L4 vs L7 — bytes or requests

An L4 proxy moves opaque TCP bytes; an L7 proxy parses HTTP and can see path, method, and headers — and only L7 can implement route-based policy.

Previously

A sidecar that owns 'policy' has to know what a request IS before it can apply any policy to it — that is the L4/L7 split.

Scene 03

L4 vs L7 — bytes or requests

  1. Watch
  2. Try it
  3. Predict
  4. Capture
L4: the proxy moves bytes; only IP/port are legible.L4 PROXY (BYTES)SRC10.0.2.14:51022DST10.0.7.31:8080Sidecar (proxy)sees: TCP bytes + IPs0x4A 7F E2 …opaque bytes — proxy cannot parseROUTING TASKL4L7forward bytesroute on /users/* path prefixroute on x-canary: true header
L4 proxy: sees IPs, not bytes' meaning →
L7 sees path + headers · L4 sees only IP/port
What to watch for

The same request enters the same sidecar twice. First as L4: only the IP/port labels light up; the payload is a featureless byte bar. Flip the slider and the proxy's interior changes — the parsed HTTP envelope (method, path, headers) becomes visible.

Continue unlocks when the animation finishes.
Implementation

Highlighted lines are the ones running in the diagram right now.

L4Proxy.serve()
transport-layer pipe — bytes pass through opaquely
def serve():
conn = accept(':8080')
upstream = dial('backend:8080')
# splice both directions; never look inside
pipe(conn, upstream)
pipe(upstream, conn)
# we don't even know if it's HTTP
L7Proxy.serve()
application-layer parse — bytes become an HTTP request
def serve():
conn = accept(':8080')
req = http.parse(conn) # method, path, headers
route = match(routes, req)
upstream = dial(route.cluster)
resp = upstream.send(req)
http.write(conn, resp)
L7Proxy.match(routes, req)
the rules that only exist once HTTP is parsed
def match(routes, req):
for r in routes:
if r.path and not req.path.startswith(r.path):
continue
if r.header:
name, want = r.header
if req.headers.get(name) != want:
continue
return r # first match wins
return default_route

Where this sits in Build a Service Mesh (Envoy / Istio style)

Scene 03 of 13. An L4 proxy forwards opaque TCP bytes; an L7 proxy parses HTTP and can act on path, method, and headers. The mesh is L7 for everything that follows.

Up next. If the sidecar can read method and path, it needs a structured way to match on them and decide where to send the request next.

All 13 scenes in Build a Service Mesh (Envoy / Istio style) · Every curriculum

Built with Arqly
Every scene in Build a Service Mesh (Envoy / Istio style) builds on the one before it.All 13 Build a Service Mesh (Envoy / Istio style) scenes