Networking
These guides help platform engineers configure networking and service mesh features in UDS Core. Each guide focuses on a single task and includes step-by-step instructions with verification.
For background on how the service mesh, gateways, and authorization model work, see Networking & Service Mesh Concepts.
Guides
Section titled “Guides”Configure TLS certificatesSet up TLS certificates for your ingress gateways.
Expose applications on gatewaysMake applications accessible through the tenant or admin gateway.
Enable the passthrough gatewayDeploy the optional passthrough gateway for apps that handle their own TLS.
Define network accessConfigure intra-cluster ingress/egress, Kubernetes API access, and external egress for your application.
Set up non-HTTP ingressAccept TCP traffic (SSH, database ports, etc.) through a gateway.
Create a custom gatewayDeploy a gateway with independent domain, TLS, and security controls.
Configure an L7 load balancerRun UDS Core behind an ALB, Azure Application Gateway, or similar.
Allow permissive mesh trafficRelax strict authorization policies for exceptional workloads.
Configure network access for Core servicesExtend network rules for Core components like Falco, Vector, and Grafana.
Manage trust bundlesDistribute custom CA certificates across the cluster for private PKI or DoD CAs.