Service Mesh

A service mesh intercepts all network traffic between microservices and manages cross-cutting concerns — encryption, retries, circuit breaking, distributed tracing — transparently, without requiring changes to application code.

The Sidecar Pattern

Most service meshes inject a lightweight proxy (typically Envoy) as a sidecar container alongside every service Pod. All inbound and outbound traffic flows through the proxy, which enforces policies, collects telemetry, and handles connection management — invisible to the application.

What a Mesh Provides

  • mTLS — Mutual TLS between all services, automatically, with certificate rotation
  • Traffic Management — Canary deployments, A/B testing, weighted routing, fault injection
  • Observability — Distributed traces, per-service latency histograms, and request-level access logs
  • Resilience — Retries, timeouts, and circuit breakers applied at the network layer

Leading Implementations

Istio (CNCF graduated, Google origin) is the most feature-complete. Linkerd (CNCF graduated) prioritises simplicity and lower resource overhead. Consul Connect (HashiCorp) integrates tightly with the broader Consul service registry ecosystem.