# PeerAuthentication PERMISSIVE for namespaces that receive non-mesh traffic # The API server calls webhooks from outside the mesh (no SPIFFE identity). # The CrowdSec firewall bouncer runs on hostNetwork (no mesh identity) # and must connect to LAPI over plaintext. # PERMISSIVE allows both mTLS and plaintext inbound. --- apiVersion: security.istio.io/v1 kind: PeerAuthentication metadata: name: allow-apiserver-webhooks namespace: cnpg-system spec: mtls: mode: PERMISSIVE --- apiVersion: security.istio.io/v1 kind: PeerAuthentication metadata: name: allow-apiserver-webhooks namespace: mariadb-system spec: mtls: mode: PERMISSIVE --- # Netbird operator webhook receives calls from the API server # (namespace is "netbird", not "netbird-operator" - that namespace # doesn't exist; fixed 2026-08-17) apiVersion: security.istio.io/v1 kind: PeerAuthentication metadata: name: allow-apiserver-webhooks namespace: netbird spec: mtls: mode: PERMISSIVE --- # CrowdSec firewall bouncer (hostNetwork DaemonSet) connects to LAPI # from the host network namespace without a mesh identity apiVersion: security.istio.io/v1 kind: PeerAuthentication metadata: name: allow-hostnetwork-bouncer namespace: crowdsec spec: mtls: mode: PERMISSIVE