Skip to content
You are viewing the documentation for Solo Enterprise for Istio, formerly known as Gloo Mesh (OSS APIs).

For the complete documentation index, see llms.txt. Markdown versions of all docs pages are available by appending .md to any docs URL.

Istiod environment variables

Page as Markdown

Review the environment variables that you can set on the istiod control plane to configure features and behavior.

The istiod control plane reads the following environment variables at startup. You can use these variables to configure features and tune performance behavior.

Solo

These environment variables are specific to Solo Enterprise for Istio and are not available in upstream Istio.

VariableTypeDefaultDescription
DISABLE_LEGACY_MULTICLUSTERboolfalseIf enabled, cross-cluster service discovery can ONLY be done via peering. Remote secrets will be ignored.
ENABLE_AMBIENT_ENVOYFILTERbooltrueIf true, ambient waypoints will support EnvoyFilter API.
ENABLE_AMBIENT_ENVOY_MULTI_NETWORKboolfalseIf enabled, ambient multi-network mode will work for Envoy based data-planes (Sidecar, Gateway, Waypoint).
ENABLE_PEERING_DISCOVERYboolfalseIf enabled, cross-cluster service discovery will be done via peering.
ENABLE_PEERING_LABEL_PROPAGATIONstring""If enabled, matching label keys on the source k8s resource are propagated to the corresponding auto-generated WorkloadEntries. This includes global Services and for flat-networking setups, pods. Alternatively, the keyword ‘all’ can be specified to propagate all labels.Format: <label key 1>,<label key 2>
ENABLE_SERVICE_INHERITANCEboolfalseIf enabled, policies that target or have a parent to a Service will also include the Global Service.
ENABLE_WAYPOINT_INTEROPboolfalseIf true, sidecars will short-circuit all processing and connect directly to a waypoint if the destination service has a waypoint.
PERMIT_CROSS_NAMESPACE_RESOURCE_ACCESSstring""If enabled, cross-namespace resource access will be allowed for the given proxies. Format: namespace1/proxy1,namespace2/proxy2,namespace3/proxy3
PILOT_PEERING_WE_EXCLUSION_LABELSstring"gloo.solo.io/parent_name"Comma-separated label keys. WorkloadEntries carrying any of these keys will never be selected by peering-generated ServiceEntries. Defaults to excluding any WEs with the gloo.solo.io/parent_name label.

Ambient

VariableTypeDefaultDescription
AMBIENT_ENABLE_BAGGAGEboolfalseIf true, enables waypoints to use baggage header to discover and propagate peer metadata for metrics.
AMBIENT_ENABLE_DRY_RUN_AUTHORIZATION_POLICYboolfalseIf enabled, ztunnel will be configured with dry-run authorizationPolicies. Ensure ztunnel is 1.29 or above before enabling this feature. Older ztunnel will accept dry-run policies, but enforce them instead of only logging.
AMBIENT_ENABLE_MULTI_NETWORKboolfalseIf true, the multi-network functionality will be enabled.
AMBIENT_ENABLE_MULTI_NETWORK_INGRESSboolfalseIf true and AMBIENT_ENABLE_MULTI_NETWORK is also true, it will enable ingress gateways to route requests to clusters on remote networks while by default ingress gateways will keep traffic local.
AMBIENT_ENABLE_MULTI_NETWORK_WAYPOINTbooltrueIf true and AMBIENT_ENABLE_MULTI_NETWORK is also true, it will enable waypoints to route requests to clusters on remote networks, while by default waypoints will keep traffic local.
AMBIENT_ENABLE_STATUSbooltrueIf enabled, status messages for ambient mode will be written to resources. Currently, this does not do leader election, so may be unsafe to enable with multiple replicas.
AMBIENT_SCOPED_ADDRESS_PUSHESbooltrueIf enabled, ambient Address updates only trigger pushes for waypoints whose attached services or workloads changed, and are skipped entirely for sidecar and gateway proxies. If disabled, every Address update triggers a full LDS/CDS/EDS push to all waypoints and an RDS push to all proxies.
ENABLE_INGRESS_WAYPOINT_ROUTINGbooltrueIf true, Gateways will call service waypoints if the ‘istio.io/ingress-use-waypoint’ label set on the Service.
ENABLE_LAYERED_WAYPOINT_AUTHORIZATION_POLICIESboolfalseIf enabled, selector based authorization policies will be enforced as L4 policies in front of the waypoint.
PILOT_AUTO_ALLOW_WAYPOINT_POLICYboolfalseIf enabled, zTunnel will receive synthetic authorization policies for each workload ALLOW the Waypoint’s identity. Unless other ALLOW policies are created, this effectively denies traffic that doesn’t go through the waypoint.
PILOT_ENABLE_AMBIENTboolfalseIf enabled, ambient mode can be used. Individual flags configure fine grained enablement; this must be enabled for any ambient functionality.
PILOT_ENABLE_AMBIENT_WAYPOINTSbooltrueIf enabled, controllers required for ambient will run. This is required to run ambient mesh.
PILOT_ENABLE_SENDING_HBONEbooltrueIf enabled, HBONE will be allowed when sending to destinations.
PILOT_ENABLE_SIDECAR_LISTENING_HBONEbooltrueIf enabled, HBONE support can be configured for proxies.
PILOT_HBONE_INITIAL_CONNECTION_WINDOW_SIZEuint320Sets the HTTP/2 initial_connection_window_size on HBONE CONNECT upstream clusters generated for waypoints and east-west gateways. If 0 (the default), the field is left unset so Envoy’s built-in default applies.
PILOT_HBONE_INITIAL_STREAM_WINDOW_SIZEuint320Sets the HTTP/2 initial_stream_window_size on HBONE CONNECT upstream clusters generated for waypoints and east-west gateways. If 0 (the default), the field is left unset so Envoy’s built-in default applies.
PILOT_PREFER_SENDING_HBONEboolfalseIf enabled, HBONE will be preferred when sending to destinations.

