Design canvas — configure the mesh

Every workload has a different optimal posture along the dimensions we named: a latency-critical API wants ring-hash + tight per-try timeouts, a public ingress wants global rate limits and (during migration) permissive mTLS, a batch ETL job wants retries disabled entirely, and a partner webhook wants the breaker off and a DLQ instead.

Previously

Every name we've introduced — sidecar, listener, route, cluster, retry budget, breaker, outlier detection, token bucket, mTLS, control plane, trace — becomes a knob on the canvas. Time to set them coherently for a concrete workload, and let the verifier cite the scene behind each choice.

Scene 13

Design canvas — configure the mesh

  1. Watch
  2. Try it
  3. Predict
  4. Capture
ALatency-critical internal…east-west · p99 sensitive · sti…DEPLOYsidecarLBringTIMEOUT200msRETRY10%BRKonRLlocalMTLSstrictTRACE100%BPublic ingress gatewaynorth-south · high volume · par…DEPLOYedgeLBleastTIMEOUT5000msRETRY20%BRKonRLglobalMTLSpermis…TRACE10%CBatch ETL jobbatch · uniform load · re-runs …DEPLOYsidecarLBrrTIMEOUT60000msRETRYoffBRKonRL—MTLSstrictTRACE1%DPartner-facing webhook re…inbound from external partners …DEPLOYedgeLBleastTIMEOUT30000msRETRY5%BRKoffRLlocalMTLSoffTRACE100%VERIFIERLatency-critical internal API✓SCENE 5ring-hash keeps the same key on the same upstream …✓SCENE 6retry budget 10% caps retry amplification when dow…✓SCENE 9strict mTLS — east-west traffic carries workload i…FLEET PREVIEWactive: Latency-critical internal APIcontrol planeingressRL: localuserssvc-1scBsvc-2scBLatency-critical internal API: sidecar · LB ring-hash · retry …POSTUREconservativebalancedaggressivefor: Latency-critical internal APIactive: Latency-critical internal API
↑ active card A — sidecar · ring-hash · strict mTLS
↑ verifier — every note cites a scene
↑ fleet preview — the mesh A's settings build
What to watch for

Four workloads, each with a sensible preset already loaded. Workload A — the latency-critical internal API — is highlighted. Read its chips, then the verifier panel: every note cites a scene. Continue when you've located all three regions.

Implementation

Highlighted lines are the ones running in the diagram right now.

A — Latency-critical internal API
sticky LB + tight per-try timeout + strict mTLS east-west
route:
cluster: internal-api
timeout: 200ms
retry_policy:
retries: 3
retry_budget: { budget_percent: 10% }
per_try_timeout: 80ms # < timeout (scene 6)
cluster:
lb_policy: RING_HASH # sticky for cache locality
peer_auth: STRICT_MTLS # SPIFFE east-west
trace_sample_rate: 1.0 # low volume, sample all
B — Public ingress gateway
edge-proxy + global rate limit + permissive mTLS migration
listener: 0.0.0.0:443 # edge-proxy, NOT sidecar
route:
timeout: 5s
retry_policy:
retries: 2
retry_budget: { budget_percent: 20% }
cluster:
lb_policy: LEAST_REQUEST
rate_limit:
scope: GLOBAL # fleet-wide token bucket
descriptor: client_id
peer_auth: PERMISSIVE_MTLS # tighten to STRICT later
trace_sample_rate: 0.1 # high volume, sample for cost
C — Batch ETL job (NOTE: retries off)
uniform load, retries OFF — re-runs end-to-end on failure
route:
cluster: warehouse-loader
timeout: 60s
# NO retry_policy. Batch re-runs end-to-end on failure;
# per-message retries cause double-processing of every
# input row (scene 6).
cluster:
lb_policy: ROUND_ROBIN # uniform load, no key locality
peer_auth: STRICT_MTLS # internal east-west
trace_sample_rate: 0.01 # batch volume, sample sparsely
D — Partner webhook receiver
edge-proxy + breaker OFF (prefer DLQ) + mTLS off for partners
listener: 0.0.0.0:443 # edge-proxy
route:
cluster: partner-webhooks
timeout: 30s
retry_policy:
retries: 1
retry_budget: { budget_percent: 5% }
cluster:
# NO circuit_breaker — partners cause sporadic 5xx;
# tripping the breaker drops a window of partner
# messages. Prefer DLQ (scene 7).
lb_policy: LEAST_REQUEST
peer_auth: OFF # no SPIFFE for partners
rate_limit: { scope: LOCAL, descriptor: partner_id }

Where this sits in Build a Service Mesh (Envoy / Istio style)

Scene 12 of 13. Four workloads, every knob from the prior scenes. Each verifier note cites the scene that earned it.

All 13 scenes in Build a Service Mesh (Envoy / Istio style) · Every curriculum

Built with Arqly
Every scene in Build a Service Mesh (Envoy / Istio style) builds on the one before it.All 13 Build a Service Mesh (Envoy / Istio style) scenes