mTLS — identity for both sides
TLS proves the server to the client; mTLS adds a client cert so the proxy has a cryptographic workload identity — a stable name signed by a shared CA — for whoever called it, not just an IP.
Rate limiting and routing both want to know WHO is calling — but pod IPs change every restart, so the proxy needs a stronger answer to 'who are you' than an IP.
Scene 10
mTLS — identity for both sides
- Watch
- Try it
- Predict
- Capture
The control plane mints a short-lived cert for each sidecar, carrying a workload name — prod/order on the left, prod/checkout on the right. Watch the handshake: A presents its cert, B verifies it, B presents its cert, A verifies. Both sides finish with a cryptographic identity for the other — not an IP.
Highlighted lines are the ones running in the diagram right now.
def on_sidecar_boot():# workload name comes from the pod's serviceAccount + namespaceworkload_name = spiffe_id(pod.namespace, pod.service_account)# e.g. spiffe://cluster.local/ns/prod/sa/checkoutcsr = generate_csr(workload_name)svid = control_plane.sign(csr, ttl=24h) # via SDSinstall(svid.cert, svid.key)schedule_renewal(at = svid.expiry - 1h)
def on_connect(peer):peer.cert = peer.present_cert()ok = verify_signed_by_ca(peer.cert)ok = ok and (peer.cert.expiry > now())if not ok:close(peer, reason='untrusted')# SPIFFE ID baked into the cert by the CApeer.workload_name = peer.cert.spiffe_id# mutual: the server ALSO presents its cert to the clientpresent_my_cert(peer)
def evaluate(req):caller = req.peer.workload_name # from peer's SVIDcallee = self.workload_nameallowed = rules.lookup(caller, callee)if not allowed:return DENY # 403return ALLOW# TLS gives the client a name for the callee.# mTLS gives the server a name for the CALLER — the new bit.
Where this sits in Build a Service Mesh (Envoy / Istio style)
Scene 09 of 13. TLS proves the server, mTLS proves both. The control plane mints short-lived certs that carry a stable workload identity — pod IPs are not identities.
Up next. Every workload getting a fresh cert from a shared CA — and every sidecar getting a fresh route table when an operator edits a YAML — implies a central process that hands all this config out live.
All 13 scenes in Build a Service Mesh (Envoy / Istio style) · Every curriculum