Service Mesh Networking
Sidecar proxies supplying mTLS, retries and traffic policy.
4 to work through
-
intermediate
A multi-product SaaS company with about forty services in three languages is evaluating a service mesh. Is it justified, and what would you check first?
2 min answer -
advanced
A platform team proposes adopting a service mesh for 40 services. Make the case for and against, then decide.
2 min answer -
advanced
A service mesh is introduced. p99 latency rises 15% and error rates fall by half. How do you decide whether that is a good trade?
3 min answer -
advanced
A team adopts a service mesh and sees a 10 ms latency tax on every hop across deep call chains. When is the mesh worth it, and what are the alternatives?
3 min answer
3 terms in this topic
Data Plane Proxy
The per-workload proxy that actually carries mesh traffic, applying mTLS, retries, timeouts, routing and telemetry outside the application.
conceptService Mesh Networking
What a mesh actually does at the network level, the cost per hop, and the shift from sidecar to shared-proxy models.
patternTraffic Splitting
Directing a defined percentage or subset of requests to a different version of a service, configured at the routing layer rather than in application code.
Neighbouring topics
Networking
General material on the network path underneath an architecture.
TCP/IP
Handshakes, congestion control, head-of-line blocking and connection reuse.
HTTP/1.1, HTTP/2 & HTTP/3
Multiplexing, prioritisation and the transport each is built on.
DNS
Resolution, TTL behaviour, traffic steering and failover latency.
TLS & Certificates
Encryption, integrity, authentication, termination points and expiry.
Layer 4 vs Layer 7
Connection-level versus request-level balancing, and what each unlocks.
Reverse Proxies
One place for TLS, routing, caching, compression and rate limiting.
Content Delivery Networks
Edge caching, origin offload, spike absorption and dynamic content.
Firewalls & Security Groups
Default-deny, stateful rules, and restricting egress as well as ingress.
NAT & Egress
Outbound-only connectivity, its per-gigabyte cost and its zone binding.
VPC Design
Address planning, peering and the ranges you can never resize.
Subnetting
Tiering, zone binding, and sizing for an address-hungry platform.
Routing & BGP
How traffic finds you, anycast, and route withdrawal as a failure mode.
WebSockets & Realtime
Persistent bidirectional connections and the capacity model they impose.
gRPC Transport
HTTP/2 multiplexing, binary encoding and streaming semantics.
API Gateways
The single entry point, and the business logic that must stay out of it.
Network Performance
Latency floors, bandwidth-delay product, and what no code change fixes.
Private Connectivity
Private endpoints, peering and dedicated links to managed services.
Network Troubleshooting
Flow logs, packet paths, and localising a problem to a hop.