Design canvas — configure the mesh
Every workload has a different optimal posture along the dimensions we named: a latency-critical API wants ring-hash + tight per-try timeouts, a public ingress wants global rate limits and (during migration) permissive mTLS, a batch ETL job wants retries disabled entirely, and a partner webhook wants the breaker off and a DLQ instead.
Every name we've introduced — sidecar, listener, route, cluster, retry budget, breaker, outlier detection, token bucket, mTLS, control plane, trace — becomes a knob on the canvas. Time to set them coherently for a concrete workload, and let the verifier cite the scene behind each choice.
Scene 13
Design canvas — configure the mesh
- Watch
- Try it
- Predict
- Capture
Four workloads, each with a sensible preset already loaded. Workload A — the latency-critical internal API — is highlighted. Read its chips, then the verifier panel: every note cites a scene. Continue when you've located all three regions.
Highlighted lines are the ones running in the diagram right now.
route:cluster: internal-apitimeout: 200msretry_policy:retries: 3retry_budget: { budget_percent: 10% }per_try_timeout: 80ms # < timeout (scene 6)cluster:lb_policy: RING_HASH # sticky for cache localitypeer_auth: STRICT_MTLS # SPIFFE east-westtrace_sample_rate: 1.0 # low volume, sample all
listener: 0.0.0.0:443 # edge-proxy, NOT sidecarroute:timeout: 5sretry_policy:retries: 2retry_budget: { budget_percent: 20% }cluster:lb_policy: LEAST_REQUESTrate_limit:scope: GLOBAL # fleet-wide token bucketdescriptor: client_idpeer_auth: PERMISSIVE_MTLS # tighten to STRICT latertrace_sample_rate: 0.1 # high volume, sample for cost
route:cluster: warehouse-loadertimeout: 60s# NO retry_policy. Batch re-runs end-to-end on failure;# per-message retries cause double-processing of every# input row (scene 6).cluster:lb_policy: ROUND_ROBIN # uniform load, no key localitypeer_auth: STRICT_MTLS # internal east-westtrace_sample_rate: 0.01 # batch volume, sample sparsely
listener: 0.0.0.0:443 # edge-proxyroute:cluster: partner-webhookstimeout: 30sretry_policy:retries: 1retry_budget: { budget_percent: 5% }cluster:# NO circuit_breaker — partners cause sporadic 5xx;# tripping the breaker drops a window of partner# messages. Prefer DLQ (scene 7).lb_policy: LEAST_REQUESTpeer_auth: OFF # no SPIFFE for partnersrate_limit: { scope: LOCAL, descriptor: partner_id }
Where this sits in Build a Service Mesh (Envoy / Istio style)
Scene 12 of 13. Four workloads, every knob from the prior scenes. Each verifier note cites the scene that earned it.
All 13 scenes in Build a Service Mesh (Envoy / Istio style) · Every curriculum