In this demo I show how the Identity provisioning flow works in Istio when using a custom CA for workload certificate issuance and the Kubernetes CSR API for certificate signing.
request, then forwards the CSR to the CA to have it signed Service istiod Data plane Control Plane SDS Authenticates client Checks identity and sends CSR to the CA