Experimental

VariableTypeDefaultDescription
ENABLE_100_CONTINUE_HEADERSbooltrueIf enabled, istiod will proxy 100-continue headers as is
ENABLE_ENHANCED_DESTINATIONRULE_MERGEbooltrueIf enabled, Istio merge destinationrules considering their exportTo fields, they will be kept as independent rules if the exportTos are not equal.
ENABLE_GATEWAY_API_INFERENCE_EXTENSIONboolfalseIf true, support gateway inference extension routing apis
ENABLE_HCM_INTERNAL_NETWORKSboolfalseIf enable, endpoints defined in mesh networks will be configured as internal addresses in Http Connection Manager
ENABLE_LEADER_ELECTIONbooltrueIf enabled (default), starts a leader election client and gains leadership before executing controllers. If false, it assumes that only one instance of istiod is running and skips leader election.
ENABLE_LOCALITY_WEIGHTED_LB_CONFIGboolfalseIf enabled, always set LocalityWeightedLbConfig for a cluster, otherwise only apply it when locality lb is specified by DestinationRule for a service
ENABLE_MCS_AUTO_EXPORTboolfalseIf enabled, istiod will automatically generate Kubernetes Multi-Cluster Services (MCS) ServiceExport resources for every service in the mesh. Services defined to be cluster-local in MeshConfig are excluded.
ENABLE_MCS_CLUSTER_LOCALboolfalseIf enabled, istiod will treat the host <svc>.<namespace>.svc.cluster.local as defined by the Kubernetes Multi-Cluster Services (MCS) spec. In this mode, requests to cluster.local will be routed to only those endpoints residing within the same cluster as the client. Requires that both ENABLE_MCS_SERVICE_DISCOVERY and ENABLE_MCS_HOST also be enabled.
ENABLE_MCS_HOSTboolfalseIf enabled, istiod will configure a Kubernetes Multi-Cluster Services (MCS) host (..svc.clusterset.local) for each service exported (via ServiceExport) in at least one cluster. Clients must, however, be able to successfully lookup these DNS hosts. That means that either Istio DNS interception must be enabled or an MCS controller must be used. Requires that ENABLE_MCS_SERVICE_DISCOVERY also be enabled.
ENABLE_MCS_SERVICE_DISCOVERYboolfalseIf enabled, istiod will enable Kubernetes Multi-Cluster Services (MCS) service discovery mode. In this mode, service endpoints in a cluster will only be discoverable within the same cluster unless explicitly exported via ServiceExport.
ENABLE_TLS_ON_SIDECAR_INGRESSboolfalseIf enabled, the TLS configuration on Sidecar.ingress will take effect
ENABLE_WILDCARD_HOST_SERVICE_ENTRIES_FOR_TLSboolfalseIf enabled, ServiceEntries with wildcard hosts and dynamic dns resolution will be allowed for TLS traffic. This is a security risk, susceptible to SNI spoofing, and should be used with caution. Only consider using this feature if the client is trusted and you understand the risks.
ENVOY_STATUS_PORT_ENABLE_PROXY_PROTOCOLboolfalseIf enabled, Envoy will support requests with proxy protocol on its status port
ISTIO_DELTA_XDSbooltrueIf enabled, pilot will only send the delta configs as opposed to the state of the world configuration on a Resource Request. While this feature uses the delta xds api, it may still occasionally send unchanged configurations instead of just the actual deltas.
ISTIO_DUAL_STACKboolfalseIf true, Istio will enable the Dual Stack feature.
MCS_API_GROUPstring"multicluster.x-k8s.io"The group to be used for the Kubernetes Multi-Cluster Services (MCS) API.
MCS_API_VERSIONstring"v1alpha1"The version to be used for the Kubernetes Multi-Cluster Services (MCS) API.
PILOT_ALLOW_SIDECAR_SERVICE_INBOUND_LISTENER_MERGEboolfalseIf set, it allows creating inbound listeners for service ports and sidecar ingress listeners
PILOT_ANALYSIS_INTERVALduration10sIf analysis is enabled, pilot will run istio analyzers using this value as interval in seconds Istio Resources
