---
title: Charmhub | Deploy Istio using Charmhub - The Open Operator Collection
description: Deploy the latest version of Istio as a Kubernetes Operator on any cloud.
url: https://charmhub.io/istio/configurations/istio-pilot
---

##### We've discontinued the registration of new Bundles

New Bundle registrations are no longer accepted. Existing bundles remain functional. We recommend using the Juju Terraform Provider for new deployments.

[Learn more](https://discourse.charmhub.io/t/discontinuing-new-charmhub-bundle-registrations/15344)

# Istio

[Istio Charmers](https://charmhub.io/publisher/istio-charmers "View all packages from Istio Charmers")
| bundle

* [Istio Charmers](https://charmhub.io/publisher/istio-charmers "View all packages from Istio Charmers")
  | bundle
* [Monitoring](https://charmhub.io/?filter=monitoring)
* [Networking](https://charmhub.io/?filter=networking)
* [Security](https://charmhub.io/?filter=security)

Platform:

stable 58

```
juju deploy istio
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [Istio Gateway](https://charmhub.io/istio/configurations/istio-gateway)
* [Istio Pilot](https://charmhub.io/istio/configurations/istio-pilot)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* cni-bin-dir | string

  Path to CNI binaries, e.g. /opt/cni/bin. If not provided, the Istio control plane will be installed/upgraded with the Istio CNI plugin disabled. This path depends on the Kubernetes installation, please refer to https://kubernetes.io/docs/concepts/extend-kubernetes/compute-storage-net/network-plugins/ for information to find out the correct path.
* cni-conf-dir | string

  Path to conflist files describing the CNI configuration, e.g. /etc/cni/net.d. If not provided, the Istio control plane will be installed/upgraded with the Istio CNI plugin disabled. This path depends on the Kubernetes installation, please refer to https://kubernetes.io/docs/concepts/extend-kubernetes/compute-storage-net/network-plugins/ for information to find out the correct path.
* csr-domain-name | string

  The domain name to be used by the charm to send a Certificate Signing Request (CSR) to a TLS certificate provider. In the absence of this configuration option, the charm will try to use the ingress gateway service hostname (if configured by a LB) or its IP address.
* default-gateway | string

  Default: istio-gateway

  Name to use as a default gateway
* gateway-service-name | string

  Default: istio-ingressgateway-workload

  Name of the service created by istio-gateway to use as a Gateway
* image-configuration | string

  Default: pilot-image: 'pilot' # values.pilot.image
  global-tag: '1.24.2' # values.global.tag
  global-hub: 'docker.io/istio' # values.global.hub
  global-proxy-image: 'proxyv2' # values.global.proxy.image
  global-proxy-init-image: 'proxyv2' # values.global.proxy\_init.image
  grpc-bootstrap-init: 'busybox:1.28'

  YAML or JSON formatted input defining image configuration to use when installing the Istio control plane. For reference https://istio.io/v1.5/docs/reference/config/installation-options/
* tls-secret-id | secret

  A configuration option to store the user secret ID that stores the TLS certificate and key values.
  The secret ID is the result of adding a secret with the following format
  juju add-secret istio-tls-secret tls-crt="$(cat CERT\_FILE)" tls-key=$"$(cat KEY\_FILE)"
