Government & Public Sector
Zero trust connectivity for mission-critical platforms
Solo.io helps defense, intelligence and civilian agencies modernize application connectivity, enforce zero trust and scale cloud-native platforms across Kubernetes, VMs and hybrid environments, with FIPS 140-3 compliant images and an architecture aligned to the NIST zero trust guidance federal programs are built on.
Use cases
Secure modernization for every mission
Agencies are modernizing on Kubernetes while keeping decades of existing systems in service. Solo.io gives both one consistent layer for identity, policy and traffic control.
Zero trust architecture for modern applications
Enforce zero trust on service-to-service and north-south traffic with cryptographic workload identity, mTLS, authorization policy and segmentation. The architecture maps to NIST SP 800-207 and 800-204A, and multicluster peering connects clusters over mTLS without remote Kubernetes API server access or shared secrets.
Policy-driven security and compliance
Define, apply and verify policy at the application networking layer, so security shifts left and is enforced the same way at runtime. Declarative, GitOps-friendly configuration and centralized control keep every cluster on the same baseline.
Modernization without disruption
Move legacy and VM-based systems to cloud-native platforms in phases. The ambient mesh extends to virtual machines, Amazon ECS services and EC2 instances, so mission systems keep running while new services come online around them.
Government-ready
Built for federal security requirements
The controls security teams ask for first, delivered as part of the platform instead of bolted on afterward.
FIPS
FIPS 140-3 compliant images
FIPS builds of Solo Enterprise for Istio use current releases of cryptographic module families with active NIST CMVP validations, the update-stream approach FedRAMP’s cryptographic module policy prefers. Solo Enterprise for kgateway ships FIPS images for its control and data planes.
NIST
Zero trust by design
Cryptographic workload identity, mTLS between workloads and deny-by-default authorization policy, aligned to NIST SP 800-207 (zero trust architecture) and SP 800-204A (service mesh security for microservices).
Identity
Identity you can prove
SPIRE integration issues each workload’s mTLS certificate only after SPIRE node and workload attestation, instead of trusting a Kubernetes service account alone. Pods need no changes.
Lifecycle
Extended support and CVE response
Solo patches the current Istio release and the four before it (n-4, 1.27 through 1.31 today), well beyond the upstream window, with daily CVE scans. Security fixes ship in Solo builds of Istio.
Compliance
Built for FedRAMP programs
Software vendors pursuing FedRAMP run Solo’s FIPS builds of Istio in their government offerings. Solo can provide per-component cryptographic module details and image digests for your System Security Plan.
Control
No shared secrets, no call-home
Clusters peer through east-west gateways over mTLS, with no remote API server access. Identity, policy, telemetry and audit stay inside your environment, and air-gapped installs are supported.
Outcomes
Secure. Modernize. Scale.
One connectivity layer for the platforms agencies run today and the ones they are building next.
Secure
Deliver resilient infrastructure with zero trust enforcement, strong workload identity and FIPS 140-3 compliant builds. kgateway adds FIPS images, a web application firewall with the OWASP Core Rule Set, and data loss prevention at the edge.
Modernize
Turn legacy and VM-based estates into cloud-native platforms one step at a time. Solo Enterprise for Istio spans multicluster, hybrid and multi-cloud architectures, and brings VMs, Amazon ECS services and EC2 instances into the same mesh as Kubernetes.
Scale
Carry high-volume, mission-critical traffic. Solo Enterprise for Istio multicluster peering has been tested at 100 million pods across 2,000 clusters, and kgateway led the open source gateway-api-bench benchmark at over 400,000 requests per second from a single instance.
Defense and government modernization
Solutions for government platforms
Istio is the service mesh in DoD DevSecOps baselines such as Platform One’s Big Bang. Solo.io helps agencies standardize secure connectivity and runtime controls on top of it.
Centralized policy
Service networking and policy enforcement managed from one control point.
Hybrid and multicluster
One mesh across clusters, clouds, VMs and on-premises environments.
Secure ingress
API traffic management and edge security for every application.
Identity-based control
Workload and agent identity for modern service and agentic architectures.
Service mesh
Solo Enterprise for Istio
Enterprise service mesh built on Istio Ambient Mesh, with no sidecars required. It adds multicluster peering, SPIRE integration, L7 observability, and support for VMs, Amazon ECS and EC2. The latest release, 1.31, adds SPIFFE trust-domain validation and Workload Identity Tokens.
API gateway
Solo Enterprise for kgateway
High-performance, Kubernetes-native API gateway built on kgateway, a CNCF Sandbox project. It provides secure ingress, OAuth 2.0/OIDC and JWT authentication, WAF and DLP policies, FIPS images, 24x7 support and patches for the current and three previous releases (n-3).
Agentic AI
Solo Enterprise for kagent
For agencies adopting agentic AI: run agents, MCP tools and skills on Kubernetes with kagent. Every agent gets a verifiable identity, and every action is governed by policy and traced. Pair it with agentgateway to control agent, tool and model traffic at one gateway.
FAQ
Solo.io for government, answered
Are Solo.io’s Istio images FIPS compliant?
Yes. Solo’s FIPS builds of Istio are FIPS 140-3 compliant. Each component uses a current release of a cryptographic module family that holds active NIST CMVP validations, which fits the update-stream position in FedRAMP’s Policy for Cryptographic Module Selection and Use. Solo can share per-component module details and image digests for your audit. Solo Enterprise for kgateway also ships FIPS images.
How does Solo.io support NIST zero trust guidance?
Solo Enterprise for Istio gives every workload a cryptographic identity, encrypts traffic between workloads with mTLS and lets you enforce deny-by-default authorization policy. That architecture aligns with NIST SP 800-207 and SP 800-204A.
Can we modernize without replacing legacy systems?
Yes. The ambient mesh extends to virtual machines, Amazon ECS services and EC2 instances, so existing systems join the same mTLS, policy and observability as new Kubernetes services and can be migrated in phases.
Does Solo.io support FedRAMP programs?
Yes. Software vendors pursuing FedRAMP run Solo’s FIPS builds of Istio in their government offerings. The images track validated cryptographic module update streams, and Solo can provide the module and digest details your System Security Plan needs.
How long are releases supported?
Solo patches the current Istio release and the four before it (n-4; 1.27 through 1.31 as of October 2026), beyond the upstream support window, with daily CVE scanning. Solo Enterprise for kgateway is supported n-3.
Can Solo.io secure agentic AI in government environments?
Yes. Solo Enterprise for kagent runs agents, MCP tools and skills with verifiable identity, policy and tracing, and agentgateway governs agent-to-model, agent-to-tool and agent-to-agent traffic. Both are open source and run inside your environment.
Additional resources
Go deeper on FIPS, zero trust and the latest release of Solo Enterprise for Istio.
Topic
FIPS for Istio from Solo.io
Government-ready zero trust architecture aligned to FIPS, NIST 800-204A and 800-207.
Blog
How service mesh supports a zero trust architecture
How identity, mTLS and policy in the mesh map to federal zero trust requirements.
Docs
Solo Enterprise for Istio 1.31 release notes
SPIFFE trust-domain validation, Workload Identity Tokens, multi-workload VMs and performance gains.
Modernize without compromising the mission
Talk to Solo.io about zero trust connectivity, FIPS builds and extended support for your agency’s platforms.