🎯 LESSON OBJECTIVE__HTMLTAG_66___
- ✅ Understand what a service mesh is and why it is needed
- ✅ Istio Architecture: Control Plane + Data Plane
- ✅ Envoy sidecar proxy — how it works
- ✅ Core features: traffic management, security, observability
- ✅ Compare Istio vs Linkerd vs Cilium Service Mesh
- ✅ Install Istio on K8s cluster
PART 1: WHAT IS SERVICE MESH?
graph LR
subgraph WITHOUT["❌ WITHOUT Service Mesh"]
A1["Service A
Retry? Timeout?"] -->|"Direct call
no encryption
no retry
no tracing"| B1["Service B
No auth? No limit?"]
end
subgraph WITH["✅ WITH Service Mesh — Istio"]
A2["Service A
business logic"] --> EA["🔷 Envoy Sidecar
• Retry
• Timeout
• Tracing"]
EA -->|"mTLS auto"| EB["🔷 Envoy Sidecar
• Auth
• RateLimit
• Metrics"]
EB --> B2["Service B
business logic"]
CP["istiod
Control Plane"] -.->|"Config push"| EA & EB
end
style WITHOUT fill:#450a0a,stroke:#dc2626,color:#fca5a5
style WITH fill:#052e16,stroke:#22c55e,color:#bbf7d0
style EA fill:#1d4ed8,stroke:#60a5fa,color:#fff
style EB fill:#1d4ed8,stroke:#60a5fa,color:#fff
style CP fill:#7c3aed,stroke:#a78bfa,color:#fff
1.1. When do you need Service Mesh?
- ✅ > 10 microservices communicating
- ✅ Need mTLS (zero-trust network)
- ✅ Complex traffic routing (canary, A/B)
- ✅ Distributed tracing & observability
- ✅ Rate limiting, circuit breaking consistent
- ❌ Overhead not required for monolith or < 5 services
PART 2: ISTIO ARCHITECTURE
graph TB
subgraph CONTROL["🧠 CONTROL PLANE"]
subgraph ISTIOD["istiod — Unified Binary"]
Pilot["Pilot
Traffic config"]
Citadel["Citadel
mTLS certs"]
Galley["Galley
Config validation"]
end
end
subgraph DATA["📡 DATA PLANE"]
subgraph PodA["Pod A"]
AppA["App A"]
EnvA["🔷 Envoy Sidecar"]
AppA --> EnvA
end
subgraph PodB["Pod B"]
AppB["App B"]
EnvB["🔷 Envoy Sidecar"]
AppB --> EnvB
end
subgraph PodC["Pod C"]
AppC["App C"]
EnvC["🔷 Envoy Sidecar"]
AppC --> EnvC
end
end
ISTIOD -->|"xDS API
push config"| EnvA & EnvB & EnvC
EnvA <-->|"mTLS"| EnvB
EnvB <-->|"mTLS"| EnvC
EnvA <-->|"mTLS"| EnvC
style CONTROL fill:#4c1d95,stroke:#8b5cf6,color:#e2e8f0
style ISTIOD fill:#5b21b6,stroke:#a78bfa,color:#fff
style EnvA fill:#1d4ed8,stroke:#60a5fa,color:#fff
style EnvB fill:#1d4ed8,stroke:#60a5fa,color:#fff
style EnvC fill:#1d4ed8,stroke:#60a5fa,color:#fff
| Component | Role | Details |
|---|---|---|
| istiod | Control Plane | Single binary: Pilot + Citadel + Galley_ |
| Envoy | Sidecar Proxy | L4/L7 proxy, injected into every pod_ |
| Pilot | Traffic Management | Converts routing rules → Envoy xDS config |
| Citadel_ | Security | Certificate authority, mTLS cert rotation_ |
| Galley_ | Configuration | Validates & distributes Istio config |
| Feature | Istio | Linkerd | Cilium SM |
|---|---|---|---|
| Proxy | Envoy (C++) | linkerd2-proxy (Rust) | eBPF (kernel) |
| Resource Usage | Medium-High | Low | Lowest |
| Features_ | Most complete | Essential features_ | Growing_ |
| Learning Curve | Steep | Moderate | Low-Moderate |
| mTLS | Yes (auto) | Yes (auto) | Yes (WireGuard) |
| Traffic Mgmt | Advanced | Basic | Basic |
| Multi-cluster | Yes | Yes | Yes |
| WASM Extensions | Yes | No | No |
PART 3: ISTIO SETUP
3.1. Install istioctl
# Download istioctl: curl -L https://istio.io/downloadIstio | ISTIO_VERSION=1.22.0 sh - cd istio-1.22.0 export PATH=$PWD/bin:$PATHVerify:
istioctl version
client version: 1.22.0
3.2. Install Istio (Production Profile)
# istio-config.yaml:
apiVersion: install.istio.io/v1alpha1
kind: IstioOperator
metadata:
name: production-istio
spec:
profile: default
meshConfig:
accessLogFile: /dev/stdout
accessLogEncoding: JSON
enableTracing: true
defaultConfig:
tracing:
sampling: 100.0
holdApplicationUntilProxyStarts: true
# Outbound traffic policy:
outboundTrafficPolicy:
mode: REGISTRY_ONLY # Only allow registered services
# Enable strict mTLS:
# (configured via PeerAuthentication below)
components:
pilot:
k8s:
resources:
