🎯 Mục tiêu bài học
Hiểu tại sao cần Service Mesh, so sánh 3 implementations phổ biến năm 2026 (Cilium Sidecarless, Istio Ambient, Linkerd), và biết khi nào chọn gì cho use case cụ thể.
1. Tại sao cần Service Mesh?
Microservices tạo ra nhiều thách thức:
- mTLS: mã hóa traffic giữa services, xác thực identity
- Traffic management: canary, circuit breaking, retry, timeout
- Observability: distributed tracing, metrics per service-to-service
- Load balancing: L7 load balancing thông minh hơn kube-proxy
Service Mesh implement những tính năng này ở infrastructure level — application code không cần thay đổi.
2. Sidecar vs Sidecarless Architecture
Service Mesh truyền thống (Istio sidecar mode) inject Envoy proxy vào mỗi Pod:
Pod: [app container] + [Envoy sidecar proxy]
# Tất cả traffic đi qua Envoy → overhead về latency và resource
# Overhead: ~50MB memory/pod + ~2ms latency thêm
Sidecarless approach (Cilium, Istio Ambient): proxy nằm ngoài Pod, ở node level hoặc kernel level.
3. Cilium Service Mesh — Sidecarless eBPF
Cilium implement Service Mesh ở kernel level với eBPF — không cần sidecar proxy trong Pod.
Ưu điểm:
- 40-60% giảm network overhead so với Istio sidecar
- Latency thấp nhất (kernel-space processing)
- Không cần inject sidecar → đơn giản hơn, upgrade dễ hơn
- Tích hợp native với Cilium CNI (một stack cho networking + policy + mesh)
- Hubble: L7 observability được tích hợp
Nhược điểm:
- Tính năng ít hơn Istio full (không có fault injection, advanced traffic management)
- Yêu cầu Cilium làm CNI
# Enable Cilium Service Mesh helm upgrade cilium cilium/cilium \ --namespace kube-system \ --reuse-values \ --set ingressController.enabled=true \ --set ingressController.loadbalancerMode=sharedmTLS: enable mutual authentication
kubectl annotate namespace production
"service.cilium.io/global=true"Verify mTLS với Hubble
hubble observe --namespace production --protocol tcp --verdict FORWARDED
4. Istio Ambient Mode — Stable Istio 1.24+
Istio Ambient Mode (stable từ Istio 1.24+) là alternative không dùng sidecar.
Architecture:
- ztunnel: per-node L4 proxy, xử lý mTLS và basic routing cho tất cả workloads
- Waypoint proxy: per-workload L7 proxy, optional — chỉ deploy khi cần L7 features
Node:
├── ztunnel (L4: mTLS, basic routing) ← tất cả workloads đi qua
│
Namespace "production":
├── app-a pod → cần mTLS? → ztunnel handles it
├── app-b pod → cần canary L7? → ztunnel + waypoint proxy
└── waypoint proxy → L7: HTTP routing, header manipulation, metrics
# Cài Istio Ambient istioctl install --set profile=ambientEnable ambient cho namespace
kubectl label namespace production istio.io/dataplane-mode=ambient
Deploy waypoint cho L7 features
istioctl waypoint apply --namespace production --enroll-namespace
Verify
istioctl experimental waypoint status -n production
Ưu điểm Istio Ambient: Giảm ~40% resource so với sidecar mode. Đầy đủ Istio features khi cần (waypoint). Tương thích với ecosystem Istio.
5. Linkerd — Rust Micro-proxy
Linkerd dùng linkerd2-proxy viết bằng Rust — nhỏ nhất, nhanh nhất trong số các service mesh có sidecar.
- Sidecar nhưng cực nhẹ: ~10MB memory/proxy (so với Envoy ~50MB)
- Rust: memory-safe, zero-cost abstractions, ultra-fast
- Automatic mTLS không cần cấu hình
- HTTP/1.1, HTTP/2, gRPC support
- Retries và timeouts đơn giản
- Service profiles: per-route metrics và retries
# Cài Linkerd curl --proto '=https' --tlsv1.2 -sSfL https://run.linkerd.io/install | sh linkerd install --crds | kubectl apply -f - linkerd install | kubectl apply -f -Inject sidecar
kubectl annotate namespace production linkerd.io/inject=enabled
Verify
linkerd check linkerd viz install | kubectl apply -f - linkerd viz dashboard # mở browser
Linkerd vs Cilium vs Istio: Linkerd phù hợp khi bạn muốn sidecar model nhưng nhẹ nhất, đơn giản nhất.
6. So sánh Service Mesh 2026
Feature Cilium Mesh Istio Ambient Linkerd
───────────────────────────────────────────────────────────────
Architecture Sidecarless Sidecarless* Sidecar (Rust)
Memory overhead/pod ~0 ~0** ~10MB
mTLS ✅ ✅ ✅
L7 traffic mgmt Limited ✅ (waypoint) Limited
Circuit breaking ❌ ✅ ❌
Fault injection ❌ ✅ ❌
Observability ✅ (Hubble) ✅ ✅
Gateway API ✅ Native ✅ ✅
Multi-cluster Limited ✅ ✅ (linkerd-multicluster)
Complexity Low Medium Low
CNCF status Graduated Graduated Graduated
Best for Cilium clusters, Enterprise, Lightweight,
new clusters full feature set resource-constrained
Ambient không inject sidecar vào application pods ** ztunnel là shared per-node, không per-pod
7. Traffic Management với Istio
# VirtualService: canary deployment
apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
name: my-app
namespace: production
spec:
hosts:
- my-app
http:
- match:
- headers:
x-canary:
exact: "true"
route:
- destination:
host: my-app
subset: canary
- route:
- destination:
host: my-app
subset: stable
weight: 90
- destination:
host: my-app
subset: canary
weight: 10
---
# DestinationRule: define subsets
apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
name: my-app
spec:
host: my-app
trafficPolicy:
connectionPool:
http:
http2MaxRequests: 1000
outlierDetection:
consecutive5xxErrors: 5 # circuit breaking
interval: 30s
baseEjectionTime: 30s
subsets:
- name: stable
labels:
version: stable
- name: canary
labels:
version: canary
8. Khi nào chọn gì?
- Cilium Service Mesh: đã dùng Cilium CNI, muốn sidecarless, performance ưu tiên, mTLS và basic traffic management là đủ
- Istio Ambient Mode: enterprise, cần full Istio features (circuit breaking, fault injection, advanced traffic), đã có Istio expertise
- Linkerd: muốn sidecar model nhưng nhẹ nhất, đơn giản nhất, resource-constrained clusters
- Không dùng Service Mesh: cluster nhỏ, ít services, NetworkPolicy đã đủ isolation
Tóm tắt
- Service Mesh: mTLS, traffic management, observability ở infrastructure level
- Cilium Sidecarless: eBPF kernel-level, overhead thấp nhất, phù hợp clusters đã dùng Cilium
- Istio Ambient: L4 ztunnel + optional L7 waypoint, đầy đủ tính năng nhất
- Linkerd: Rust micro-proxy, nhẹ nhất trong sidecar model
- Trend 2026: sidecarless là hướng đi, nhưng Istio sidecar vẫn được dùng trong enterprise