Launch an environment with Istio/Envoy and Kubeshark and try all possible common scenario. Document the process and the results.
What permissions are required
What envoy configuration is required
how to enable/disable mTLS - see if Kubeshark shows encrypted traffic.