← Policy catalog
</> PeerAuthentication · Apache-2.0

Mesh-wide mTLS Strict

peerauthentication-mesh-wide-strict

productIstio

Enforce STRICT mTLS across the entire mesh.

What this is

A reference manifest to copy and adapt, not a rule cenroq enforces for you. It carries no severity, belongs to no bundle, and nothing on your cluster changes until you apply it yourself.

Manifest

apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
  name: default
  # This must be the namespace where istiod is deployed!
  namespace: istio-system
  annotations:
    cenroq.io/displayName: "Mesh-wide mTLS Strict"
    cenroq.io/description: "Enforce STRICT mTLS across the entire mesh."
spec:
  mtls:
    mode: STRICT

Save it as peerauthentication-mesh-wide-strict.yaml — the commands below assume that name.

Apply it

This is a manifest, not an admission policy, so there is nothing for kubeapt validate to check it against. Adapt the selectors and namespace first, then:

$ kubectl apply -f ./peerauthentication-mesh-wide-strict.yaml