🎯 MỤC TIÊU BÀI HỌC
- ✅ Hiểu service mesh là gì và tại sao cần
- ✅ Kiến trúc Istio: Control Plane + Data Plane
- ✅ Envoy sidecar proxy — cách thức hoạt động
- ✅ Core features: traffic management, security, observability
- ✅ So sánh Istio vs Linkerd vs Cilium Service Mesh
- ✅ Install Istio trên K8s cluster
PHẦN 1: SERVICE MESH LÀ GÌ?
graph LR
subgraph WITHOUT["❌ WITHOUT Service Mesh"]
A1["Service A
Retry? Timeout?"] -->|"Direct call
no encryption
no retry
no tracing"| B1["Service B
No auth? No limit?"]
end
subgraph WITH["✅ WITH Service Mesh — Istio"]
A2["Service A
business logic"] --> EA["🔷 Envoy Sidecar
• Retry
• Timeout
• Tracing"]
EA -->|"mTLS auto"| EB["🔷 Envoy Sidecar
• Auth
• RateLimit
• Metrics"]
EB --> B2["Service B
business logic"]
CP["istiod
Control Plane"] -.->|"Config push"| EA & EB
end
style WITHOUT fill:#450a0a,stroke:#dc2626,color:#fca5a5
style WITH fill:#052e16,stroke:#22c55e,color:#bbf7d0
style EA fill:#1d4ed8,stroke:#60a5fa,color:#fff
style EB fill:#1d4ed8,stroke:#60a5fa,color:#fff
style CP fill:#7c3aed,stroke:#a78bfa,color:#fff
1.1. Khi nào cần Service Mesh?
- ✅ > 10 microservices communicating
- ✅ Cần mTLS (zero-trust network)
- ✅ Complex traffic routing (canary, A/B)
- ✅ Distributed tracing & observability
- ✅ Rate limiting, circuit breaking consistent
- ❌ Overhead không cần cho monolith hoặc < 5 services
PHẦN 2: KIẾN TRÚC ISTIO
graph TB
subgraph CONTROL["🧠 CONTROL PLANE"]
subgraph ISTIOD["istiod — Unified Binary"]
Pilot["Pilot
Traffic config"]
Citadel["Citadel
mTLS certs"]
Galley["Galley
Config validation"]
end
end
subgraph DATA["📡 DATA PLANE"]
subgraph PodA["Pod A"]
AppA["App A"]
EnvA["🔷 Envoy Sidecar"]
AppA --> EnvA
end
subgraph PodB["Pod B"]
AppB["App B"]
EnvB["🔷 Envoy Sidecar"]
AppB --> EnvB
end
subgraph PodC["Pod C"]
AppC["App C"]
EnvC["🔷 Envoy Sidecar"]
AppC --> EnvC
end
end
ISTIOD -->|"xDS API
push config"| EnvA & EnvB & EnvC
EnvA <-->|"mTLS"| EnvB
EnvB <-->|"mTLS"| EnvC
EnvA <-->|"mTLS"| EnvC
style CONTROL fill:#4c1d95,stroke:#8b5cf6,color:#e2e8f0
style ISTIOD fill:#5b21b6,stroke:#a78bfa,color:#fff
style EnvA fill:#1d4ed8,stroke:#60a5fa,color:#fff
style EnvB fill:#1d4ed8,stroke:#60a5fa,color:#fff
style EnvC fill:#1d4ed8,stroke:#60a5fa,color:#fff
| Component | Role | Details |
|---|---|---|
| istiod | Control Plane | Single binary: Pilot + Citadel + Galley |
| Envoy | Sidecar Proxy | L4/L7 proxy, injected into every pod |
| Pilot | Traffic Management | Converts routing rules → Envoy xDS config |
| Citadel | Security | Certificate authority, mTLS cert rotation |
| Galley | Configuration | Validates & distributes Istio config |
| Feature | Istio | Linkerd | Cilium SM |
|---|---|---|---|
| Proxy | Envoy (C++) | linkerd2-proxy (Rust) | eBPF (kernel) |
| Resource Usage | Medium-High | Low | Lowest |
| Features | Most complete | Essential features | Growing |
| Learning Curve | Steep | Moderate | Low-Moderate |
| mTLS | Yes (auto) | Yes (auto) | Yes (WireGuard) |
| Traffic Mgmt | Advanced | Basic | Basic |
| Multi-cluster | Yes | Yes | Yes |
| WASM Extensions | Yes | No | No |
PHẦN 3: CÀI ĐẶT ISTIO
3.1. Install istioctl
# Download istioctl: curl -L https://istio.io/downloadIstio | ISTIO_VERSION=1.22.0 sh - cd istio-1.22.0 export PATH=$PWD/bin:$PATHVerify:
istioctl version
client version: 1.22.0
3.2. Install Istio (Production Profile)
# istio-config.yaml: apiVersion: install.istio.io/v1alpha1 kind: IstioOperator metadata: name: production-istio spec: profile: defaultmeshConfig: accessLogFile: /dev/stdout accessLogEncoding: JSON enableTracing: true defaultConfig: tracing: sampling: 100.0 holdApplicationUntilProxyStarts: true
# Outbound traffic policy: outboundTrafficPolicy: mode: REGISTRY_ONLY # Only allow registered services # Enable strict mTLS: # (configured via PeerAuthentication below)components: pilot: k8s: resources: requests: cpu: 500m memory: 512Mi limits: cpu: "2" memory: 2Gi replicas: 2 # HA istiod hpaSpec: maxReplicas: 3 minReplicas: 2
ingressGateways: - name: istio-ingressgateway enabled: true k8s: resources: requests: cpu: 200m memory: 256Mi service: type: LoadBalancer hpaSpec: maxReplicas: 5 minReplicas: 2
