istioctl - Istio configuration command line utility
istioctl COMMAND [flags]
Options you will use
install [--set profile=default|minimal|demo] [-y]- install or reconfigure the control plane (istiod, the injector webhook, the CRDs, a gateway in the default profile)
analyze [-n NS | -A]- check config the way istiod sees it: IST0101 referenced host/subset not found, IST0102 namespace not injected, IST0103 pod missing proxy, IST0108 unknown annotation, IST0118 port naming. Exit 79 on errors
proxy-status [POD] [-v 1]- is every Envoy in sync with istiod? (SYNCED / STALE / NOT SENT)
proxy-config cluster|listener|route|endpoint|secret|log POD[.NS]- what ONE Envoy was told: clusters (+ subsets and DestinationRule), listeners, routes (+ VirtualService), endpoints (HEALTHY, OUTLIER CHECK FAILED), its certificate
x describe pod POD- service, DestinationRule, VirtualService, effective mTLS mode and policies for one pod
x precheck- is the cluster ready for an install or upgrade?
version- client, control plane and data plane versions
uninstall --purge -y- remove everything
-n, --namespace NS- The namespace (default: the kubeconfig context's).
-i, --istioNamespace NS- The namespace Istio is installed in (default istio-system).
-c, --kubeconfig FILE- The kubeconfig to use.
--context NAME- The kubeconfig context to use.
-r, --revision REV- The control plane revision to talk to (canary upgrades).
-h, --help- Help for the command.
Examples
$ istioctl install --set profile=default -yistiod + ingress gateway
$ istioctl install --set meshConfig.accessLogFile=/dev/stdout -yturn on Envoy access logs mesh-wide
$ istioctl analyze -n shopcatch a VirtualService that points at a subset nobody defined
$ istioctl pc endpoints deploy/web -n shop --cluster "outbound|80||api.shop.svc.cluster.local"which api pods the web sidecar may use, and which outlier detection ejected
$ istioctl pc routes deploy/web -n shop --name 80which VirtualService decides traffic to port 80
Gotchas
- proxy-config shows one proxy's view. When two pods disagree, compare their proxy-config, not the YAML you applied.
Taught in
Try istioctl in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.