Istio · Schema
Istio PeerAuthentication
A PeerAuthentication defines how traffic will be tunneled (or not) to the sidecar proxy. It configures mutual TLS (mTLS) mode for workload-to-workload communication within the mesh.
CNCFKubernetesMicroservicesOpen-SourceService Mesh
Properties
| Name | Type | Description |
|---|---|---|
| selector | object | Workload selector to apply the policy to specific workloads. If not set, the policy applies to all workloads in the namespace. |
| mtls | object | Mutual TLS settings for workload communication. |
| portLevelMtls | object | Port-specific mutual TLS settings. Keys are port numbers. |
JSON Schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://github.com/api-evangelist/istio/blob/main/json-schema/peer-authentication.json",
"title": "Istio PeerAuthentication",
"description": "A PeerAuthentication defines how traffic will be tunneled (or not) to the sidecar proxy. It configures mutual TLS (mTLS) mode for workload-to-workload communication within the mesh.",
"type": "object",
"properties": {
"selector": {
"type": "object",
"properties": {
"matchLabels": {
"type": "object",
"additionalProperties": {
"type": "string"
},
"description": "One or more labels that indicate a specific set of pods/VMs on which the policy should be applied."
}
},
"description": "Workload selector to apply the policy to specific workloads. If not set, the policy applies to all workloads in the namespace."
},
"mtls": {
"type": "object",
"properties": {
"mode": {
"type": "string",
"enum": ["UNSET", "DISABLE", "PERMISSIVE", "STRICT"],
"description": "Defines the mTLS mode used for peer authentication. UNSET inherits from parent, DISABLE disables mTLS tunnel, PERMISSIVE accepts both plaintext and mTLS, STRICT requires mTLS."
}
},
"description": "Mutual TLS settings for workload communication."
},
"portLevelMtls": {
"type": "object",
"additionalProperties": {
"type": "object",
"properties": {
"mode": {
"type": "string",
"enum": ["UNSET", "DISABLE", "PERMISSIVE", "STRICT"],
"description": "Defines the mTLS mode for this specific port."
}
}
},
"description": "Port-specific mutual TLS settings. Keys are port numbers."
}
}
}
Work with this as data
Every JSON Schema here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for schemas
4 MCP tools reach this
find_json_schemasBrowse and filter every JSON Schema in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This JSON Schema
curl "https://apis.io/api/v1/json-schemas/peer-authentication"
All schemas
curl "https://apis.io/api/v1/json-schemas?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.