Skip to content

Add service-mesh contract and Istio reference module for mutual TLS between module instances #776

Description

@RonaldHensbergen

Problem statement

docs/haven-parity-plan.md workstream 3.4 identifies service mesh (mutual TLS between module instances, Kubernetes-only) as a security-platform gap, but explicitly defers it: "lowest priority in this group... TLS-at-the-proxy covers most profiles' actual need without it." No issue has been filed for it yet, which leaves this gap invisible in the tracker even though it is a named prerequisite for a coherent Zero-Trust story (see the companion umbrella issue).

Proposed solution

  • Define a new vendor-neutral service-mesh contract under shared/contracts/, scoped to what a consuming module needs: mTLS enforcement between named services, and (optionally) per-service authorization policy.
  • Add modules-experimental/security/istio/module.yaml as the reference provider, gated to --target helm only (Kubernetes-only, per the parity plan's non-goals).
  • Explicitly defer: this is not required for any stable profile; it exists so profiles that need mTLS between module instances (rather than just TLS at the ingress/reverse-proxy) have a documented, contract-based option.

Acceptance criteria

  • service-mesh contract schema defined and validated by cli/validator.py.
  • istio module renders under --target helm and a profile can bind an existing module (e.g. two warehouse/orchestration modules) to it without consumer-side code changes.
  • Not wired into any stable profile in this issue.
  • docs/haven-parity-plan.md section 4 status table updated to reference this issue.

References

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:kubernetesKubernetes/Helm target rendering, runtime, and k3d toolingarea:securitySecurity policies and checksenhancementNew feature or requestpriority:lowNice to have, low urgency

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions