Chuyển đến nội dung chính

BÀI 24: KIẾN TRÚC ISTIO SERVICE MESH

Hiểu kiến trúc Istio service mesh: data plane (Envoy sidecar), control plane (istiod), traffic management, security (mTLS), observability, và so sánh với Linkerd.

🔒 DevSecOps — Bài 24 BÀI 24: KIẾN TRÚC ISTIO SERVICE MESH

Deploy Microservices On-Premises với Kubernetes HA

Phần 6: Service Mesh & Ingress với Istio

xdev.asia

🎯 MỤC TIÊU BÀI HỌC

  • ✅ Hiểu service mesh là gì và tại sao cần
  • ✅ Kiến trúc Istio: Control Plane + Data Plane
  • ✅ Envoy sidecar proxy — cách thức hoạt động
  • ✅ Core features: traffic management, security, observability
  • ✅ So sánh Istio vs Linkerd vs Cilium Service Mesh
  • ✅ Install Istio trên K8s cluster

PHẦN 1: SERVICE MESH LÀ GÌ?


graph LR
    subgraph WITHOUT["❌ WITHOUT Service Mesh"]
        A1["Service A
Retry? Timeout?"] -->|"Direct call
no encryption
no retry
no tracing"| B1["Service B
No auth? No limit?"] end subgraph WITH["✅ WITH Service Mesh — Istio"] A2["Service A
business logic"] --> EA["🔷 Envoy Sidecar
• Retry
• Timeout
• Tracing"] EA -->|"mTLS auto"| EB["🔷 Envoy Sidecar
• Auth
• RateLimit
• Metrics"] EB --> B2["Service B
business logic"] CP["istiod
Control Plane"] -.->|"Config push"| EA & EB end style WITHOUT fill:#450a0a,stroke:#dc2626,color:#fca5a5 style WITH fill:#052e16,stroke:#22c55e,color:#bbf7d0 style EA fill:#1d4ed8,stroke:#60a5fa,color:#fff style EB fill:#1d4ed8,stroke:#60a5fa,color:#fff style CP fill:#7c3aed,stroke:#a78bfa,color:#fff

1.1. Khi nào cần Service Mesh?

  • ✅ > 10 microservices communicating
  • ✅ Cần mTLS (zero-trust network)
  • ✅ Complex traffic routing (canary, A/B)
  • ✅ Distributed tracing & observability
  • ✅ Rate limiting, circuit breaking consistent
  • ❌ Overhead không cần cho monolith hoặc < 5 services

PHẦN 2: KIẾN TRÚC ISTIO


graph TB
    subgraph CONTROL["🧠 CONTROL PLANE"]
        subgraph ISTIOD["istiod — Unified Binary"]
            Pilot["Pilot
Traffic config"] Citadel["Citadel
mTLS certs"] Galley["Galley
Config validation"] end end subgraph DATA["📡 DATA PLANE"] subgraph PodA["Pod A"] AppA["App A"] EnvA["🔷 Envoy Sidecar"] AppA --> EnvA end subgraph PodB["Pod B"] AppB["App B"] EnvB["🔷 Envoy Sidecar"] AppB --> EnvB end subgraph PodC["Pod C"] AppC["App C"] EnvC["🔷 Envoy Sidecar"] AppC --> EnvC end end ISTIOD -->|"xDS API
push config"| EnvA & EnvB & EnvC EnvA <-->|"mTLS"| EnvB EnvB <-->|"mTLS"| EnvC EnvA <-->|"mTLS"| EnvC style CONTROL fill:#4c1d95,stroke:#8b5cf6,color:#e2e8f0 style ISTIOD fill:#5b21b6,stroke:#a78bfa,color:#fff style EnvA fill:#1d4ed8,stroke:#60a5fa,color:#fff style EnvB fill:#1d4ed8,stroke:#60a5fa,color:#fff style EnvC fill:#1d4ed8,stroke:#60a5fa,color:#fff
ComponentRoleDetails
istiodControl PlaneSingle binary: Pilot + Citadel + Galley
EnvoySidecar ProxyL4/L7 proxy, injected into every pod
PilotTraffic ManagementConverts routing rules → Envoy xDS config
CitadelSecurityCertificate authority, mTLS cert rotation
GalleyConfigurationValidates & distributes Istio config
FeatureIstioLinkerdCilium SM
ProxyEnvoy (C++)linkerd2-proxy (Rust)eBPF (kernel)
Resource UsageMedium-HighLowLowest
FeaturesMost completeEssential featuresGrowing
Learning CurveSteepModerateLow-Moderate
mTLSYes (auto)Yes (auto)Yes (WireGuard)
Traffic MgmtAdvancedBasicBasic
Multi-clusterYesYesYes
WASM ExtensionsYesNoNo

PHẦN 3: CÀI ĐẶT ISTIO

3.1. Install istioctl

# Download istioctl:
curl -L https://istio.io/downloadIstio | ISTIO_VERSION=1.22.0 sh -
cd istio-1.22.0
export PATH=$PWD/bin:$PATH

