The sidecar — one proxy per pod
A sidecar is a second container next to your app that intercepts all of its network traffic; the fleet of those sidecars, sharing one policy, is a service mesh.
Taking the network out of fifty apps' hands means putting a single, identical piece of code next to each app and routing every request through it.
Scene 02
The sidecar — one proxy per pod
- Watch
- Try it
- Predict
- Capture
Watch one request travel through two pods. It leaves App A, drops into Sidecar A on localhost, crosses the network to Sidecar B (mTLS), then surfaces in App B. The sidecars — not the apps — own the policy on that hop.
Highlighted lines are the ones running in the diagram right now.
def handle_request():# App still calls a hostname.# It does not know there's a sidecar.response = http.get('checkout-svc/cart')return render(response)
# Installed by the istio-init container at pod start.iptables -t nat -N ISTIO_OUTPUTiptables -t nat -A OUTPUT -p tcp -j ISTIO_OUTPUT# Skip traffic the sidecar itself originates (uid 1337).iptables -t nat -A ISTIO_OUTPUT -m owner \--uid-owner 1337 -j RETURN# Everything else from the app: redirect to Envoy on 15001.iptables -t nat -A ISTIO_OUTPUT -p tcp \-j REDIRECT --to-ports 15001
def serve_outbound():conn = accept(':15001') # from iptables REDIRECTreq = http.parse(conn)route = routes.match(req) # listener -> routefor attempt in range(route.retry_budget):upstream = mtls.dial(route.cluster, deadline=route.timeout)resp = upstream.send(req)if not retryable(resp): breakhttp.write(conn, resp)
def serve_inbound():conn = accept(':15006') # inbound REDIRECT targetpeer = mtls.terminate(conn) # verify Sidecar A's certreq = http.parse(conn)upstream = dial('127.0.0.1:app_port')resp = upstream.send(req)http.write(conn, resp)
Where this sits in Build a Service Mesh (Envoy / Istio style)
Scene 02 of 13. Put a small proxy next to every service. App talks to localhost; cross-service traffic flows sidecar to sidecar. The fleet of sidecars is the service mesh.
Up next. The sidecar can rewrite policy because it actually opens the request and reads it — but that requires the proxy to speak the language of the request, not just shuffle bytes.
All 13 scenes in Build a Service Mesh (Envoy / Istio style) · Every curriculum