Chuyển đến nội dung chính

BÀI 35: SERVICE MESH 2026 — CILIUM, ISTIO, LINKERD

Service Mesh 2026: Cilium Service Mesh sidecarless eBPF (40-60% less overhead), Istio 1.24+ ambient mode, Linkerd Rust-based micro-proxy. mTLS, traffic management, observability. So sánh và khi nào chọn gì.

🔒 DevSecOps — Bài 35 BÀI 35: SERVICE MESH 2026 — CILIUM, ISTIO, LINKERD

KUBERNETES: TỪ CƠ BẢN ĐẾN NÂNG CAO

Module 8: Helm, Operators & GitOps

xdev.asia

🎯 Mục tiêu bài học

Hiểu tại sao cần Service Mesh, so sánh 3 implementations phổ biến năm 2026 (Cilium Sidecarless, Istio Ambient, Linkerd), và biết khi nào chọn gì cho use case cụ thể.

1. Tại sao cần Service Mesh?

Microservices tạo ra nhiều thách thức:

  • mTLS: mã hóa traffic giữa services, xác thực identity
  • Traffic management: canary, circuit breaking, retry, timeout
  • Observability: distributed tracing, metrics per service-to-service
  • Load balancing: L7 load balancing thông minh hơn kube-proxy

Service Mesh implement những tính năng này ở infrastructure level — application code không cần thay đổi.

2. Sidecar vs Sidecarless Architecture

Service Mesh truyền thống (Istio sidecar mode) inject Envoy proxy vào mỗi Pod:

Pod: [app container] + [Envoy sidecar proxy]
# Tất cả traffic đi qua Envoy → overhead về latency và resource
# Overhead: ~50MB memory/pod + ~2ms latency thêm

Sidecarless approach (Cilium, Istio Ambient): proxy nằm ngoài Pod, ở node level hoặc kernel level.

3. Cilium Service Mesh — Sidecarless eBPF

Cilium implement Service Mesh ở kernel level với eBPF — không cần sidecar proxy trong Pod.

Ưu điểm:

  • 40-60% giảm network overhead so với Istio sidecar
  • Latency thấp nhất (kernel-space processing)
  • Không cần inject sidecar → đơn giản hơn, upgrade dễ hơn
  • Tích hợp native với Cilium CNI (một stack cho networking + policy + mesh)
  • Hubble: L7 observability được tích hợp

Nhược điểm:

  • Tính năng ít hơn Istio full (không có fault injection, advanced traffic management)
  • Yêu cầu Cilium làm CNI
# Enable Cilium Service Mesh
helm upgrade cilium cilium/cilium \
  --namespace kube-system \
  --reuse-values \
  --set ingressController.enabled=true \
  --set ingressController.loadbalancerMode=shared

mTLS: enable mutual authentication

kubectl annotate namespace production
"service.cilium.io/global=true"

Verify mTLS với Hubble

hubble observe --namespace production --protocol tcp --verdict FORWARDED

4. Istio Ambient Mode — Stable Istio 1.24+

Istio Ambient Mode (stable từ Istio 1.24+) là alternative không dùng sidecar.

Architecture:

  • ztunnel: per-node L4 proxy, xử lý mTLS và basic routing cho tất cả workloads
  • Waypoint proxy: per-workload L7 proxy, optional — chỉ deploy khi cần L7 features
Node:
├── ztunnel (L4: mTLS, basic routing) ← tất cả workloads đi qua
│
Namespace "production":
├── app-a pod       → cần mTLS? → ztunnel handles it
├── app-b pod       → cần canary L7? → ztunnel + waypoint proxy
└── waypoint proxy  → L7: HTTP routing, header manipulation, metrics
# Cài Istio Ambient
istioctl install --set profile=ambient

Enable ambient cho namespace

kubectl label namespace production istio.io/dataplane-mode=ambient

Deploy waypoint cho L7 features

istioctl waypoint apply --namespace production --enroll-namespace

Verify

istioctl experimental waypoint status -n production

Ưu điểm Istio Ambient: Giảm ~40% resource so với sidecar mode. Đầy đủ Istio features khi cần (waypoint). Tương thích với ecosystem Istio.

