3 ms·
The promise of ISTIO is great, but the complexity it adds are not worth it IMHO. If you want to run the BookInfo demo app, ISTIO will work great for you. If y
by coleca 8y ago
The promise of ISTIO is great, but the complexity it adds are not worth it IMHO. If you want to run the BookInfo demo app, ISTIO will work great for you. If you want to run anything else, buckle up. I'm sure there are people running ISTIO successfully, but there is little information out there about how they do it, at least not with gRPC.
We fell for the hype and tried running ISTIO for a production workload and spent months trying to get it working with little success. Our use case was to load balance gRPC traffic amongst a small number of services on K8S. Regardless of which load balancing algorithm we used or the amount of traffic that was pushed at it we could not get ISTIO to actually spread the traffic in any sort of reasonable pattern. For example, if we had 8 containers running 4 would get a ton of traffic, 2 would get a small amount, and 2 would just have heartbeats.
We tried to get help, but the RocketChat channel was a ghost town and got little response on the Google group. Lots of people asking questions but no one answering. Some friends at Google told us there's an invite-only Slack channel, but we could never figure out what secret incantation we would need to do to get access there. Evidently only people at Google, IBM and Lyft are allowed into that one.
I'll contrast this to the LinkerD2 (linkerd.io) project. We ripped out ISTIO and installed LinkerD2 and it just worked. We didn't have to spend days hand writing YAML files to configure our VirtualServices, DestinationRules, Gateways, and ServiceEntries. One command and the whole thing was installed and running. We injected the sidecar with their cool CLI utility and boom we had a service mesh that actually load balanced gRPC properly. The LinkerD2 dashboard is a very powerful tool to visualize how your traffic is being routed, response times, success rates, etc. When we had questions, we could pop into the LinkerD2 Slack and someone from the team got right back to us with suggestions and sincere offers to help. The CEO of Buoyant even reached out personally to us, a fledgling Miami startup.
We also had issues where ISTIO would route requests to the wrong micro-service at random. We would run the same request multiple times and get different results every time. After moving to LinkerD2, those issues completely disappeared.
LinkerD2 is still a very new project, but as far as we have experienced, it is far more production ready than ISTIO. I can only imagine how far along LinkerD2 would be if it was given a tenth of the resources that are pushing ISTIO.
Our experience was back in the Fall of last year, but we tried ISTIO again last week and had the exact same results on a new installation. Once again, we had to pull ISTIO out and put LinkerD in and were able to get the system functioning immediately.
ISTIO did do a great job of load balancing HTTP/HTTPS traffic, it's just gRPC that is a long way off from being ready for prime time. Maybe if you have an army of consultants at your disposal it will work for you, but as a startup I'd stay away.