The SecurityPolicy in cloudArmor.ts is unattached to the backend service defined in istio.ts. Attach it when defined. Might involve [defining BackendConfig](https://cloud.google.com/kubernetes-engine/docs/how-to/ingress-configuration#cloud_armor) from Pulumi, as we can't modify the backend service directly.