5. Linkerd — Rust Micro-proxy

Linkerd dùng linkerd2-proxy viết bằng Rust — nhỏ nhất, nhanh nhất trong số các service mesh có sidecar.

  • Sidecar nhưng cực nhẹ: ~10MB memory/proxy (so với Envoy ~50MB)
  • Rust: memory-safe, zero-cost abstractions, ultra-fast
  • Automatic mTLS không cần cấu hình
  • HTTP/1.1, HTTP/2, gRPC support
  • Retries và timeouts đơn giản
  • Service profiles: per-route metrics và retries
# Cài Linkerd
curl --proto '=https' --tlsv1.2 -sSfL https://run.linkerd.io/install | sh
linkerd install --crds | kubectl apply -f -
linkerd install | kubectl apply -f -

Inject sidecar

kubectl annotate namespace production linkerd.io/inject=enabled

Verify

linkerd check linkerd viz install | kubectl apply -f - linkerd viz dashboard # mở browser

Linkerd vs Cilium vs Istio: Linkerd phù hợp khi bạn muốn sidecar model nhưng nhẹ nhất, đơn giản nhất.

6. So sánh Service Mesh 2026

Feature              Cilium Mesh    Istio Ambient    Linkerd
───────────────────────────────────────────────────────────────
Architecture         Sidecarless    Sidecarless*     Sidecar (Rust)
Memory overhead/pod  ~0             ~0**             ~10MB
mTLS                 ✅            ✅               ✅
L7 traffic mgmt      Limited        ✅ (waypoint)    Limited
Circuit breaking     ❌            ✅               ❌
Fault injection      ❌            ✅               ❌
Observability        ✅ (Hubble)   ✅               ✅
Gateway API          ✅ Native     ✅               ✅
Multi-cluster        Limited        ✅               ✅ (linkerd-multicluster)
Complexity           Low            Medium           Low
CNCF status          Graduated      Graduated        Graduated
Best for             Cilium clusters,  Enterprise,    Lightweight,
                     new clusters  full feature set  resource-constrained
  • Ambient không inject sidecar vào application pods ** ztunnel là shared per-node, không per-pod

7. Traffic Management với Istio

# VirtualService: canary deployment
apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
  name: my-app
  namespace: production
spec:
  hosts:
  - my-app
  http:
  - match:
    - headers:
        x-canary:
          exact: "true"
    route:
    - destination:
        host: my-app
        subset: canary
  - route:
    - destination:
        host: my-app
        subset: stable
      weight: 90
    - destination:
        host: my-app
        subset: canary
      weight: 10
---
# DestinationRule: define subsets
apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
  name: my-app
spec:
  host: my-app
  trafficPolicy:
    connectionPool:
      http:
        http2MaxRequests: 1000
    outlierDetection:
      consecutive5xxErrors: 5       # circuit breaking
      interval: 30s
      baseEjectionTime: 30s
  subsets:
  - name: stable
    labels:
      version: stable
  - name: canary
    labels:
      version: canary

8. Khi nào chọn gì?

  • Cilium Service Mesh: đã dùng Cilium CNI, muốn sidecarless, performance ưu tiên, mTLS và basic traffic management là đủ
  • Istio Ambient Mode: enterprise, cần full Istio features (circuit breaking, fault injection, advanced traffic), đã có Istio expertise
  • Linkerd: muốn sidecar model nhưng nhẹ nhất, đơn giản nhất, resource-constrained clusters
  • Không dùng Service Mesh: cluster nhỏ, ít services, NetworkPolicy đã đủ isolation

Tóm tắt

  • Service Mesh: mTLS, traffic management, observability ở infrastructure level
  • Cilium Sidecarless: eBPF kernel-level, overhead thấp nhất, phù hợp clusters đã dùng Cilium
  • Istio Ambient: L4 ztunnel + optional L7 waypoint, đầy đủ tính năng nhất
  • Linkerd: Rust micro-proxy, nhẹ nhất trong sidecar model
  • Trend 2026: sidecarless là hướng đi, nhưng Istio sidecar vẫn được dùng trong enterprise