PILOT_CA_CERT_CONFIGMAPstring"istio-ca-root-cert"The name of the ConfigMap that stores the Root CA Certificate that is used by istiod
PILOT_CRL_CONFIGMAPstring"istio-ca-crl"The name of the ConfigMap that stores the Certificate Revocation List (CRL) for a plugged-in CA
PILOT_DRAINING_LABELstring"istio.io/draining"If not empty, endpoints with the label value present will be sent with status DRAINING.
PILOT_ENABLE_AGENTGATEWAYboolfalseIf enabled, the istio-agentgateway GatewayClass will be enabled.
PILOT_ENABLE_ALPHA_GATEWAY_APIboolfalseIf this is set to true, support for alpha APIs in the Kubernetes gateway-api (github.com/kubernetes-sigs/gateway-api) will be enabled. In addition to this being enabled, the gateway-api CRDs need to be installed.
PILOT_ENABLE_ANALYSISboolfalseIf enabled, pilot will run istio analyzers and write analysis errors to the Status field of any Istio Resources
PILOT_ENABLE_GATEWAY_APIbooltrueIf this is set to true, support for Kubernetes gateway-api (github.com/kubernetes-sigs/gateway-api) will be enabled. In addition to this being enabled, the gateway-api CRDs need to be installed.
PILOT_ENABLE_GATEWAY_API_COPY_LABELS_ANNOTATIONSbooltrueIf this is set to false, istiod will not copy any attributes from the Gateway resource onto its related Deployment resources.
PILOT_ENABLE_GATEWAY_API_DEPLOYMENT_CONTROLLERbooltrueIf this is set to true, gateway-api resources will automatically provision in cluster deployment, services, etc
PILOT_ENABLE_GATEWAY_API_GATEWAYCLASS_CONTROLLERbooltrueIf this is set to true, istiod will create and manage its default GatewayClasses
PILOT_ENABLE_GATEWAY_API_STATUSbooltrueIf this is set to true, gateway-api resources will have status written to them
PILOT_ENABLE_PERSISTENT_SESSION_FILTERboolfalseIf enabled, Istiod sets up persistent session filter for listeners, if services have ‘PILOT_PERSISTENT_SESSION_LABEL’ set.
PILOT_ENABLE_QUIC_LISTENERSboolfalseIf true, QUIC listeners will be generated wherever there are listeners terminating TLS on gateways if the gateway service exposes a UDP port with the same number (for example 443/TCP and 443/UDP)
PILOT_FILTER_GATEWAY_CLUSTER_CONFIGboolfalseIf enabled, Pilot will send only clusters that referenced in gateway virtual services attached to gateway
PILOT_IGNORE_RESOURCESstring""If set, the resources set on this list will be ignored and never reconciled.This value should be a comma-separated list of resources names.Items on this list can be prefixed with a ‘*.’ meaning a whole group should be ignored.
PILOT_INCLUDE_RESOURCESstring""If set, and combined with ‘PILOT_IGNORE_RESOURCES’ the resources set on this list will not be ignored.This value should be a comma-separated list of resources names.Items on this list can be prefixed with a ‘*.’ meaning a whole group should be included regardless of the ignore list.
PILOT_PERSISTENT_SESSION_HEADER_LABELstring"istio.io/persistent-session-header"If not empty, services with this label will use header based persistent sessions
PILOT_PERSISTENT_SESSION_LABELstring"istio.io/persistent-session"If not empty, services with this label will use cookie based persistent sessions
PILOT_SEND_UNHEALTHY_ENDPOINTSboolfalseIf enabled, Pilot will include unhealthy endpoints in EDS pushes and even if they are sent Envoy does not use them for load balancing. To avoid, sending traffic to non ready endpoints, enabling this flag, disables panic threshold in Envoy i.e. Envoy does not load balance requests to unhealthy/non-ready hosts even if the percentage of healthy hosts fall below minimum health percentage(panic threshold).
PILOT_UNIFIED_SIDECAR_SCOPEbooltrueIf true, unified SidecarScope creation will be used. This is only intended as a temporary feature flag for backwards compatibility.

