GHOSTby AlphaBravo
CatalogWhy GhostContactAccount
Ghost Container Registry — Secure, signed, FIPS-ready images·Built by AlphaBravo
Catalog/istio-pilot

istio pilot

FIPS 140-3Monitoring & observability

Istio control plane component that configures proxies and handles service discovery

OverviewGuidesTags
Signed
SBOM
FIPS
CIS

Pull this image

About

About Istio Pilot

Istio Pilot is the core control plane component of the Istio service mesh, responsible for service discovery, configuration management, and intelligent traffic management. Pilot acts as the brain of the mesh, continuously communicating with Kubernetes API server and translating high-level Istio configuration into proxy configurations that are pushed to all sidecar proxies and gateway proxies in the mesh.

Pilot handles the complex task of translating service mesh policies and routing rules into low-level proxy configurations, ensuring consistent behavior across all proxies in the mesh. It maintains awareness of all services running in the cluster and dynamically distributes their configuration to proxies as services scale up, down, or move between nodes.

Key responsibilities of Istio Pilot:

  • Service Discovery: Automatic detection and registration of services from Kubernetes
  • Configuration Distribution: Pushes proxy configurations to all proxies in the mesh (sidecar and gateway)
  • Traffic Management: Implements load balancing, circuit breaking, retries, and traffic splitting policies
  • Security Policy Enforcement: Manages mutual TLS (mTLS) configuration and authorization policies
  • Certificate Rotation: Manages and rotates short-lived certificates for mTLS connections
  • Dynamic Reconfiguration: Updates proxy configurations in real-time as services and policies change
  • Service Mesh Observability: Provides metrics and diagnostic information about mesh health
  • Multi-Cluster Coordination: Handles service discovery and traffic management across multiple clusters
  • Virtual Service Processing: Translates VirtualService CRDs into Envoy routing configurations
  • Destination Rule Processing: Applies DestinationRule policies for load balancing and connection pooling

Pilot is a stateless component that scales horizontally and is typically deployed as a highly available deployment with multiple replicas. It communicates with proxies using the xDS gRPC protocol, enabling real-time configuration updates and efficient resource management.

For more information about Istio Pilot and control plane architecture, visit https://istio.io/latest/docs/ops/deployment/architecture/.

Recently pushed

View all →
1.30.3-distroless-950d3f125ae1FIPSDistroless
0 CVEs60 MBAug 18
1.30.3-distroless-8ff7d5572d17FIPSDistroless
0 CVEs60 MBAug 13
1.29.6-distroless-954e3aad91dc

Image details

Distribution
Debian
Architecture
amd64
Latest size
27 MB
Variants
Base + FIPS
Last pushed
Aug 12, 2026
Last scanned
Aug 12, 2026 · Trivy

Resources

Documentation ↗
Available tags
4 tags
View tags →
Latest digest
sha256:69fabc66a54e…
FIPS
Distroless
0 CVEs58 MBAug 13
1.30.3-24bc9f5f9e3d
0 CVEs27 MBAug 12
1.29.6-6db609d9c638
0 CVEs26 MBAug 12