4 ms·
Istio adds to Kubernetes: - Automatic load balancing for HTTP, gRPC, WebSockets, and TCP traffic. - Fine-grained control of traffic behaviour with rich routin
by olafmol 8y ago
Istio adds to Kubernetes:
- Automatic load balancing for HTTP, gRPC, WebSockets, and TCP traffic.
- Fine-grained control of traffic behaviour with rich routing rules, retries, fail-overs, and fault injection.
- A pluggable policy layer and configuration API supporting access controls, rate limits and quotas.
- Automatic metrics, logs, and traces for all traffic within a cluster, including cluster ingress and egress.
- Secure service-to-service communication in a cluster with strong identity-based authentication and authorization.
Istio on its own is powerful and flexible. It can also be hard to understand, setup, and manage, plus can be brittle.
(disclaimer: I'm co-founder of Vamp.io, a canary test & release system for DevOps teams that works with both HAProxy and Istio)
What Istio imho misses is a user-friendly way of setting up, managing and automating Istio configurations for microservices topologies to quickly achieve automated canary-releasing and A/B testing pipelines. Call Vamp a canary-releasing and A/B testing “control plane” for Istio/K8s if you will.
Basically the potential of service-meshes like Istio lies in "driving" it from higher-level metric/KPI-based automation systems.
We wrote several blog-posts on how to make use of Istio, starting here: https://medium.com/vamp-io/taming-istio-76fab339f685 https://medium.com/vamp-io/taming-istio-76fab339f685 (more blogs on Istio can be found here https://medium.com/vamp-io/tagged/istio https://medium.com/vamp-io/tagged/istio)
Hopefully this gives some more insights in what Istio is, what it isn't, and how you can leverage it in your pipelines and architectures.
- chrisweekly 8y agoThank you. Your comment is exemplary, just super-helpful.