Service Mesh Platform · View 19 of 31 · 5 · Runtime
Decisions
- The east-west gateway routes on SNI and passes TLS through untouched. It holds no workload identity, so the destination authorises the original caller and nobody else.
- Spillover starts when fewer than 70% of local endpoints are healthy. The threshold is declared per destination, not left to a default, because it is a cost decision as much as a latency one.
- Remote endpoints come only from services the owning cluster has exported. A cluster's whole service list is never merged into another's discovery.
Targets
- Loss of one cluster needs no configuration change anywhere else. Survivors degrade to their own capacity and outlier detection removes the lost cluster's endpoints.
Cost signal
- Every spilled request is counted by source and destination locality. Cross-cluster bytes appear in the monthly cost report next to the team that caused them.