requests:
cpu: 500m
memory: 512Mi
limits:
cpu: "2"
memory: 2Gi
replicas: 2 # HA istiod
hpaSpec:
maxReplicas: 3
minReplicas: 2
ingressGateways:
- name: istio-ingressgateway
enabled: true
k8s:
resources:
requests:
cpu: 200m
memory: 256Mi
service:
type: LoadBalancer
hpaSpec:
maxReplicas: 5
minReplicas: 2
values:
global:
proxy:
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
cpu: 500m
memory: 256Mi
pilot:
traceSampling: 100.0
# Install:
istioctl install -f istio-config.yaml -y
# Verify:
kubectl -n istio-system get pods
# NAME READY STATUS
# istiod-xxx 1/1 Running
# istiod-xxx 1/1 Running (HA replica)
# istio-ingressgateway-xxx 1/1 Running
# istio-ingressgateway-xxx 1/1 Running
# Enable sidecar injection cho namespaces:
kubectl label namespace default istio-injection=enabled
kubectl label namespace messaging istio-injection=enabled
# Verify injection:
kubectl get namespace -L istio-injection
# default Active istio-injection=enabled
# messaging Active istio-injection=enabled
PART 4: mTLS (MUTUAL TLS)
# Strict mTLS cho toàn mesh:
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
name: default
namespace: istio-system # Mesh-wide
spec:
mtls:
mode: STRICT # All traffic must be mTLS
---
# Exclude specific namespace (legacy apps):
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
name: legacy-permissive
namespace: legacy
spec:
mtls:
mode: PERMISSIVE # Accept both plain + mTLS
# Verify mTLS:
istioctl x describe pod order-service-xxx.default
# Service: order-service.default
# mTLS: STRICT
# Certificates:
# Certificate chain: valid
# Server certificate: valid
# Check certificate:
istioctl proxy-config secret order-service-xxx.default
# RESOURCE NAME TYPE STATUS VALID CERT SERIAL NUMBER
# default Cert ACTIVE true xxx
# ROOTCA CA ACTIVE true xxx
PART 5: SIDECAR INJECTION
# Automatic injection (namespace label):
kubectl label namespace default istio-injection=enabled
# Manual injection (specific deployment):
kubectl apply -f <(istioctl kube-inject -f deployment.yaml)
# Verify sidecar:
kubectl get pods -n default
# order-service-xxx 2/2 Running ← 2 containers = app + envoy
# Check Envoy config:
istioctl proxy-config clusters order-service-xxx.default
istioctl proxy-config routes order-service-xxx.default
istioctl proxy-config listeners order-service-xxx.default
# Envoy dashboard:
istioctl dashboard envoy order-service-xxx.default
PART 6: OBSERVABILITY ADD-ONS
# Install Kiali (service mesh dashboard):
kubectl apply -f https://raw.githubusercontent.com/istio/istio/release-1.22/samples/addons/kiali.yaml
# Install Jaeger (distributed tracing):
kubectl apply -f https://raw.githubusercontent.com/istio/istio/release-1.22/samples/addons/jaeger.yaml
# Access:
istioctl dashboard kiali
istioctl dashboard jaeger
# Kiali shows:
# - Service topology graph (real-time)
# - Traffic flow between services
# - Error rates, latency
# - mTLS status
# - Istio configuration validation
💡 KEY TAKEAWAYS
- Service Mesh: Infrastructure layer for service-to-service communication
- Istio: Most feature-rich mesh, Envoy sidecar proxy
- istiod: Single control plane binary (Pilot + Citadel + Galley)
- mTLS STRICT: Zero-trust, all traffic encrypted automatically
- Sidecar injection: Label namespace, auto-inject Envoy
- Kiali: Visual service topology, essential for understanding mesh
🎯 EXERCISE
Exercise 1: Install Istio__HTMLTAG_306___
- Install Istio with production profile
- Enable sidecar injection on default namespace__HTMLTAG_311___
- Deploy sample Bookinfo app
- Verify mTLS between services
Exercise 2: Kiali & Jaeger
- Install Kiali, explore service graph
- Generate traffic, view traces in Jaeger__HTMLTAG_323___
- Identify slowest service in request chain
📚 NEXT POST
In Lesson 25: Istio Traffic Management — VirtualService, DestinationRule, we will configure traffic routing, canary deployment, and circuit breaking.