Verify:

istioctl version

client version: 1.22.0

3.2. Install Istio (Production Profile)

# istio-config.yaml:
apiVersion: install.istio.io/v1alpha1
kind: IstioOperator
metadata:
  name: production-istio
spec:
  profile: default

meshConfig: accessLogFile: /dev/stdout accessLogEncoding: JSON enableTracing: true defaultConfig: tracing: sampling: 100.0 holdApplicationUntilProxyStarts: true

# Outbound traffic policy:
outboundTrafficPolicy:
  mode: REGISTRY_ONLY    # Only allow registered services

# Enable strict mTLS:
# (configured via PeerAuthentication below)

components: pilot: k8s: resources: requests: cpu: 500m memory: 512Mi limits: cpu: "2" memory: 2Gi replicas: 2 # HA istiod hpaSpec: maxReplicas: 3 minReplicas: 2

ingressGateways:
  - name: istio-ingressgateway
    enabled: true
    k8s:
      resources:
        requests:
          cpu: 200m
          memory: 256Mi
      service:
        type: LoadBalancer
      hpaSpec:
        maxReplicas: 5
        minReplicas: 2

values: global: proxy: resources: requests: cpu: 50m memory: 64Mi limits: cpu: 500m memory: 256Mi pilot: traceSampling: 100.0

# Install:
istioctl install -f istio-config.yaml -y

# Verify:
kubectl -n istio-system get pods
# NAME                                    READY   STATUS
# istiod-xxx                              1/1     Running
# istiod-xxx                              1/1     Running  (HA replica)
# istio-ingressgateway-xxx                1/1     Running
# istio-ingressgateway-xxx                1/1     Running

# Enable sidecar injection cho namespaces:
kubectl label namespace default istio-injection=enabled
kubectl label namespace messaging istio-injection=enabled

# Verify injection:
kubectl get namespace -L istio-injection
# default     Active   istio-injection=enabled
# messaging   Active   istio-injection=enabled

PHẦN 4: mTLS (MUTUAL TLS)

# Strict mTLS cho toàn mesh:
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
  name: default
  namespace: istio-system    # Mesh-wide
spec:
  mtls:
    mode: STRICT             # All traffic must be mTLS
---
# Exclude specific namespace (legacy apps):
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
  name: legacy-permissive
  namespace: legacy
spec:
  mtls:
    mode: PERMISSIVE         # Accept both plain + mTLS
# Verify mTLS:
istioctl x describe pod order-service-xxx.default
# Service: order-service.default
# mTLS: STRICT
# Certificates:
#   Certificate chain: valid
#   Server certificate: valid

# Check certificate:
istioctl proxy-config secret order-service-xxx.default
# RESOURCE NAME     TYPE     STATUS   VALID CERT   SERIAL NUMBER
# default           Cert     ACTIVE   true         xxx
# ROOTCA            CA       ACTIVE   true         xxx

PHẦN 5: SIDECAR INJECTION

# Automatic injection (namespace label):
kubectl label namespace default istio-injection=enabled

# Manual injection (specific deployment):
kubectl apply -f <(istioctl kube-inject -f deployment.yaml)

# Verify sidecar:
kubectl get pods -n default
# order-service-xxx   2/2   Running   ← 2 containers = app + envoy

# Check Envoy config:
istioctl proxy-config clusters order-service-xxx.default
istioctl proxy-config routes order-service-xxx.default
istioctl proxy-config listeners order-service-xxx.default

# Envoy dashboard:
istioctl dashboard envoy order-service-xxx.default

PHẦN 6: OBSERVABILITY ADD-ONS

# Install Kiali (service mesh dashboard):
kubectl apply -f https://raw.githubusercontent.com/istio/istio/release-1.22/samples/addons/kiali.yaml

# Install Jaeger (distributed tracing):
kubectl apply -f https://raw.githubusercontent.com/istio/istio/release-1.22/samples/addons/jaeger.yaml

# Access:
istioctl dashboard kiali
istioctl dashboard jaeger

# Kiali shows:
# - Service topology graph (real-time)
# - Traffic flow between services
# - Error rates, latency
# - mTLS status
# - Istio configuration validation

💡 KEY TAKEAWAYS

  1. Service Mesh: Infrastructure layer for service-to-service communication
  2. Istio: Most feature-rich mesh, Envoy sidecar proxy
  3. istiod: Single control plane binary (Pilot + Citadel + Galley)
  4. mTLS STRICT: Zero-trust, all traffic encrypted automatically
  5. Sidecar injection: Label namespace, auto-inject Envoy
  6. Kiali: Visual service topology, essential for understanding mesh

🎯 BÀI TẬP

Bài tập 1: Install Istio

  • Install Istio with production profile
  • Enable sidecar injection on default namespace
  • Deploy sample Bookinfo app
  • Verify mTLS between services

Bài tập 2: Kiali & Jaeger

  • Install Kiali, explore service graph
  • Generate traffic, view traces in Jaeger
  • Identify slowest service in request chain

📚 BÀI TIẾP THEO

Trong Bài 25: Istio Traffic Management — VirtualService, DestinationRule, chúng ta sẽ cấu hình traffic routing, canary deployment, và circuit breaking.