---
title: Charmhub | Deploy Istio Pilot using Charmhub - The Open Operator Collection
description: Deploy the latest version of Istio Pilot on any cloud.
url: https://charmhub.io/istio-pilot/configurations
---

# Istio Pilot

[Kubeflow Charmers](https://charmhub.io/publisher/ckfbot "View all packages from Kubeflow Charmers")

* [Kubeflow Charmers](https://charmhub.io/publisher/ckfbot "View all packages from Kubeflow Charmers")

Platform:

24.04

20.04

1.24/stable 1401

```
juju deploy istio-pilot --channel 1.24/stable
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [cni-bin-dir](https://charmhub.io/istio-pilot/configurations#cni-bin-dir)
* [cni-conf-dir](https://charmhub.io/istio-pilot/configurations#cni-conf-dir)
* [csr-domain-name](https://charmhub.io/istio-pilot/configurations#csr-domain-name)
* [default-gateway](https://charmhub.io/istio-pilot/configurations#default-gateway)
* [gateway-service-name](https://charmhub.io/istio-pilot/configurations#gateway-service-name)
* [image-configuration](https://charmhub.io/istio-pilot/configurations#image-configuration)
* [tls-secret-id](https://charmhub.io/istio-pilot/configurations#tls-secret-id)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* cni-bin-dir | string

  Path to CNI binaries, e.g. /opt/cni/bin. If not provided, the Istio control plane will be installed/upgraded with the Istio CNI plugin disabled. This path depends on the Kubernetes installation, please refer to https://kubernetes.io/docs/concepts/extend-kubernetes/compute-storage-net/network-plugins/ for information to find out the correct path.
* cni-conf-dir | string

  Path to conflist files describing the CNI configuration, e.g. /etc/cni/net.d. If not provided, the Istio control plane will be installed/upgraded with the Istio CNI plugin disabled. This path depends on the Kubernetes installation, please refer to https://kubernetes.io/docs/concepts/extend-kubernetes/compute-storage-net/network-plugins/ for information to find out the correct path.
* csr-domain-name | string

  The domain name to be used by the charm to send a Certificate Signing Request (CSR) to a TLS certificate provider. In the absence of this configuration option, the charm will try to use the ingress gateway service hostname (if configured by a LB) or its IP address.
* default-gateway | string

  Default: istio-gateway

  Name to use as a default gateway
* gateway-service-name | string

  Default: istio-ingressgateway-workload

  Name of the service created by istio-gateway to use as a Gateway
* image-configuration | string

  Default: pilot-image: 'pilot' # values.pilot.image
  global-tag: '1.24.2' # values.global.tag
  global-hub: 'docker.io/istio' # values.global.hub
  global-proxy-image: 'proxyv2' # values.global.proxy.image
  global-proxy-init-image: 'proxyv2' # values.global.proxy\_init.image
  grpc-bootstrap-init: 'busybox:1.28'

  YAML or JSON formatted input defining image configuration to use when installing the Istio control plane. For reference https://istio.io/v1.5/docs/reference/config/installation-options/
* tls-secret-id | secret

  A configuration option to store the user secret ID that stores the TLS certificate and key values.
  The secret ID is the result of adding a secret with the following format
  juju add-secret istio-tls-secret tls-crt="$(cat CERT\_FILE)" tls-key=$"$(cat KEY\_FILE)"
