Egress TCP traffic not working on new install

I’ve just installed istio in a staging envrionment and one of my applications isn’t able to connect to the external postgres database; I did try setting meshConfig.outboundTrafficPolicy.mode explicitly to ALLOW_ANY but this seems to not have helped.

here’s a log entry for the istio-proxy container:


I was able to use netcat from the istio-proxy container to test connecting to the postgres host succesfully.

Any ideas about what to try next?

I’ve been looking at the envoy config based on this article:

It seems like the default outbound cluster for 5432 has no endpoints associated, does this mean there’s an issue with my DNS discovery for envoy?