values: global: proxy: resources: requests: cpu: 50m memory: 64Mi limits: cpu: 500m memory: 256Mi pilot: traceSampling: 100.0
# Install:
istioctl install -f istio-config.yaml -y
# Verify:
kubectl -n istio-system get pods
# NAME READY STATUS
# istiod-xxx 1/1 Running
# istiod-xxx 1/1 Running (HA replica)
# istio-ingressgateway-xxx 1/1 Running
# istio-ingressgateway-xxx 1/1 Running
# Enable sidecar injection cho namespaces:
kubectl label namespace default istio-injection=enabled
kubectl label namespace messaging istio-injection=enabled
# Verify injection:
kubectl get namespace -L istio-injection
# default Active istio-injection=enabled
# messaging Active istio-injection=enabled
PHẦN 4: mTLS (MUTUAL TLS)
# Strict mTLS cho toàn mesh:
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
name: default
namespace: istio-system # Mesh-wide
spec:
mtls:
mode: STRICT # All traffic must be mTLS
---
# Exclude specific namespace (legacy apps):
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
name: legacy-permissive
namespace: legacy
spec:
mtls:
mode: PERMISSIVE # Accept both plain + mTLS
# Verify mTLS:
istioctl x describe pod order-service-xxx.default
# Service: order-service.default
# mTLS: STRICT
# Certificates:
# Certificate chain: valid
# Server certificate: valid
# Check certificate:
istioctl proxy-config secret order-service-xxx.default
# RESOURCE NAME TYPE STATUS VALID CERT SERIAL NUMBER
# default Cert ACTIVE true xxx
# ROOTCA CA ACTIVE true xxx
PHẦN 5: SIDECAR INJECTION
# Automatic injection (namespace label):
kubectl label namespace default istio-injection=enabled
# Manual injection (specific deployment):
kubectl apply -f <(istioctl kube-inject -f deployment.yaml)
# Verify sidecar:
kubectl get pods -n default
# order-service-xxx 2/2 Running ← 2 containers = app + envoy
# Check Envoy config:
istioctl proxy-config clusters order-service-xxx.default
istioctl proxy-config routes order-service-xxx.default
istioctl proxy-config listeners order-service-xxx.default
# Envoy dashboard:
istioctl dashboard envoy order-service-xxx.default
PHẦN 6: OBSERVABILITY ADD-ONS
# Install Kiali (service mesh dashboard):
kubectl apply -f https://raw.githubusercontent.com/istio/istio/release-1.22/samples/addons/kiali.yaml
# Install Jaeger (distributed tracing):
kubectl apply -f https://raw.githubusercontent.com/istio/istio/release-1.22/samples/addons/jaeger.yaml
# Access:
istioctl dashboard kiali
istioctl dashboard jaeger
# Kiali shows:
# - Service topology graph (real-time)
# - Traffic flow between services
# - Error rates, latency
# - mTLS status
# - Istio configuration validation
💡 KEY TAKEAWAYS
- Service Mesh: Infrastructure layer for service-to-service communication
- Istio: Most feature-rich mesh, Envoy sidecar proxy
- istiod: Single control plane binary (Pilot + Citadel + Galley)
- mTLS STRICT: Zero-trust, all traffic encrypted automatically
- Sidecar injection: Label namespace, auto-inject Envoy
- Kiali: Visual service topology, essential for understanding mesh
🎯 BÀI TẬP
Bài tập 1: Install Istio
- Install Istio with production profile
- Enable sidecar injection on default namespace
- Deploy sample Bookinfo app
- Verify mTLS between services
Bài tập 2: Kiali & Jaeger
- Install Kiali, explore service graph
- Generate traffic, view traces in Jaeger
- Identify slowest service in request chain
📚 BÀI TIẾP THEO
Trong Bài 25: Istio Traffic Management — VirtualService, DestinationRule, chúng ta sẽ cấu hình traffic routing, canary deployment, và circuit breaking.