Docs

Browse releases →

envoy

Envoy proxy — high-performance L7 proxy and communication bus

envoy

Envoy proxy — high-performance L7 proxy and communication bus

1.37.0 · aarch64-darwin

TLS and xDS credentials

Static TLS handles use opaque system-credential references and are bound only when selected. SDS names xDS resources rather than embedding secret material.

Runtime lifecycle

Systemd owns restarts, so hot restart is disabled. The administration endpoint remains loopback-only and its access log uses the managed package log directory.

Quick start

Install Envoy, enable envoy.enable, and declare listeners and clusters. Every rendered bootstrap is checked with Envoy validation before the service starts.

{
  aos.apm.desiredPackages = ["envoy"];
  envoy.enable = true;
  envoy.listeners.http.port = 10000;
}
OptionTypeDescription
adminsubmoduleThe local Envoy administration interface.
clustersattribute set of submoduleThe statically configured upstream clusters.
configattribute set of attribute set of any valueDesired values for the package's declared config artifacts.
credentialsattribute set of submoduleOpaque references for the package's declared credentials.
dynamicResourcessubmoduleThe xDS dynamic-resource configuration.
enablebooleanWhether to enable the Envoy proxy service.
listenersattribute set of submoduleThe statically configured listeners.
nodesubmoduleThe Envoy node identity advertised to xDS servers.
runtimeLayersattribute set of submoduleStatic, non-secret Envoy runtime layers.
telemetrysubmoduleEnvoy telemetry sinks and tags.