Service mesh internals deep dive across 3 layers (istio sidecar, ambient mesh, cilium-ebpf) with 4 scenarios: Istio mTLS auto, canary 95/5 traffic shift, AuthorizationPolicy deny, sidecarless (ambient ztunnel+waypoint and Cilium eBPF kernel path).
In sidecar mode, application traffic passes through Envoy proxies while Istiod distributes configuration and identity material. In Istio ambient mode, per-node ztunnels provide L4 mesh transport and identity; an optional Envoy waypoint is the L7 policy and routing point. “Sidecarless” therefore does not mean “no proxy anywhere.”
Istio mTLS policy is explicit: permissive and strict modes have different migration and security behavior. Verify effective policy and plaintext escape paths instead of assuming installation implies strict mTLS.
xDS delivery is asynchronous. Proxies ACK accepted versions and NACK invalid resources while retaining the last valid configuration. Treat mixed versions, NACKs, stale endpoints and certificate expiry as observable states. Existing data-plane traffic may continue during a control-plane outage, but that does not make configuration or certificate changes instantaneous.
Введите числа или выберите пресет