apiVersion: v1 kind: Namespace metadata: name: istio labels: istio-injection: enabled # Istio sidecar requer NET_ADMIN e NET_RAW capabilities pod-security.kubernetes.io/enforce: privileged pod-security.kubernetes.io/warn: privileged