L4 vs L7 — bytes or requests
An L4 proxy moves opaque TCP bytes; an L7 proxy parses HTTP and can see path, method, and headers — and only L7 can implement route-based policy.
A sidecar that owns 'policy' has to know what a request IS before it can apply any policy to it — that is the L4/L7 split.
Scene 03
L4 vs L7 — bytes or requests
- Watch
- Try it
- Predict
- Capture
The same request enters the same sidecar twice. First as L4: only the IP/port labels light up; the payload is a featureless byte bar. Flip the slider and the proxy's interior changes — the parsed HTTP envelope (method, path, headers) becomes visible.
Highlighted lines are the ones running in the diagram right now.
def serve():conn = accept(':8080')upstream = dial('backend:8080')# splice both directions; never look insidepipe(conn, upstream)pipe(upstream, conn)# we don't even know if it's HTTP
def serve():conn = accept(':8080')req = http.parse(conn) # method, path, headersroute = match(routes, req)upstream = dial(route.cluster)resp = upstream.send(req)http.write(conn, resp)
def match(routes, req):for r in routes:if r.path and not req.path.startswith(r.path):continueif r.header:name, want = r.headerif req.headers.get(name) != want:continuereturn r # first match winsreturn default_route
Where this sits in Build a Service Mesh (Envoy / Istio style)
Scene 03 of 13. An L4 proxy forwards opaque TCP bytes; an L7 proxy parses HTTP and can act on path, method, and headers. The mesh is L7 for everything that follows.
Up next. If the sidecar can read method and path, it needs a structured way to match on them and decide where to send the request next.
All 13 scenes in Build a Service Mesh (Envoy / Istio style) · Every curriculum