Community release · v0.2.0

Know your effective Istio posture. Follow the evidence.

OpenMeshGuard resolves deployed mTLS and authorization for sidecar, ambient, and mixed meshes. Every conclusion carries the policies that produced it, so you can inspect the evidence and act on what is known. Add an optional Prometheus endpoint to compare sidecar configuration with observed destination mTLS evidence.

Least-privilege get/listSidecar + ambientNever reads SecretsUpstream Istio first
Illustrative report · example dataprod-istio-east-01
74 / 100
Mesh governance score74
3 fail19 warn81 pass7 unknown
mTLS posture67%Production namespaces enforcing strict mode
AuthZ coverage54%Workloads with explicit policy
Runtime verificationUnknownNo Prometheus endpoint in this example
Mesh modeSidecar + ambientMixed meshes supported
FindingEvidence
Failpayments/frontend-gatewayWildcard host exposes an internal service
Failclaims-prodWorkload has no explicit authorization coverage
Unknownztunnel coverage2 scheduled nodes have missing ambient evidence

Why it exists

Configuration tells one part of the story. Resolution shows which policies actually apply.

Available in v0.2.0

Govern the mesh without taking over the mesh.

Start with a lean Go CLI that reads Kubernetes, Istio, and Gateway API resources using explicit least-privilege RBAC. OpenMeshGuard reports effective posture and missing evidence with remediation guidance. Missing permissions and unclassified context stay unknown; declared and runtime-verified posture remain separate.

Inventory

Discover namespaces, workloads, Istio resources, Gateway API routes, proxy versions, ztunnel, and waypoints.

Findings

Resolve effective mTLS and authorization; evaluate gateway exposure, ambient enforcement gaps, ownership, and exceptions.

Evidence

Export canonical JSON, SARIF, and self-contained HTML. Use weighted scores and opt-in CI thresholds with explicit unknowns.

Install and scan

Your first scan starts with read access.

Download signed archives for macOS and Linux, on Intel / amd64 or arm64. Verify the archive and signed checksumsbefore extraction, then put the binary on your PATH. Homebrew is also available through the public OpenMeshGuard tap. A Go toolchain is an alternative.

The scanner uses only Kubernetes get/list operations. It never reads Secrets, changes resources, installs Istio, or opens exec sessions. Review the RBAC profiles.

# Install with Homebrew
brew install openmeshguard/tap/openmeshguard

# Alternative install with Go 1.24+
go install github.com/openmeshguard/openmeshguard/cmd/openmeshguard@v0.2.0
openmeshguard version

# Scan one namespace; save canonical JSON
openmeshguard scan --context my-cluster --namespace payments > report.json

# Render self-contained HTML and SARIF
openmeshguard report --input report.json --format html --output report.html
openmeshguard export --input report.json --format sarif --output report.sarif

# Inspect scores from the same evidence
openmeshguard score --input report.json

Optional runtime evidence

Compare declared posture with observed sidecar events.

Use a Prometheus endpoint containing metrics for the scanned cluster only. Declared and runtime-verified posture stay separate. The default lookback is seven days; the report shows the actual window when collection degrades.

The mTLS event share combines HTTP request events and TCP connection-opening events; it does not measure bytes or compare traffic volume across protocols. Plaintext observed during the window can predate the current policy. Missing telemetry stays unknown, and no traffic does not prove protection.

# Add destination-side runtime evidence
openmeshguard scan --context my-cluster --namespace payments \
  --prometheus-url https://prometheus.example.com \
  --prometheus-token-file /path/to/prometheus-token \
  --prometheus-lookback 168h > verified-report.json

openmeshguard report --input verified-report.json --output verified-report.html

Support and boundaries

Clear about what this release can prove.

Upstream Istio

Sidecar, ambient, and mixed meshes are supported. A scan evaluates one cluster at a time. Multi-cluster participation can be detected; cross-cluster policy correlation is future work.

Opt-in sidecar verification

Prometheus adds observed destination plaintext and the mutual TLS share of combined HTTP request and TCP connection-opening events. Missing telemetry and no observed traffic cannot establish a pass. Ambient/mixed runtime verification and source attribution remain unsupported.

Read the telemetry boundaries

Community support

Report unexpected results with the affected policy and resolution chain. Distribution validation, lifecycle controls, offline scanning, and GitOps drift are future work.

Report a finding or ask a question

OpenMeshGuard produces security posture evidence, not a compliance certification. Lifecycle scores remain unknown until lifecycle controls ship.