Chuyển đến nội dung chính

LESSON 24: ISTIO SERVICE MESH ARCHITECTURE

Understand the Istio service mesh architecture: data plane (Envoy sidecar), control plane (istiod), traffic management, security (mTLS), observability, and compare with Linkerd.

🔒 DevSecOps — Lesson 24 LESSON 24: ISTIO SERVICE MESH ARCHITECTURE

Deploy Microservices On-Premises with Kubernetes HA

Part 6: Service Mesh & Ingress with Istio

xdev.asia

🎯 LESSON OBJECTIVE__HTMLTAG_66___
  • ✅ Understand what a service mesh is and why it is needed
  • ✅ Istio Architecture: Control Plane + Data Plane
  • ✅ Envoy sidecar proxy — how it works
  • ✅ Core features: traffic management, security, observability
  • ✅ Compare Istio vs Linkerd vs Cilium Service Mesh
  • ✅ Install Istio on K8s cluster

PART 1: WHAT IS SERVICE MESH?


graph LR
    subgraph WITHOUT["❌ WITHOUT Service Mesh"]
        A1["Service A
Retry? Timeout?"] -->|"Direct call
no encryption
no retry
no tracing"| B1["Service B
No auth? No limit?"] end subgraph WITH["✅ WITH Service Mesh — Istio"] A2["Service A
business logic"] --> EA["🔷 Envoy Sidecar
• Retry
• Timeout
• Tracing"] EA -->|"mTLS auto"| EB["🔷 Envoy Sidecar
• Auth
• RateLimit
• Metrics"] EB --> B2["Service B
business logic"] CP["istiod
Control Plane"] -.->|"Config push"| EA & EB end style WITHOUT fill:#450a0a,stroke:#dc2626,color:#fca5a5 style WITH fill:#052e16,stroke:#22c55e,color:#bbf7d0 style EA fill:#1d4ed8,stroke:#60a5fa,color:#fff style EB fill:#1d4ed8,stroke:#60a5fa,color:#fff style CP fill:#7c3aed,stroke:#a78bfa,color:#fff

1.1. When do you need Service Mesh?

  • ✅ > 10 microservices communicating
  • ✅ Need mTLS (zero-trust network)
  • ✅ Complex traffic routing (canary, A/B)
  • ✅ Distributed tracing & observability
  • ✅ Rate limiting, circuit breaking consistent
  • ❌ Overhead not required for monolith or < 5 services

PART 2: ISTIO ARCHITECTURE


graph TB
    subgraph CONTROL["🧠 CONTROL PLANE"]
        subgraph ISTIOD["istiod — Unified Binary"]
            Pilot["Pilot
Traffic config"] Citadel["Citadel
mTLS certs"] Galley["Galley
Config validation"] end end subgraph DATA["📡 DATA PLANE"] subgraph PodA["Pod A"] AppA["App A"] EnvA["🔷 Envoy Sidecar"] AppA --> EnvA end subgraph PodB["Pod B"] AppB["App B"] EnvB["🔷 Envoy Sidecar"] AppB --> EnvB end subgraph PodC["Pod C"] AppC["App C"] EnvC["🔷 Envoy Sidecar"] AppC --> EnvC end end ISTIOD -->|"xDS API
push config"| EnvA & EnvB & EnvC EnvA <-->|"mTLS"| EnvB EnvB <-->|"mTLS"| EnvC EnvA <-->|"mTLS"| EnvC style CONTROL fill:#4c1d95,stroke:#8b5cf6,color:#e2e8f0 style ISTIOD fill:#5b21b6,stroke:#a78bfa,color:#fff style EnvA fill:#1d4ed8,stroke:#60a5fa,color:#fff style EnvB fill:#1d4ed8,stroke:#60a5fa,color:#fff style EnvC fill:#1d4ed8,stroke:#60a5fa,color:#fff
ComponentRoleDetails
istiodControl PlaneSingle binary: Pilot + Citadel + Galley_
EnvoySidecar ProxyL4/L7 proxy, injected into every pod_
PilotTraffic ManagementConverts routing rules → Envoy xDS config
Citadel_SecurityCertificate authority, mTLS cert rotation_
Galley_ConfigurationValidates & distributes Istio config
FeatureIstioLinkerdCilium SM
ProxyEnvoy (C++)linkerd2-proxy (Rust)eBPF (kernel)
Resource UsageMedium-HighLowLowest
Features_Most completeEssential features_Growing_
Learning CurveSteepModerateLow-Moderate
mTLSYes (auto)Yes (auto)Yes (WireGuard)
Traffic MgmtAdvancedBasicBasic
Multi-clusterYesYesYes
WASM ExtensionsYesNoNo

PART 3: ISTIO SETUP

3.1. Install istioctl

# Download istioctl:
curl -L https://istio.io/downloadIstio | ISTIO_VERSION=1.22.0 sh -
cd istio-1.22.0
export PATH=$PWD/bin:$PATH

