Build a Service Mesh (Envoy / Istio style)

About Build a Service Mesh (Envoy / Istio style)

Every microservice request crosses two proxies. This curriculum is what they do: routing, load balancing, timeout-and-retry-budget, circuit breakers, outlier detection, token-bucket rate limits, mTLS with workload identity, and a control plane that streams config to all of them. Build it in the order the production problems show up — and feel why Envoy plus a control plane has eaten the east-west world.

Difficulty
advanced
Time
about 90 minutes
Stages
9
Topic
Caching, Proxies & the Edge

How this problem is worked

Nine stages, from what the thing is for to how it compares with the real implementations. Each asks one question, and the simulator runs the architecture you draw against the requirements you wrote.

  1. 01Purpose & invariantsWhat is this for, and what must always be true of it?
  2. 02Workload characterizationWho writes, who reads, and in what shapes?
  3. 03Data model & on-disk formatWhat does the data look like at rest?
  4. 04Core algorithmsHow do the write path and the read path actually work?
  5. 05Distribution & replicationHow does this scale out and survive losing a machine?
  6. 06Consistency & correctnessUnder concurrency and failure, what is guaranteed?
  7. 07Failure modes & recoveryWhat actually happens when each part fails?
  8. 08Operational characteristicsCan a human run this at three in the morning?
  9. 09Trade-offs & comparisonWhere does this sit against the alternatives?

Primary sources for this problem

  • Envoy proxy docs — Architecture overview, Listeners, Clusters, Outlier detection, Circuit breaking, Rate limiting, xDS protocol (envoyproxy.io/docs/envoy/latest)
  • Istio docs — Architecture, Traffic management, Security, Observability, Ambient mesh (istio.io/latest/docs)
  • Matt Klein — Announcing Envoy (Lyft Engineering, 2016)
  • Nygard — Release It! 2e — circuit breakers and bulkheads (Pragmatic Bookshelf)
  • Marc Brooker — Timeouts, retries, backoff with jitter (AWS Builders' Library)
  • W3C Trace Context — Level 2 (w3.org/TR/trace-context/)
  • SPIFFE & SPIRE concepts (spiffe.io/docs/latest/spiffe-about/spiffe-concepts/)
  • Linkerd — Why we don't use Envoy (linkerd.io/2020/12/03/why-linkerd-doesnt-use-envoy/)
  • Cilium / eBPF Service Mesh and Istio Ambient mode for sidecar-less designs

Browse the full problem catalog, or see what the simulator does and does not model.