How does Istio implement mTLS between services?
⚡
Quick Answer
istiod issues per-workload certificates; sidecars use them to encrypt and mutually authenticate all mesh traffic transparently.
Detailed Answer
With a PeerAuthentication policy set to STRICT, every request between sidecars is encrypted and both ends verify each other's identity (SPIFFE cert), with zero app changes. This gives encryption in transit and strong service identity for authorization policies.
💡
Interview Tip
Mention PeerAuthentication STRICT and SPIFFE identities.
istiomtlssecurity