Pilot

VariableTypeDefaultDescription
BLOCKED_CIDRS_IN_JWKS_URISstring""Comma separated list of CIDR ranges that are blocked in JWKS URIs (e.g., 10.0.0.0/8,192.168.1.0/24).
CLUSTER_IDstringconstants.DefaultClusterNameDefines the cluster and service registry that this Istiod instance belongs to
DEBUG_ENDPOINT_AUTH_ALLOWED_NAMESPACESstring""Comma separated list of namespaces to allow access to debug endpoints. Only used if ENABLE_DEBUG_ENDPOINT_AUTH is enabled. The system namespaceis always authorized.
DISABLE_SHADOW_HOST_SUFFIXbooltrueIf disabled, the shadow host suffix will be added to the hostnames of the mirrored requests.
DISABLE_TRACK_REMAINING_CB_METRICSbooltrueIf disabled, the remaining metrics for circuit breakers will not be tracked.
ENABLE_CA_SERVERbooltrueIf this is set to false, will not create CA server in istiod.
ENABLE_CLUSTER_TRUST_BUNDLE_APIboolfalseIf enabled, uses the ClusterTrustBundle API instead of ConfigMaps to store the root certificate in the cluster.
ENABLE_DEBUG_ENDPOINT_AUTHbooltrueEnforce namespace-based authorization on debug endpoints. Non-system namespaces restricted to config_dump/ndsz/edsz for same-namespace proxies only.
ENABLE_DEBUG_ON_HTTPbooltrueIf this is set to false, the debug interface will not be enabled, recommended for production
ENABLE_GATEWAY_API_MANUAL_DEPLOYMENTbooltrueIf true, allows users to bind Gateway API resources to existing gateway deployments.
ENABLE_LAZY_SIDECAR_EVALUATIONbooltrueIf enabled, pilot will only compute sidecar resources when actually used
ENABLE_MULTICLUSTER_HEADLESSbooltrueIf true, the DNS name table for a headless service will resolve to same-network endpoints in any cluster.
ENABLE_NATIVE_SIDECARSstring"auto"If set to true, use Kubernetes native sidecar container support. Requires SidecarContainer feature flag. Set to true to unconditionally enable, false to unconditionally disable. Set to auto to automatically enable for supported scenarios
ENABLE_PROXY_FIND_POD_BY_IPboolfalseIf enabled, the pod controller will allow finding pods matching proxies by IP if it fails to find them by name.
ENABLE_SELECTOR_BASED_K8S_GATEWAY_POLICYbooltrueIf disabled, Gateway API gateways will ignore workloadSelector policies, onlyapplying policies that select the gateway with a targetRef.
ENABLE_VTPROTOBUFbooltrueIf true, will use optimized vtprotobuf based marshaling. Requires a build with -tags=vtprotobuf.
EXTERNAL_ISTIODboolfalseIf this is set to true, one Istiod will control remote clusters including CA.
INJECTION_WEBHOOK_CONFIG_NAMEstring"istio-sidecar-injector"Name of the mutatingwebhookconfiguration to patch, if istioctl is not used.
ISTIOD_CUSTOM_HOSTstring""Custom host name of istiod that istiod signs the server cert. Multiple custom host names are supported, and multiple values are separated by commas.
ISTIO_AGENT_ENABLE_WASM_REMOTE_LOAD_CONVERSIONbooltrueIf enabled, Istio agent will intercept ECDS resource update, downloads Wasm module, and replaces Wasm module remote load with downloaded local module file.
ISTIO_ENABLE_IPV4_OUTBOUND_LISTENER_FOR_IPV6_CLUSTERSboolfalseIf true, pilot will configure an additional IPv4 listener for outbound traffic in IPv6 only clusters, e.g. AWS EKS IPv6 only clusters.
ISTIO_KUBE_CLIENT_CONTENT_TYPEstring"protobuf"The content type to use for Kubernetes clients. Defaults to protobuf. Valid options: [protobuf, json]
ISTIO_MULTIROOT_MESHboolfalseIf enabled, mesh will support certificates signed by more than one trustAnchor for ISTIO_MUTUAL mTLS
ISTIO_WASM_MAX_BINARY_SIZE_BYTESint641024*1024*256Maximum size of a Wasm binary in bytes. Default is 256MB.
ISTIO_WATCH_NAMESPACEstring""If set, limit Kubernetes watches to a single namespace. Warning: only a single namespace can be set.
ISTIO_WORKLOAD_ENTRY_VALIDATE_IDENTITYbooltrueIf enabled, will validate the identity of a workload matches the identity of the WorkloadEntry it is associating with for health checks and auto registration. This flag is added for backwards compatibility only and will be removed in future releases
JWKS_RESOLVER_INSECURE_SKIP_VERIFYboolfalseIf enabled, istiod will skip verifying the certificate of the JWKS server.
