS IPv6 only clusters.
ISTIO_KUBE_CLIENT_CONTENT_TYPEstring"protobuf"The content type to use for Kubernetes clients. Defaults to protobuf. Valid options: [protobuf, json]
ISTIO_MULTIROOT_MESHboolfalseIf enabled, mesh will support certificates signed by more than one trustAnchor for ISTIO_MUTUAL mTLS
ISTIO_WATCH_NAMESPACEstring""If set, limit Kubernetes watches to a single namespace. Warning: only a single namespace can be set.
ISTIO_WORKLOAD_ENTRY_VALIDATE_IDENTITYbooltrueIf enabled, will validate the identity of a workload matches the identity of the WorkloadEntry it is associating with for health checks and auto registration. This flag is added for backwards compatibility only and will be removed in future releases
JWKS_RESOLVER_INSECURE_SKIP_VERIFYboolfalseIf enabled, istiod will skip verifying the certificate of the JWKS server.
LABEL_CANONICAL_SERVICES_FOR_MESH_EXTERNAL_SERVICE_ENTRIESboolfalseIf enabled, metadata representing canonical services for ServiceEntry resources with a location of mesh_external will be populatedin the cluster metadata for those endpoints.
LOCAL_CLUSTER_SECRET_WATCHERboolfalseIf enabled, the cluster secret watcher will watch the namespace of the external cluster instead of config cluster
MAX_CONNECTIONS_PER_SOCKET_EVENT_LOOPint1The maximum number of connections to accept from the kernel per socket event. Set this to ‘0’ to accept unlimited connections.
PILOT_CERT_PROVIDERstringconstants.CertProviderIstiodThe provider of Pilot DNS certificate. K8S RA will be used for k8s.io/NAME. ‘istiod’ value will sign using Istio build in CA. Other values will not not generate TLS certs, but still distribute ./etc/certs/root-cert.pem. Only used if custom certificates are not mounted.
PILOT_DISABLE_MX_ALPNboolfalseIf true, pilot will not put istio-peer-exchange ALPN into TLS handshake configuration.
PILOT_DNS_CARES_UDP_MAX_QUERIESuint32100Sets the udp_max_queries option in Envoy for the Cares DNS resolver. Defaults to 0, an unlimited number of queries. See extensions.network.dns_resolver.cares.v3.CaresDnsResolverConfig in https://www.envoyproxy.io/docs/envoy/latest/api-v3/extensions/network/dns_resolver/cares/v3/cares_dns_resolver.proto and ARES_OPT_UDP_MAX_QUERIES in https://c-ares.org/docs/ares_init.html
PILOT_DNS_JITTER_DURATIONduration100msJitter added to periodic DNS resolution
PILOT_ENABLE_ALPN_FILTERbooltrueIf true, pilot will add Istio ALPN filters, required for proper protocol sniffing.
PILOT_ENABLE_CROSS_CLUSTER_WORKLOAD_ENTRYbooltrueIf enabled, pilot will read WorkloadEntry from other clusters, selectable by Services in that cluster.
PILOT_ENABLE_IP_AUTOALLOCATEbooltrueIf enabled, pilot will start a controller that assigns IP addresses to ServiceEntry which do not have a user-supplied IP. This, when combined with DNS capture allows for tcp routing of traffic sent to the ServiceEntry.
PILOT_ENABLE_K8S_SELECT_WORKLOAD_ENTRIESbooltrueIf enabled, Kubernetes services with selectors will select workload entries with matching labels. It is safe to disable it if you are quite sure you don’t need this feature
PILOT_ENABLE_NODE_UNTAINT_CONTROLLERSboolfalseIf enabled, controller that untaints nodes with cni pods ready will run. This should be enabled if you disabled ambient init containers.
PILOT_ENABLE_ROUTE_COLLAPSE_OPTIMIZATIONbooltrueIf true, Pilot will merge virtual hosts with the same routes into a single virtual host, as an optimization.
PILOT_ENABLE_SERVICEENTRY_SELECT_PODSbooltrueIf enabled, service entries with selectors will select pods from the cluster. It is safe to disable it if you are quite sure you don’t need this feature
PILOT_ENABLE_WORKLOAD_ENTRY_AUTOREGISTRATIONbooltrueEnables auto-registering WorkloadEntries based on associated WorkloadGroups upon XDS connection by the workload.
PILOT_ENABLE_WORKLOAD_ENTRY_HEALTHCHECKSbooltrueEnables automatic health checks of WorkloadEntries based on the config provided in the associated WorkloadGroup
PILOT_ENVOY_FILTER_STATSboolfalseIf true, Pilot will collect metrics for envoy filter operations.
PILOT_GATEWAY_API_CONTROLLER_NAMEstring"istio.io/gateway-controller"Gateway API controller name. istiod will only reconcile Gateway API resources referencing a GatewayClass with this controller name
PILOT_GATEWAY_API_DEFAULT_GATEWAYCLASS_NAMEstring"istio"Name of the default GatewayClass
PILOT_HTTP10boolfalseEnables the use of HTTP 1.0 in the outbound HTTP listeners, to support legacy applications.
PILOT_INSECURE_MULTICLUSTER_KUBECONFIG_OPTIONSstring""Comma separated list of potentially insecure kubeconfig authentication options that are allowed for multicluster authentication.Support values: all authProviders (gcp, azure, exec, openstack), clientKey, clientCertificate, tokenFile, and exec.
PILOT_JWT_ENABLE_REMOTE_JWKSstring"false"Mode of fetching JWKs from JwksUri in RequestAuthentication. Supported value: istiod, false, hybrid, true, envoy. The client fetching JWKs is as following: istiod/false - Istiod; hybrid/true - Envoy and fallback to Istiod if JWKs server is external; envoy - Envoy.
PILOT_JWT_PUB_KEY_REFRESH_INTERVALduration20mThe interval for istiod to fetch the jwks_uri for the jwks public key.
PILOT_MULTI_NETWORK_DISCOVER_GATEWAY_APIbooltrueIf true, Pilot will discover labeled Kubernetes gateway objects as multi-network gateways.
PILOT_REMOTE_CLUSTER_TIMEOUTduration30sAfter this timeout expires, pilot can become ready without syncing data from clusters added via remote-secrets. Setting the timeout to 0 disables this behavior.
PILOT_SCOPE_GATEWAY_TO_NAMESPACEboolfalseIf enabled, a gateway workload can only select gateway resources in the same namespace. Gateways with same selectors in different namespaces will not be applicable.
PILOT_SOLO_ENABLE_AUTO_WAYPOINTbooltrueIf true, pilot will automatically create a waypoint for namespaces that have the istio.io/use-waypoint label set to auto.
PILOT_WORKLOAD_ENTRY_GRACE_PERIODduration10sThe amount of time an auto-registered workload can remain disconnected from all Pilot instances before the associated WorkloadEntry is cleaned up.
PREFER_DESTINATIONRULE_TLS_FOR_EXTERNAL_SERVICESbooltrueIf true, external services will prefer the TLS settings from DestinationRules over the metadata TLS settings.
RESOLVE_HOSTNAME_GATEWAYSbooltrueIf true, hostnames in the LoadBalancer addresses of a Service will be resolved at the control plane for use in cross-network gateways.
SHARED_MESH_CONFIGstring""Additional config map to load for shared MeshConfig settings. The standard mesh config will take precedence.
UNSAFE_ENABLE_ADMIN_ENDPOINTSboolfalseIf this is set to true, dangerous admin endpoints will be exposed on the debug interface. Not recommended for production.
UNSAFE_PILOT_ENABLE_DELTA_TESTboolfalseIf enabled, addition runtime tests for Delta XDS efficiency are added. These checks are extremely expensive, so this should be used only for testing, not production.
UNSAFE_PILOT_ENABLE_RUNTIME_ASSERTIONSboolfalseIf enabled, addition runtime asserts will be performed. These checks are both expensive and panic on failure. As a result, this should be used only for testing.
VALIDATION_WEBHOOK_CONFIG_NAMEstring"istio-istio-system"If not empty, the controller will automatically patch validatingwebhookconfiguration when the CA certificate changes. Only works in kubernetes environment.

