Service Mesh: Istio & Linkerd
Sidecars, mTLS and traffic policy without code changes: what a mesh does, modelled honestly.
An interactive Kubernetes lesson: 21 steps, about 35 minutes, on a live simulation in your browser.
The shop's frontend, web, calls the backend api for product data. Two Deployments, two replicas each, one Service in front of api. The stream is green: every request returns 200.
The app code does nothing special. It opens plain HTTP to http://api and reads the reply. There is no TLS here, no identity check, nothing that proves either side is who it claims to be.
What you will learn
Traffic in the clear
- web calls api over plain HTTP: A bare Service gives you reachability: anyone who can route to it may call it, as anyone.
- Anyone on the path can read it: Encryption is not the default anywhere: not in etcd, not on the wire, not between sidecars you never installed.
- A stranger calls api: Without a policy, the only question the cluster asks is whether packets can route. Identity is never asked for.
A proxy in every pod
- Label the namespace for injection: Injection is admission-time templating: the label opts the namespace in, and new pods are born with two containers.
- Every pod gains a proxy: The mesh moves networking out of the app: the app speaks plain HTTP to localhost, and the proxy speaks mesh to the world.
- The app dials localhost: In a meshed pod the app's whole network is localhost plus its own proxy. The proxy owns every connection that leaves.
- Drill: enable injection
mTLS: strict vs permissive
- PERMISSIVE accepts both: PERMISSIVE is the migration mode: mTLS where both ends have a proxy, plain text everywhere else, no breakage mid-rollout.
- STRICT meets an unmeshed caller: STRICT moves the question from can packets route to can the caller prove who it is. No certificate, no answer.
- STRICT in YAML
Who may call
- AuthorizationPolicy: what, not who: PeerAuthentication asks who are you. AuthorizationPolicy asks who are you, and may you do this.
- A real allow and a real deny: A NetworkPolicy allow-list is re-evaluated continuously: change a label and the next connection follows it.
- probe borrows web's label: A label is a claim, a certificate is a proof. NetworkPolicy trusts the sticker; mTLS checks the proof.
- Break it: deny all, allow nothing
Split the traffic
- Version 2, running and unused
- Send a tenth of the traffic to v2: Weights are proportions: a backend gets weight over total. 90 and 10 is the same split as 9 and 1.
- Break it: the canary crashes
Istio, Linkerd or ambient
- Three ways to run a mesh: Every mesh trades per-request features against per-pod cost. Sidecars see the most, ambient costs the least per pod.
- Drill: why is my route dark?
Recap & playground
- Cheat sheet
- Playground