LABEL_CANONICAL_SERVICES_FOR_MESH_EXTERNAL_SERVICE_ENTRIESboolfalseIf enabled, metadata representing canonical services for ServiceEntry resources with a location of mesh_external will be populatedin the cluster metadata for those endpoints.
LOCAL_CLUSTER_SECRET_WATCHERboolfalseIf enabled, the cluster secret watcher will watch the namespace of the external cluster instead of config cluster
MAX_CONNECTIONS_PER_SOCKET_EVENT_LOOPint1The maximum number of connections to accept from the kernel per socket event. Set this to ‘0’ to accept unlimited connections.
PILOT_CERT_PROVIDERstringconstants.CertProviderIstiodThe provider of Pilot DNS certificate. K8S RA will be used for k8s.io/NAME. ‘istiod’ value will sign using Istio build in CA. Other values will not not generate TLS certs, but still distribute ./etc/certs/root-cert.pem. Only used if custom certificates are not mounted.
PILOT_DISABLE_MX_ALPNboolfalseIf true, pilot will not put istio-peer-exchange ALPN into TLS handshake configuration.
PILOT_DNS_CARES_UDP_MAX_QUERIESuint32100Sets the udp_max_queries option in Envoy for the Cares DNS resolver. Defaults to 0, an unlimited number of queries. See extensions.network.dns_resolver.cares.v3.CaresDnsResolverConfig in https://www.envoyproxy.io/docs/envoy/latest/api-v3/extensions/network/dns_resolver/cares/v3/cares_dns_resolver.proto and ARES_OPT_UDP_MAX_QUERIES in https://c-ares.org/docs/ares_init.html
PILOT_DNS_JITTER_DURATIONduration100msJitter added to periodic DNS resolution
PILOT_ENABLE_ABSOLUTE_FQDN_VHOST_DOMAINstring`// Environment variable name
true`If set to false, Istio will not add the absolute FQDN variant (e.g., my-service.my-ns.svc.cluster.local.) to the domains list for VirtualHost entries.
PILOT_ENABLE_ALPN_FILTERbooltrueIf true, pilot will add Istio ALPN filters, required for proper protocol sniffing.
PILOT_ENABLE_CA_CRLbooltrueIf set to false, Istio will not watch for the ca-crl.pem file in the /etc/cacerts directory and will not distribute CRL data to namespaces for proxies to consume.
PILOT_ENABLE_CROSS_CLUSTER_WORKLOAD_ENTRYbooltrueIf enabled, pilot will read WorkloadEntry from other clusters, selectable by Services in that cluster.
PILOT_ENABLE_IP_AUTOALLOCATEbooltrueIf enabled, pilot will start a controller that assigns IP addresses to ServiceEntry which do not have a user-supplied IP. This, when combined with DNS capture allows for tcp routing of traffic sent to the ServiceEntry.
PILOT_ENABLE_K8S_SELECT_WORKLOAD_ENTRIESbooltrueIf enabled, Kubernetes services with selectors will select workload entries with matching labels. It is safe to disable it if you are quite sure you don’t need this feature
PILOT_ENABLE_NODE_UNTAINT_CONTROLLERSboolfalseIf enabled, controller that untaints nodes with cni pods ready will run. This should be enabled if you disabled ambient init containers.
PILOT_ENABLE_ROUTE_COLLAPSE_OPTIMIZATIONbooltrueIf true, Pilot will merge virtual hosts with the same routes into a single virtual host, as an optimization.
PILOT_ENABLE_SERVICEENTRY_SELECT_PODSbooltrueIf enabled, service entries with selectors will select pods from the cluster. It is safe to disable it if you are quite sure you don’t need this feature
PILOT_ENABLE_WORKLOAD_ENTRY_AUTOREGISTRATIONbooltrueEnables auto-registering WorkloadEntries based on associated WorkloadGroups upon XDS connection by the workload.
PILOT_ENABLE_WORKLOAD_ENTRY_HEALTHCHECKSbooltrueEnables automatic health checks of WorkloadEntries based on the config provided in the associated WorkloadGroup
PILOT_ENVOY_FILTER_STATSboolfalseIf true, Pilot will collect metrics for envoy filter operations.
PILOT_GATEWAY_API_CONTROLLER_NAMEstring"istio.io/gateway-controller"Gateway API controller name. istiod will only reconcile Gateway API resources referencing a GatewayClass with this controller name
PILOT_GATEWAY_API_DEFAULT_GATEWAYCLASS_NAMEstring"istio"Name of the default GatewayClass
PILOT_GATEWAY_TRANSPORT_SOCKET_CONNECT_TIMEOUTduration15sThe timeout for transport socket (e.g., TLS handshake) connections on gateway listeners. This helps protect against slow TLS handshake attacks. Set to 0s to disable.
PILOT_HTTP10boolfalseEnables the use of HTTP 1.0 in the outbound HTTP listeners, to support legacy applications.
PILOT_INSECURE_MULTICLUSTER_KUBECONFIG_OPTIONSstring""Comma separated list of potentially insecure kubeconfig authentication options that are allowed for multicluster authentication.Support values: all authProviders (gcp, azure, exec, openstack), clientKey, clientCertificate, tokenFile, and exec.
PILOT_IP_AUTOALLOCATE_IPV4_PREFIXstring"240.240.0.0/16"The CIDR range/prefix to use for auto-allocated IPv4 addresses. This should be a private range, and not conflict with any other IPs in the cluster.
PILOT_IP_AUTOALLOCATE_IPV6_PREFIXstring"2001:2::/48"The CIDR range/prefix to use for auto-allocated IPv6 addresses. This should be a private range, and not conflict with any other IPs in the cluster.
PILOT_JWT_ENABLE_REMOTE_JWKSstring"false"Mode of fetching JWKs from JwksUri in RequestAuthentication. Supported value: istiod, false, hybrid, true, envoy. The client fetching JWKs is as following: istiod/false - Istiod; hybrid/true - Envoy and fallback to Istiod if JWKs server is external; envoy - Envoy.
PILOT_JWT_PUB_KEY_REFRESH_INTERVALduration20mThe interval for istiod to fetch the jwks_uri for the jwks public key.
PILOT_MULTICLUSTER_KUBECONFIG_PATHstring""If set, istiod reads remote cluster kubeconfigs from this local directory. If both PILOT_MULTICLUSTER_KUBECONFIG_PATH and LOCAL_CLUSTER_SECRET_WATCHER are set, PILOT_MULTICLUSTER_KUBECONFIG_PATH takes precedence.
PILOT_MULTI_NETWORK_DISCOVER_GATEWAY_APIbooltrueIf true, Pilot will discover labeled Kubernetes gateway objects as multi-network gateways.
PILOT_NODE_UNTAINT_CONTROLLERS_TAINT_NAMEstring"cni.istio.io/not-ready"The taint key used by the node-untaint controller to identify nodes that should be untainted.
PILOT_REMOTE_CLUSTER_TIMEOUTduration30sAfter this timeout expires, pilot can become ready without syncing data from clusters added via remote-secrets. Setting the timeout to 0 disables this behavior.
PILOT_SCOPE_GATEWAY_TO_NAMESPACEboolfalseIf enabled, a gateway workload can only select gateway resources in the same namespace. Gateways with same selectors in different namespaces will not be applicable.
PILOT_SIDECAR_PICK_BEST_SERVICE_NAMESPACEbooltrueIf enabled, when a sidecar needs to pick a service namespace for a hostname, it will prefer Kubernetes services and fall back to the oldest non-Kubernetes service. When disabled, the first visible namespace alphabetically is used.
PILOT_SOLO_ENABLE_AUTO_WAYPOINTbooltrueIf true, pilot will automatically create a waypoint for namespaces that have the istio.io/use-waypoint label set to auto.
PILOT_WORKLOAD_ENTRY_GRACE_PERIODduration10sThe amount of time an auto-registered workload can remain disconnected from all Pilot instances before the associated WorkloadEntry is cleaned up.
PREFER_DESTINATIONRULE_TLS_FOR_EXTERNAL_SERVICESbooltrueIf true, external services will prefer the TLS settings from DestinationRules over the metadata TLS settings.
RESOLVE_HOSTNAME_GATEWAYSbooltrueIf true, hostnames in the LoadBalancer addresses of a Service will be resolved at the control plane for use in cross-network gateways.
SHARED_MESH_CONFIGstring""Additional config map to load for shared MeshConfig settings. The standard mesh config will take precedence.
UNSAFE_ENABLE_ADMIN_ENDPOINTSboolfalseIf this is set to true, dangerous admin endpoints will be exposed on the debug interface. Not recommended for production.
UNSAFE_PILOT_ENABLE_DELTA_TESTboolfalseIf enabled, addition runtime tests for Delta XDS efficiency are added. These checks are extremely expensive, so this should be used only for testing, not production.
UNSAFE_PILOT_ENABLE_RUNTIME_ASSERTIONSboolfalseIf enabled, addition runtime asserts will be performed. These checks are both expensive and panic on failure. As a result, this should be used only for testing.
VALIDATION_WEBHOOK_CONFIG_NAMEstring"istio-istio-system"If not empty, the controller will automatically patch validatingwebhookconfiguration when the CA certificate changes. Only works in kubernetes environment.

