Enable Ambient Mode ​
Enable ambient mode when you want to adopt Istio's sidecarless service mesh without injecting a proxy container into every workload Pod.
By default, the Istio module uses the sidecar model, where an Envoy proxy is injected into each workload Pod to handle traffic encryption, observability, and policy enforcement. Ambient mode replaces this per-Pod sidecar with a shared, per-node Layer 4 proxy called ztunnel and an optional per-namespace Layer 7 proxy called waypoint. For more information, see Sidecar or ambient?.
When you set enableAmbient to true in the istio-features ConfigMap, the Istio module applies the following configuration changes:
- ztunnel DaemonSet – The ztunnel component is deployed as a DaemonSet. It handles encrypted mTLS communication between workloads at Layer 4 without requiring a sidecar in each Pod.
- CNI ambient support – The Istio CNI node agent is configured with
cni.ambient.enabled: trueso that it can redirect Pod traffic into the ztunnel on each node. - Pilot ambient support – The
PILOT_ENABLE_AMBIENTenvironment variable is set totrueon istiod, enabling the control plane to manage ambient-mode workloads. - HBONE transport – All Envoy proxies and ztunnel instances are configured with
ISTIO_META_ENABLE_HBONE=truevia mesh configdefaultConfig.proxyMetadata, enabling the HTTP-Based Overlay Network Encapsulation (HBONE) tunneling protocol used by ambient mode.
NOTE
If you use the experimental version of the Istio module, you can also enable the ambient mode in the spec.experimental.enableAmbient field in the Istio CR's field. The enableAmbient feature flag in the istio-features ConfigMap is an OR condition: ambient mode is active when either the ConfigMap flag or the CR field is set to true.
CAUTION
Support for ambient mode in the Istio module is a beta feature that may be changed or removed in any future release without prior notice.