SSH access stops working (Can't connect to LDAP server) when istio vm agent not working properly

SSH access stops working (Can’t connect to LDAP server) when istio vm agent not working properly

Hi Team,

We are facing issue with istio vm agent (can’t connect to LDAP server).

Setup:

  1. Version: 1.16.2
  2. OS: OEL7 (managed to deploy agent on OEL with patched glibc)
  3. Cluster setup:
  • Istio cluster setup on k8s cluster is done(SVC to SVC communication working)
  • Istio vm agent is deployed (no issues if all went well and vm to k8s and revers communication is working)

Issue:

  1. SSH access stops working if isito-agent on vm not able to fetch the certs or failed by any means

Logs:

No particular logs have been observed related to LDAP connection issue, just “ldap_sasl_bind_s(): Can’t contact LDAP server”

client version: 1.16.2
control plane version: 1.16.2
data plane version: 1.16.0 (1 proxies), 1.16.2 (37 proxies)