Security

VariableTypeDefaultDescription
CA_TRUSTED_NODE_ACCOUNTSstring""If set, the list of service accounts that are allowed to use node authentication for CSRs. Node authentication allows an identity to create CSRs on behalf of other identities, but only if there is a pod running on the same node with that identity. This is intended for use with node proxies.
CERT_SIGNER_DOMAINstring""The cert signer domain info
PILOT_ENABLE_XDS_IDENTITY_CHECKbooltrueIf enabled, pilot will authorize XDS clients, to ensure they are acting only as namespaces they have permissions for.
PILOT_SKIP_VALIDATE_TRUST_DOMAINboolfalseSkip validating the peer is from the same trust domain when mTLS is enabled in authentication policy
TRUSTED_GATEWAY_CIDRstring""If set, any connections from gateway to Istiod with this CIDR range are treated as trusted for using authentication mechanisms like XFCC. This can only be used when the network where Istiod and the authenticating gateways are running in a trusted/secure network
USE_CACERTS_FOR_SELF_SIGNED_CAboolfalseIf enabled, istiod will use a secret named cacerts to store its self-signed istio-generated root certificate.
XDS_AUTHbooltrueIf true, will authenticate XDS clients.

Telemetry

VariableTypeDefaultDescription
ISTIO_ENABLE_CONTROLLER_QUEUE_METRICSboolfalseIf enabled, publishes metrics for queue depth, latency and processing times.
METRIC_GRACEFUL_DELETION_INTERVALduration5mMetric expiry graceful deletion interval. No-op if METRIC_ROTATION_INTERVAL is disabled.
METRIC_ROTATION_INTERVALduration0sMetric scope rotation interval, set to 0 to disable the metric scope rotation
PILOT_ENABLE_METADATA_EXCHANGEbooltrueIf true, pilot will add metadata exchange filters, which will be consumed by telemetry filter.
PILOT_ENABLE_TELEMETRY_LABELbooltrueIf true, pilot will add telemetry related metadata to cluster and endpoint resources, which will be consumed by telemetry filter.
PILOT_ENDPOINT_TELEMETRY_LABELbooltrueIf true, pilot will add telemetry related metadata to Endpoint resource, which will be consumed by telemetry filter.
PILOT_MX_ADDITIONAL_LABELSstring""Comma separated list of additional labels to be added to metadata exchange filter.
PILOT_SPAWN_UPSTREAM_SPAN_FOR_GATEWAYboolfalseIf true, separate tracing span for each upstream request for gateway.
PILOT_TRACE_SAMPLINGfloat641.0Sets the mesh-wide trace sampling percentage. Should be 0.0 - 100.0. Precision to 0.01. Default is 1.0.

