Government & Public Sector

Zero trust connectivity for mission-critical platforms

Solo.io helps defense, intelligence and civilian agencies modernize application connectivity, enforce zero trust and scale cloud-native platforms across Kubernetes, VMs and hybrid environments, with FIPS 140-3 compliant images and an architecture aligned to the NIST zero trust guidance federal programs are built on.

Use cases

Secure modernization for every mission

Agencies are modernizing on Kubernetes while keeping decades of existing systems in service. Solo.io gives both one consistent layer for identity, policy and traffic control.

Zero trust architecture for modern applications

Enforce zero trust on service-to-service and north-south traffic with cryptographic workload identity, mTLS, authorization policy and segmentation. The architecture maps to NIST SP 800-207 and 800-204A, and multicluster peering connects clusters over mTLS without remote Kubernetes API server access or shared secrets.

Policy-driven security and compliance

Define, apply and verify policy at the application networking layer, so security shifts left and is enforced the same way at runtime. Declarative, GitOps-friendly configuration and centralized control keep every cluster on the same baseline.

Modernization without disruption

Move legacy and VM-based systems to cloud-native platforms in phases. The ambient mesh extends to virtual machines, Amazon ECS services and EC2 instances, so mission systems keep running while new services come online around them.

Government-ready

Built for federal security requirements

The controls security teams ask for first, delivered as part of the platform instead of bolted on afterward.

FIPS

FIPS 140-3 compliant images

FIPS builds of Solo Enterprise for Istio use current releases of cryptographic module families with active NIST CMVP validations, the update-stream approach FedRAMP’s cryptographic module policy prefers. Solo Enterprise for kgateway ships FIPS images for its control and data planes.

NIST

Zero trust by design

Cryptographic workload identity, mTLS between workloads and deny-by-default authorization policy, aligned to NIST SP 800-207 (zero trust architecture) and SP 800-204A (service mesh security for microservices).

Identity

Identity you can prove

SPIRE integration issues each workload’s mTLS certificate only after SPIRE node and workload attestation, instead of trusting a Kubernetes service account alone. Pods need no changes.

Lifecycle

Extended support and CVE response

Solo patches the current Istio release and the four before it (n-4, 1.27 through 1.31 today), well beyond the upstream window, with daily CVE scans. Security fixes ship in Solo builds of Istio.

Compliance

Built for FedRAMP programs

Software vendors pursuing FedRAMP run Solo’s FIPS builds of Istio in their government offerings. Solo can provide per-component cryptographic module details and image digests for your System Security Plan.

Control

No shared secrets, no call-home

Clusters peer through east-west gateways over mTLS, with no remote API server access. Identity, policy, telemetry and audit stay inside your environment, and air-gapped installs are supported.

Outcomes

Secure. Modernize. Scale.

One connectivity layer for the platforms agencies run today and the ones they are building next.

Secure

Deliver resilient infrastructure with zero trust enforcement, strong workload identity and FIPS 140-3 compliant builds. kgateway adds FIPS images, a web application firewall with the OWASP Core Rule Set, and data loss prevention at the edge.

Modernize

Turn legacy and VM-based estates into cloud-native platforms one step at a time. Solo Enterprise for Istio spans multicluster, hybrid and multi-cloud architectures, and brings VMs, Amazon ECS services and EC2 instances into the same mesh as Kubernetes.

Scale

Carry high-volume, mission-critical traffic. Solo Enterprise for Istio multicluster peering has been tested at 100 million pods across 2,000 clusters, and kgateway led the open source gateway-api-bench benchmark at over 400,000 requests per second from a single instance.

Defense and government modernization

Solutions for government platforms

Istio is the service mesh in DoD DevSecOps baselines such as Platform One’s Big Bang. Solo.io helps agencies standardize secure connectivity and runtime controls on top of it.

Centralized policy

Service networking and policy enforcement managed from one control point.

Hybrid and multicluster

One mesh across clusters, clouds, VMs and on-premises environments.

Secure ingress

API traffic management and edge security for every application.

Identity-based control

Workload and agent identity for modern service and agentic architectures.

Service mesh

Solo Enterprise for Istio

Enterprise service mesh built on Istio Ambient Mesh, with no sidecars required. It adds multicluster peering, SPIRE integration, L7 observability, and support for VMs, Amazon ECS and EC2. The latest release, 1.31, adds SPIFFE trust-domain validation and Workload Identity Tokens.

API gateway

Solo Enterprise for kgateway

High-performance, Kubernetes-native API gateway built on kgateway, a CNCF Sandbox project. It provides secure ingress, OAuth 2.0/OIDC and JWT authentication, WAF and DLP policies, FIPS images, 24x7 support and patches for the current and three previous releases (n-3).

Agentic AI

Solo Enterprise for kagent

For agencies adopting agentic AI: run agents, MCP tools and skills on Kubernetes with kagent. Every agent gets a verifiable identity, and every action is governed by policy and traced. Pair it with agentgateway to control agent, tool and model traffic at one gateway.

FAQ

Solo.io for government, answered

Are Solo.io’s Istio images FIPS compliant?

Yes. Solo’s FIPS builds of Istio are FIPS 140-3 compliant. Each component uses a current release of a cryptographic module family that holds active NIST CMVP validations, which fits the update-stream position in FedRAMP’s Policy for Cryptographic Module Selection and Use. Solo can share per-component module details and image digests for your audit. Solo Enterprise for kgateway also ships FIPS images.

How does Solo.io support NIST zero trust guidance?

Solo Enterprise for Istio gives every workload a cryptographic identity, encrypts traffic between workloads with mTLS and lets you enforce deny-by-default authorization policy. That architecture aligns with NIST SP 800-207 and SP 800-204A.

Can we modernize without replacing legacy systems?

Yes. The ambient mesh extends to virtual machines, Amazon ECS services and EC2 instances, so existing systems join the same mTLS, policy and observability as new Kubernetes services and can be migrated in phases.

Does Solo.io support FedRAMP programs?

Yes. Software vendors pursuing FedRAMP run Solo’s FIPS builds of Istio in their government offerings. The images track validated cryptographic module update streams, and Solo can provide the module and digest details your System Security Plan needs.

How long are releases supported?

Solo patches the current Istio release and the four before it (n-4; 1.27 through 1.31 as of October 2026), beyond the upstream support window, with daily CVE scanning. Solo Enterprise for kgateway is supported n-3.

Can Solo.io secure agentic AI in government environments?

Yes. Solo Enterprise for kagent runs agents, MCP tools and skills with verifiable identity, policy and tracing, and agentgateway governs agent-to-model, agent-to-tool and agent-to-agent traffic. Both are open source and run inside your environment.

Additional resources

Go deeper on FIPS, zero trust and the latest release of Solo Enterprise for Istio.

Topic

FIPS for Istio from Solo.io

Government-ready zero trust architecture aligned to FIPS, NIST 800-204A and 800-207.

Blog

How service mesh supports a zero trust architecture

How identity, mTLS and policy in the mesh map to federal zero trust requirements.

Docs

Solo Enterprise for Istio 1.31 release notes

SPIFFE trust-domain validation, Workload Identity Tokens, multi-workload VMs and performance gains.

Modernize without compromising the mission

Talk to Solo.io about zero trust connectivity, FIPS builds and extended support for your agency’s platforms.