istio-injection: enabled in my project’s namespace.
I have a job that uses an
initContainer and a normal container (to provide some ordering).
This seems to be incompatible with Istio sidecar…
It seems that
istio-init is an
initContainer which finishes before
istio-proxy must be running before anything else on the pod can connect to outside the pod, correct?
So, because I have my own
initContainer, that must finish before the normal containers are started, and this container requires network traffic… so it fails because
istio-proxy is not yet running…
Are there some configuration options within Istio that would help here?
There is no way to enforce ordering of containers other than
Or is the answer: exclude jobs that use
initContainers from sidecar injection, accepting the loss of traffic monitoring/security?
Thanks for any help.