Tuning

VariableTypeDefaultDescription
ISTIO_GPRC_MAXRECVMSGSIZEint4*1024*1024Sets the max receive buffer size of gRPC stream in bytes.
ISTIO_GPRC_MAXSTREAMSint100000Sets the maximum number of concurrent grpc streams.
MUTEX_PROFILE_FRACTIONint1000If set to a non-zero value, enables mutex profiling a rate of 1/MUTEX_PROFILE_FRACTION events. For example, ‘1000’ will record 0.1% of events. Set to 0 to disable entirely.
PILOT_CONVERT_SIDECAR_SCOPE_CONCURRENCYint1Used to adjust the concurrency of SidecarScope conversions. When istiod is deployed on a multi-core CPU server, increasing this value will help to use the CPU to accelerate configuration push, but it also means that istiod will consume more CPU resources.
PILOT_DEBOUNCE_AFTERduration100msThe delay added to config/registry events for debouncing. This will delay the push by at least this interval. If no change is detected within this period, the push will happen, otherwise we’ll keep delaying until things settle, up to a max of PILOT_DEBOUNCE_MAX.
PILOT_DEBOUNCE_MAXduration10sThe maximum amount of time to wait for events while debouncing. If events keep showing up with no breaks for this time, we’ll trigger a push.
PILOT_ENABLE_EDS_DEBOUNCEbooltrueIf enabled, Pilot will include EDS pushes in the push debouncing, configured by PILOT_DEBOUNCE_AFTER and PILOT_DEBOUNCE_MAX. EDS pushes may be delayed, but there will be fewer pushes. By default this is enabled
PILOT_MAX_REQUESTS_PER_SECONDfloat640.0Limits the number of incoming XDS requests per second. On larger machines this can be increased to handle more proxies concurrently. If set to 0 or unset, the max will be automatically determined based on the machine size
PILOT_PUSH_THROTTLEint0Limits the number of concurrent pushes allowed. On larger machines this can be increased for faster pushes. If set to 0 or unset, the max will be automatically determined based on the machine size
PILOT_STATUS_BURSTint500If status is enabled, controls the Burst rate with which status will be updated. See https://godoc.org/k8s.io/client-go/rest#Config Burst
PILOT_STATUS_MAX_WORKERSint100The maximum number of workers Pilot will use to keep configuration status up to date. Smaller numbers will result in higher status latency, but larger numbers may impact CPU in high scale environments.
PILOT_STATUS_QPSint100If status is enabled, controls the QPS with which status will be updated. See https://godoc.org/k8s.io/client-go/rest#Config QPS
PILOT_STATUS_UPDATE_INTERVALduration500msInterval to update the XDS distribution status.
PILOT_XDS_CACHE_INDEX_CLEAR_INTERVALduration5sThe interval for xds cache index clearing.
PILOT_XDS_CACHE_SIZEint60000The maximum number of cache entries for the XDS cache.

XDS

VariableTypeDefaultDescription
PILOT_ENABLE_CDS_CACHEbooltrueIf true, Pilot will cache CDS responses. Note: this depends on PILOT_ENABLE_XDS_CACHE.
PILOT_ENABLE_EDS_FOR_HEADLESS_SERVICESboolfalseIf enabled, for headless service in Kubernetes, pilot will send endpoints over EDS, allowing the sidecar to load balance among pods in the headless service. This feature should be enabled if applications access all services explicitly via a HTTP proxy port in the sidecar.
PILOT_ENABLE_MONGO_FILTERbooltrueEnableMongoFilter enables injection of envoy.filters.network.mongo_proxy in the filter chain.
PILOT_ENABLE_MYSQL_FILTERboolfalseEnableMysqlFilter enables injection of envoy.filters.network.mysql_proxy in the filter chain.
PILOT_ENABLE_RDS_CACHEbooltrueIf true, Pilot will cache RDS responses. Note: this depends on PILOT_ENABLE_XDS_CACHE.
PILOT_ENABLE_REDIS_FILTERboolfalseEnableRedisFilter enables injection of envoy.filters.network.redis_proxy in the filter chain.
PILOT_ENABLE_XDS_CACHEbooltrueIf true, Pilot will cache XDS responses.
PILOT_SIDECAR_USE_REMOTE_ADDRESSboolfalseUseRemoteAddress sets useRemoteAddress to true for sidecar outbound listeners.
PILOT_XDS_CACHE_STATSboolfalseIf true, Pilot will collect metrics for XDS cache efficiency.