dhi.io/istio-cni-chart
Helm chart for deploying the Istio CNI plugin.
This is an Istio CNI Docker Hardened Helm chart built from the upstream Istio istio-cni Helm chart and using a hardened configuration with Docker Hardened Images.
The following Docker Hardened Images are used in this Helm chart:
dhi/istio-install-cni (CNI plugin installer)To learn more about how to use this Helm chart you can visit the upstream documentation: https://istio.io/latest/
The Istio CNI plugin replaces the istio-init init container that would otherwise be used to configure traffic
redirection in each pod. Instead, the CNI plugin handles the required iptables rules at the node level as a DaemonSet,
removing the need for pods to have NET_ADMIN and NET_RAW capabilities. This simplifies security policies and reduces
the privilege requirements for workloads in the mesh.
For more details, visit https://istio.io/latest/docs/setup/additional-setup/cni/.
Docker Hardened Images are built to meet the highest security and compliance standards. They provide a trusted foundation for containerized workloads by incorporating security best practices from the start.
These images are published with near-zero known CVEs, include signed provenance, and come with a complete Software Bill of Materials (SBOM) and VEX metadata. They're designed to secure your software supply chain while fitting seamlessly into existing Docker workflows.
Istio® is a trademark of the Linux Foundation. All rights in the mark are reserved to the Linux Foundation. Any use by Docker is for referential purposes only and does not indicate sponsorship, endorsement, or affiliation.
Try DHI Enterprise
Start a free 30-day DHI Enterprise trial to mirror this image to your organization's registry and unlock full benefits.
SLA-backed CVE remediations
FIPS & STIG-compliant variants
Customizations at enterprise scale
Istio Install CNI 1.30.x
Join GitHub Discussions or our Slack community to share ideas, ask questions, and connect with the team.
Go to discussionsJoin community