---
title: Charmhub | Deploy Istio using Charmhub - The Open Operator Collection
description: Deploy the latest version of Istio as a Kubernetes Operator on any cloud.
url: https://charmhub.io/istio-k8s/configurations
---

# Istio

[Canonical Observability](https://charmhub.io/publisher/observability "View all packages from Canonical Observability")

* [Canonical Observability](https://charmhub.io/publisher/observability "View all packages from Canonical Observability")

Platform:

1/stable rev28-3-ga66284f

```
juju deploy istio-k8s --channel 1/stable
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [ambient](https://charmhub.io/istio-k8s/configurations#ambient)
* [auto-allow-waypoint-policy](https://charmhub.io/istio-k8s/configurations#auto-allow-waypoint-policy)
* [platform](https://charmhub.io/istio-k8s/configurations#platform)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* ambient | boolean

  Default: True

  Enable Istio's ambient mode. See https://istio.io/latest/docs/ambient/overview/ for details.
* auto-allow-waypoint-policy | boolean

  Default: True

  For workloads on an ambient mesh with traffic routed through a waypoint, that traffic passing through the waypoint to the workload can be controlled by L4 authorization policies like any other traffic. This generally means that, to allow traffic from a waypoint to a workload, users must create L4 authorization policies between the waypoint and the workload. If this option is set to true, Istio will create synthetic authorization policies allowing waypoints to communicate with their workloads automatically. If this option is set to false, users must create L4 authorization policies between waypoints and the workloads. See [PILOT\_AUTO\_ALLOW\_WAYPOINT\_POLICY]https://istio.io/latest/docs/reference/commands/pilot-discovery/#envvars for more detail.
* platform | string

  Default: microk8s

  Some Kubernetes platforms require platform-specific configuration for Istio to function correctly. This is described in more detail upstream in [Platform Prerequisites](https://istio.io/latest/docs/ambient/install/platform-prerequisites/). This configuration option maps to the `values.global.platform` field in the Istio Helm chart, and can be used to specify the platform-specific configuration for the Kubernetes platform on which the charm is deployed. If left blank, no value of `values.global.platform` will be set.