Security

VariableTypeDefaultDescription
CA_TRUSTED_NODE_ACCOUNTSstring""If set, the list of service accounts that are allowed to use node authentication for CSRs. Node authentication allows an identity to create CSRs on behalf of other identities, but only if there is a pod running on the same node with that identity. This is intended for use with node proxies.
CERT_SIGNER_DOMAINstring""The cert signer domain info
PILOT_ENABLE_MULTIPLE_CUSTOM_AUTHZ_PROVIDERSboolfalseIf enabled, allows multiple CUSTOM authorization providers per workload, enabling different authentication schemes (OAuth, LDAP, API keys) for different API paths. Each provider gets its own filter chain with provider-specific metadata matching.
PILOT_ENABLE_XDS_IDENTITY_CHECKbooltrueIf enabled, pilot will authorize XDS clients, to ensure they are acting only as namespaces they have permissions for.
PILOT_SKIP_VALIDATE_TRUST_DOMAINboolfalseSkip validating the peer is from the same trust domain when mTLS is enabled in authentication policy
TRUSTED_GATEWAY_CIDRstring""If set, any connections from gateway to Istiod with this CIDR range are treated as trusted for using authentication mechanisms like XFCC. This can only be used when the network where Istiod and the authenticating gateways are running in a trusted/secure network
USE_CACERTS_FOR_SELF_SIGNED_CAboolfalseIf enabled, istiod will use a secret named cacerts to store its self-signed istio-generated root certificate.
XDS_AUTHbooltrueIf true, will authenticate XDS clients.

Telemetry

VariableTypeDefaultDescription
ISTIO_ENABLE_CONTROLLER_QUEUE_METRICSboolfalseIf enabled, publishes metrics for queue depth, latency and processing times.
PILOT_AGENT_MERGE_ENVOY_STATSbooltrueIf false, pilot agent will not merge Envoy stats in the agent stats endpoint.
PILOT_ENABLE_METADATA_EXCHANGEbooltrueIf true, pilot will add metadata exchange filters, which will be consumed by telemetry filter.
PILOT_ENABLE_TELEMETRY_LABELbooltrueIf true, pilot will add telemetry related metadata to cluster and endpoint resources, which will be consumed by telemetry filter.
PILOT_ENDPOINT_TELEMETRY_LABELbooltrueIf true, pilot will add telemetry related metadata to Endpoint resource, which will be consumed by telemetry filter.
PILOT_MX_ADDITIONAL_LABELSstring""Comma separated list of additional labels to be added to metadata exchange filter.
PILOT_SPAWN_UPSTREAM_SPAN_FOR_GATEWAYbooltrueIf true, separate tracing span for each upstream request for gateway. This is only available when using Telemetry API.
PILOT_TRACE_SAMPLINGfloat641.0Sets the mesh-wide trace sampling percentage. Should be 0.0 - 100.0. Precision to 0.01. Default is 1.0.

