Designing Service Mesh Architecture
1. Understanding Service Mesh Concepts
| Concept | Detail |
|---|---|
| Data plane | Sidecar / ambient proxy (Envoy) |
| Control plane | Pushes config to proxies |
| Sidecar mode | Per-pod proxy |
| Ambient / sidecarless | Per-node proxy (Cilium, Istio Ambient) |
| Tools | Istio, Linkerd, Consul, Cilium Service Mesh |
2. Designing Service-to-Service Communication
| Capability | Detail |
|---|---|
| Transparent mTLS | Auto identity + encryption |
| Retries / timeouts | Mesh-level config |
| Load balancing | Round-robin, least-req, ring-hash |
| L7 routing | Header / path-based |
3. Designing Traffic Management
| Pattern | Detail |
|---|---|
| Weighted routing | Canary 90/10 |
| Header-based | x-env: canary → new version |
| Mirroring | Shadow traffic |
| Outlier detection | Eject unhealthy upstreams |
4. Designing Service Discovery
| Mechanism | Detail |
|---|---|
| DNS | K8s Service DNS |
| Mesh registry | From cluster API |
| Multi-cluster | Federation / east-west gateway |
5. Designing Mutual TLS (mTLS)
| Aspect | Detail |
|---|---|
| Identity | SPIFFE / SPIRE |
| Cert rotation | Short-lived, auto-rotated |
| Policies | STRICT mode in production |
| Authorization | Source identity → allow rules |
6. Designing Observability and Tracing
| Signal | Detail |
|---|---|
| Golden metrics | RED auto-collected per service |
| Access logs | L7 logs from sidecar |
| Tracing | Auto-propagation; needs context headers |
| Dashboards | Kiali / Linkerd-viz / Grafana |
7. Designing Traffic Policies
| Policy | Detail |
|---|---|
| DestinationRule | Subsets, LB algo, conn pool |
| VirtualService | Routing rules |
| Retry budget | Cap retries |
| Circuit breaker | Outlier ejection thresholds |
8. Designing Canary Deployments with Mesh
| Tool | Detail |
|---|---|
| Flagger / Argo Rollouts | Automated promotion |
| Metrics provider | Prom / Datadog |
| Auto-rollback | If success rate drops |
| Header-based for testers | Internal validation first |
9. Designing Fault Injection Testing
| Type | Detail |
|---|---|
| Delay | Add latency |
| Abort | Return 5xx |
| Targeted | By header / route |
| Use | Validate retry / CB / fallback |
10. Designing Rate Limiting at Mesh Level
| Mode | Detail |
|---|---|
| Local | Per-proxy; fast |
| Global | External ratelimit service (Envoy RLS) |
| Per-route | Apply selectively |
| Per-identity | Use mTLS identity as key |
11. Designing Service Mesh Security
| Control | Detail |
|---|---|
| AuthorizationPolicy | Allow service-A → service-B only |
| JWT validation at edge | Reject unauth at ingress |
| Default deny | Allow-list approach |
| Audit | All policy decisions logged |
12. Designing Multi-Cluster Service Mesh
| Pattern | Detail |
|---|---|
| Single mesh / multi-cluster | Shared root CA |
| East-west gateway | Inter-cluster traffic |
| Federated discovery | Cross-cluster endpoints |
| Locality-aware LB | Prefer same-cluster |