Verify:

istioctl version

client version: 1.22.0

3.2. Install Istio (Production Profile)

# istio-config.yaml:
apiVersion: install.istio.io/v1alpha1
kind: IstioOperator
metadata:
  name: production-istio
spec:
  profile: default
  
  meshConfig:
    accessLogFile: /dev/stdout
    accessLogEncoding: JSON
    enableTracing: true
    defaultConfig:
      tracing:
        sampling: 100.0
      holdApplicationUntilProxyStarts: true
    
    # Outbound traffic policy:
    outboundTrafficPolicy:
      mode: REGISTRY_ONLY    # Only allow registered services
    
    # Enable strict mTLS:
    # (configured via PeerAuthentication below)

  components:
    pilot:
      k8s:
        resources:
          requests:
            cpu: 500m
            memory: 512Mi
          limits:
            cpu: "2"
            memory: 2Gi
        replicas: 2          # HA istiod
        hpaSpec:
          maxReplicas: 3
          minReplicas: 2

    ingressGateways:
      - name: istio-ingressgateway
        enabled: true
        k8s:
          resources:
            requests:
              cpu: 200m
              memory: 256Mi
          service:
            type: LoadBalancer
          hpaSpec:
            maxReplicas: 5
            minReplicas: 2

  values:
    global:
      proxy:
        resources:
          requests:
            cpu: 50m
            memory: 64Mi
          limits:
            cpu: 500m
            memory: 256Mi
    pilot:
      traceSampling: 100.0
# Install:
istioctl install -f istio-config.yaml -y

# Verify:
kubectl -n istio-system get pods
# NAME                                    READY   STATUS
# istiod-xxx                              1/1     Running
# istiod-xxx                              1/1     Running  (HA replica)
# istio-ingressgateway-xxx                1/1     Running
# istio-ingressgateway-xxx                1/1     Running

# Enable sidecar injection cho namespaces:
kubectl label namespace default istio-injection=enabled
kubectl label namespace messaging istio-injection=enabled

# Verify injection:
kubectl get namespace -L istio-injection
# default     Active   istio-injection=enabled
# messaging   Active   istio-injection=enabled

PART 4: mTLS (MUTUAL TLS)

# Strict mTLS cho toàn mesh:
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
  name: default
  namespace: istio-system    # Mesh-wide
spec:
  mtls:
    mode: STRICT             # All traffic must be mTLS
---
# Exclude specific namespace (legacy apps):
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
  name: legacy-permissive
  namespace: legacy
spec:
  mtls:
    mode: PERMISSIVE         # Accept both plain + mTLS
# Verify mTLS:
istioctl x describe pod order-service-xxx.default
# Service: order-service.default
# mTLS: STRICT
# Certificates:
#   Certificate chain: valid
#   Server certificate: valid

# Check certificate:
istioctl proxy-config secret order-service-xxx.default
# RESOURCE NAME     TYPE     STATUS   VALID CERT   SERIAL NUMBER
# default           Cert     ACTIVE   true         xxx
# ROOTCA            CA       ACTIVE   true         xxx

PART 5: SIDECAR INJECTION

# Automatic injection (namespace label):
kubectl label namespace default istio-injection=enabled

# Manual injection (specific deployment):
kubectl apply -f <(istioctl kube-inject -f deployment.yaml)

# Verify sidecar:
kubectl get pods -n default
# order-service-xxx   2/2   Running   ← 2 containers = app + envoy

# Check Envoy config:
istioctl proxy-config clusters order-service-xxx.default
istioctl proxy-config routes order-service-xxx.default
istioctl proxy-config listeners order-service-xxx.default

# Envoy dashboard:
istioctl dashboard envoy order-service-xxx.default

PART 6: OBSERVABILITY ADD-ONS

# Install Kiali (service mesh dashboard):
kubectl apply -f https://raw.githubusercontent.com/istio/istio/release-1.22/samples/addons/kiali.yaml

# Install Jaeger (distributed tracing):
kubectl apply -f https://raw.githubusercontent.com/istio/istio/release-1.22/samples/addons/jaeger.yaml

# Access:
istioctl dashboard kiali
istioctl dashboard jaeger

# Kiali shows:
# - Service topology graph (real-time)
# - Traffic flow between services
# - Error rates, latency
# - mTLS status
# - Istio configuration validation

💡 KEY TAKEAWAYS

  1. Service Mesh: Infrastructure layer for service-to-service communication
  2. Istio: Most feature-rich mesh, Envoy sidecar proxy
  3. istiod: Single control plane binary (Pilot + Citadel + Galley)
  4. mTLS STRICT: Zero-trust, all traffic encrypted automatically
  5. Sidecar injection: Label namespace, auto-inject Envoy
  6. Kiali: Visual service topology, essential for understanding mesh

🎯 EXERCISE

Exercise 1: Install Istio__HTMLTAG_306___
  • Install Istio with production profile
  • Enable sidecar injection on default namespace__HTMLTAG_311___
  • Deploy sample Bookinfo app
  • Verify mTLS between services

Exercise 2: Kiali & Jaeger

  • Install Kiali, explore service graph
  • Generate traffic, view traces in Jaeger__HTMLTAG_323___
  • Identify slowest service in request chain

📚 NEXT POST

In Lesson 25: Istio Traffic Management — VirtualService, DestinationRule, we will configure traffic routing, canary deployment, and circuit breaking.