After you create an Alibaba Cloud Service Mesh (ASM) instance, you can modify the ASM instance as required. This topic describes how to modify an ASM instance.

  1. Log on to the ASM console.
  2. In the left-side navigation pane, choose Service Mesh > Mesh Management.
  3. On the Mesh Management page, find the ASM instance that you want to configure. Click the name of the ASM instance or click Manage in the Actions column.
  4. On the Basic Information page, click Settings in the upper-right corner. In the Settings Update panel, modify the parameters as needed and click OK.
    Parameter Description
    Observability Specify whether to enable Tracing Analysis for the ASM instance. If you enable this feature, you must set the Sampling Percentage and Sampling Method parameters.
    ASM integrates with Tracing Analysis. Tracing Analysis provides a wide range of tools to help you efficiently identify the performance bottlenecks of distributed applications. You can use these tools to map traces, display trace topologies, analyze application dependencies, and count the number of requests. This improves your efficiency in developing and troubleshooting distributed applications. For more information, see Use Tracing Analysis to trace applications inside and outside an ASM instance.
    Note Before you enable Tracing Analysis for the ASM instance, make sure that you have activated the Tracing Analysis service in the Tracing Analysis console.
    Specify whether to enable Prometheus for the ASM instance. If you enable this feature, you must select Enable Alibaba Cloud Prometheus or Enable Self-managed Prometheus.

    ASM integrates with Prometheus Service of Application Real-Time Monitoring Service (ARMS) and self-managed Prometheus systems. This helps you monitor ASM instances. For more information, see Monitor service meshes based on ARMS Prometheus and Deploy a self-managed Prometheus instance to monitor ASM instances.

    Specify whether to enable Kiali for the ASM instance. If you enable this feature, you must enter the endpoint of the Prometheus instance used by Kiali.
    Kiali for ASM is a tool that is used to observe ASM instances. This tool provides a GUI that allows you to view related services and configurations. For more information, see Enable Kiali for ASM to observe an ASM instance in the ASM console.
    Note To enable Kiali, you must enable Prometheus.
    Specify whether to enable access log collection.

    The Envoy proxy that is deployed on the data plane generates logs for all access records. The data plane contains the Kubernetes clusters of an ASM instance. You can enable the access log collection feature. After that, you can view the access logs on the data plane. For more information, see Customize access logs on the data plane.

    Specify whether to enable access log query. If you enable this feature, you must set the Log Service Project parameter to use the default or existing project in Log Service.

    Container Service for Kubernetes (ACK) integrates with Log Service. You can collect the access logs of clusters on the data plane of an ASM instance. To use the log collection feature for an ASM instance, you must enable access log query for the ASM instance. For more information, see Use Log Service to collect logs of ingress gateways on the data plane and Use Log Service to collect access logs of the data plane.

    Traffic Management Specify whether to use HTTP/1.

    By default, HTTP/2 is used. To use HTTP/1, select Enable HTTP 1.0.

    Policy Control Specify whether to enable the Open Policy Agent (OPA) plug-in.

    ASM integrates with OPA to help you implement fine-grained access control on your applications. If you enable the OPA plug-in, OPA containers and Istio Envoy proxy containers are injected into the pods of applications. Then, you can use OPA to define access control policies. This out-of-box feature improves your efficiency in developing distributed applications. For more information, see Use OPA to implement fine-grained access control in ASM.

    Data Plane Extension Specify whether to use the WebAssembly (Wasm)-based ASM instance extension.

    ASM supports Wasm. You can deploy Wasm filters in the Envoy proxy that is used to manage clusters on the data plane. This helps you extend the data plane with new features. For more information, see Write WASM filters for Envoy and deploy them in ASM.

    Service Mesh Resource Configuration Specify whether to enable the rollback feature for Istio resources.

    ASM provides the rollback feature for Istio resources. This feature records up to five historical versions of Istio resources that are updated in the recent period. For more information, see Roll back an Istio resource to an earlier version.

    Specify whether to allow the Kubernetes API of clusters on the data plane to access Istio resources.

    ASM allows you to create, delete, modify, and query Istio resources by using the Kubernetes API of clusters on the data plane. For more information, see Use the Kubernetes API of clusters on the data plane to access Istio resources.

    Performance Optimization Specify whether to enable MultiBuffer-based TLS encryption and decryption performance optimization.
    ASM combines with Intel Multi-Buffer to accelerate TLS processing in Envoy to alleviate the bottleneck. For more information, see Enable Multi-Buffer for TLS acceleration.
    Note This feature is supported only by ASM Enterprise Edition and Ultimate Edition instances.