5427a1465c
Initially we were loading every potential upstream address into Envoy and then routing traffic to the logical upstream service. The downside of this behavior is that traffic meant to go to a specific instance would be load balanced across ALL instances. Traffic to specific instance IPs should be forwarded to the original destination and if it's a destination in the mesh then we should ensure the appropriate certificates are used. This PR makes transparent proxying a Kubernetes-only feature for now since support for other environments requires generating virtual IPs, and Consul does not do that at the moment.
3 lines
120 B
Plaintext
3 lines
120 B
Plaintext
```release-note:improvement
|
|
connect: restrict transparent proxy mode to only match on the tagged virtual IP address.
|
|
``` |