Tuning

VariableTypeDefaultDescription
ISTIO_GPRC_MAXRECVMSGSIZEint4*1024*1024Sets the max receive buffer size of gRPC stream in bytes.
ISTIO_GPRC_MAXSTREAMSint100000Sets the maximum number of concurrent grpc streams.
MUTEX_PROFILE_FRACTIONint1000If set to a non-zero value, enables mutex profiling a rate of 1/MUTEX_PROFILE_FRACTION events. For example, ‘1000’ will record 0.1% of events. Set to 0 to disable entirely.
PILOT_CONVERT_SIDECAR_SCOPE_CONCURRENCYint1Deprecated, superseded by ENABLE_LAZY_SIDECAR_EVALUATION. Used to adjust the concurrency of SidecarScope conversions. When istiod is deployed on a multi-core CPU server, increasing this value will help to use the CPU to accelerate configuration push, but it also means that istiod will consume more CPU resources.
PILOT_DEBOUNCE_AFTERduration100msThe delay added to config/registry events for debouncing. This will delay the push by at least this interval. If no change is detected within this period, the push will happen, otherwise we’ll keep delaying until things settle, up to a max of PILOT_DEBOUNCE_MAX.
PILOT_DEBOUNCE_MAXduration10sThe maximum amount of time to wait for events while debouncing. If events keep showing up with no breaks for this time, we’ll trigger a push.
PILOT_ENABLE_EDS_DEBOUNCEbooltrueIf enabled, Pilot will include EDS pushes in the push debouncing, configured by PILOT_DEBOUNCE_AFTER and PILOT_DEBOUNCE_MAX. EDS pushes may be delayed, but there will be fewer pushes. By default this is enabled
PILOT_MAX_REQUESTS_PER_SECONDfloat640.0Limits the number of incoming XDS requests per second. On larger machines this can be increased to handle more proxies concurrently. If set to 0 or unset, the max will be automatically determined based on the machine size
PILOT_PUSH_THROTTLEint0Limits the number of concurrent pushes allowed. On larger machines this can be increased for faster pushes. If set to 0 or unset, the max will be automatically determined based on the machine size
PILOT_STATUS_MAX_WORKERSint100The maximum number of workers Pilot will use to keep configuration status up to date. Smaller numbers will result in higher status latency, but larger numbers may impact CPU in high scale environments.
PILOT_XDS_CACHE_INDEX_CLEAR_INTERVALduration5sThe interval for xds cache index clearing.
PILOT_XDS_CACHE_SIZEint60000The maximum number of cache entries for the XDS cache.

XDS

VariableTypeDefaultDescription
PILOT_ENABLE_CDS_CACHEbooltrueIf true, Pilot will cache CDS responses. Note: this depends on PILOT_ENABLE_XDS_CACHE.
PILOT_ENABLE_EDS_FOR_HEADLESS_SERVICESboolfalseIf enabled, for headless service in Kubernetes, pilot will send endpoints over EDS, allowing the sidecar to load balance among pods in the headless service. This feature should be enabled if applications access all services explicitly via a HTTP proxy port in the sidecar.
PILOT_ENABLE_MONGO_FILTERbooltrueEnableMongoFilter enables injection of envoy.filters.network.mongo_proxy in the filter chain.
PILOT_ENABLE_MYSQL_FILTERboolfalseEnableMysqlFilter enables injection of envoy.filters.network.mysql_proxy in the filter chain.
PILOT_ENABLE_RDS_CACHEbooltrueIf true, Pilot will cache RDS responses. Note: this depends on PILOT_ENABLE_XDS_CACHE.
PILOT_ENABLE_REDIS_FILTERboolfalseEnableRedisFilter enables injection of envoy.filters.network.redis_proxy in the filter chain.
PILOT_ENABLE_XDS_CACHEbooltrueIf true, Pilot will cache XDS responses.
PILOT_SIDECAR_USE_REMOTE_ADDRESSboolfalseUseRemoteAddress sets useRemoteAddress to true for sidecar outbound listeners.
PILOT_XDS_CACHE_STATSboolfalseIf true, Pilot will collect metrics for XDS cache efficiency.