
Network & Infrastructure SecurityContainer Security
Solo Enterprise for Istio
Enterprise Istio enforcing mutual TLS, L7 authorization, and zero-trust segmentation on Kubernetes.
Solo Enterprise for Istio Overview
What it does
Istio, in Solo.io's enterprise distribution, secures and routes traffic between Kubernetes and virtual-machine workloads from a single control plane. Its distinguishing mechanism is an ambient, sidecarless data plane built on a per-node ztunnel proxy, which enforces mutual TLS (mTLS) and Layer 7 policy without injecting a sidecar container into every pod, cutting the memory and operational cost of running the mesh at scale.
How it works
The platform authenticates every service-to-service connection using X.509 workload identities issued through SPIFFE and SPIRE, so traffic is encrypted and authorized by service identity rather than IP address and port. Authorization policies evaluate HTTP paths, gRPC methods, and workload claims through Common Expression Language (CEL) rules, while waypoint proxies apply Layer 7 egress controls that constrain outbound traffic. A federated multi-cluster service registry links meshes across clouds and on-premises data centers, and east-west gateways carry encrypted cross-cluster traffic that feeds flow telemetry. ECS, Lambda, and virtual-machine extensions bring non-Kubernetes workloads into the same mesh.
Credentials and traction
It was named a Visionary in the 2024 Gartner Magic Quadrant for API Management, its second consecutive placement in that report. The distribution is used by enterprises including T-Mobile, BMW, ADP, Carfax, USAA, and Zscaler, with T-Mobile citing it across workloads handling roughly 150 million transactions per day.
Key Capabilities
mapped to solution categoriesEnforces mutual TLS on every service-to-service connection using X.509 workload identities (SPIFFE), so traffic between pods is encrypted and authenticated by service identity rather than IP and port.
Enforces policy on HTTP paths, gRPC, Kafka, and service identity rather than IP and port, so rules survive pod churn and constrain what each service may do.
Enforces DNS-based and IP-based egress policies for pod outbound traffic, preventing C2 communication, data exfiltration, and unauthorized external API calls.
Captures and logs all pod-to-pod network flows including service mesh traffic, providing full observability for anomaly detection and policy validation.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on July 25, 2026
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.