Build a Service Mesh (Envoy / Istio style)
Every microservice request crosses two proxies. This curriculum is what they do: routing, load balancing, timeout-and-retry-budget, circuit breakers, outlier detection, token-bucket rate limits, mTLS with workload identity, and a control plane that streams config to all of them. Build it in the order the production problems show up — and feel why Envoy plus a control plane has eaten the east-west world.Enter to send · Shift+Enter for a new line
About Build a Service Mesh (Envoy / Istio style)
Every microservice request crosses two proxies. This curriculum is what they do: routing, load balancing, timeout-and-retry-budget, circuit breakers, outlier detection, token-bucket rate limits, mTLS with workload identity, and a control plane that streams config to all of them. Build it in the order the production problems show up — and feel why Envoy plus a control plane has eaten the east-west world.
- Difficulty
- advanced
- Time
- about 90 minutes
- Stages
- 9
- Topic
- Caching, Proxies & the Edge
How this problem is worked
Nine stages, from what the thing is for to how it compares with the real implementations. Each asks one question, and the simulator runs the architecture you draw against the requirements you wrote.
- 01Purpose & invariantsWhat is this for, and what must always be true of it?
- 02Workload characterizationWho writes, who reads, and in what shapes?
- 03Data model & on-disk formatWhat does the data look like at rest?
- 04Core algorithmsHow do the write path and the read path actually work?
- 05Distribution & replicationHow does this scale out and survive losing a machine?
- 06Consistency & correctnessUnder concurrency and failure, what is guaranteed?
- 07Failure modes & recoveryWhat actually happens when each part fails?
- 08Operational characteristicsCan a human run this at three in the morning?
- 09Trade-offs & comparisonWhere does this sit against the alternatives?
Primary sources for this problem
- Envoy proxy docs — Architecture overview, Listeners, Clusters, Outlier detection, Circuit breaking, Rate limiting, xDS protocol (envoyproxy.io/docs/envoy/latest)
- Istio docs — Architecture, Traffic management, Security, Observability, Ambient mesh (istio.io/latest/docs)
- Matt Klein — Announcing Envoy (Lyft Engineering, 2016)
- Nygard — Release It! 2e — circuit breakers and bulkheads (Pragmatic Bookshelf)
- Marc Brooker — Timeouts, retries, backoff with jitter (AWS Builders' Library)
- W3C Trace Context — Level 2 (w3.org/TR/trace-context/)
- SPIFFE & SPIRE concepts (spiffe.io/docs/latest/spiffe-about/spiffe-concepts/)
- Linkerd — Why we don't use Envoy (linkerd.io/2020/12/03/why-linkerd-doesnt-use-envoy/)
- Cilium / eBPF Service Mesh and Istio Ambient mode for sidecar-less designs
More in Caching, Proxies & the Edge
Everything between the client and the origin: in-memory caches, CDNs, load balancers and service proxies — and the three ways a cache betrays you.
- Cache Invalidation Across a FleetWrite-through vs write-behind. Two generals.
- Build Build RedisAn in-memory data-structure server: one thread, rich types, optional persistence, async replication. Internalize the cost of single-threaded simplicity and a dozen caching/HA decisions get easier.
- Build Build a CDNA globally-distributed reverse proxy whose only job is to (a) terminate the user's TCP/TLS milliseconds away and (b) serve a cached origin response so origin never sees the request. Internalize edge caching, anycast, TTL, revalidation, SWR, purge, the Vary footgun, origin shield, bypass, and hit ratio — and the dozen ways to misconfigure each.
- Build Build a gRPC-style RPC frameworkEvery microservice talks over RPC, and the framework you ship determines half the system's failure modes. Build an RPC framework with codec, streams, deadlines, cancellation, retries, interceptors, and load-aware client-side balancing — and feel why gRPC ate the polyglot RPC market and why Thrift and JSON-over-HTTP linger.
Browse the full problem catalog, or see what the simulator does and does not model.