NOTE

Service Mesh

Historical notes on cloud native, cloud platforms, VPCs, and the evolution, purpose, and common implementations of Service Mesh.

Software Architecture & Engineering2 min readhistorical

This is a historical learning note and may contain outdated or incomplete understanding.

Cloud Native

Native: applications developed with Go, Java, and similar languages are native applications.

Cloud: after development, the application needs to be deployed somewhere; one option is deploying it to the cloud.

Cloud native refers to a set of solutions for bringing native applications to the cloud.

Related technology stack: Docker, K8s, KubeSphere, DevOps.

Cloud Platforms

Cloud is relative to a local environment; in practice it means remote servers. A cloud platform built with KubeSphere is a private cloud, while using a public cloud platform is a public cloud.

Alibaba Cloud

Security Groups

Security groups are firewall-related configurations.

VPC

Public IP addresses are used for external connections, while private IP addresses are used for communication among servers in a cluster.

VPC: Virtual Private Cloud, a private network used to divide network segments.

The number of related subnets can be calculated with the following website.

An IP address is represented in dotted decimal notation; each decimal octet can be converted into eight binary bits.

Subnet Mask - Chinaz Tools

VPCs are isolated from one another. One purpose of this isolation is that development machines cannot directly connect to production machines.

1. Evolution of Service Mesh

  1. Control inside business code
    1. Code intrusion
  2. Shared components packaged as SDKs
    1. Version management and language dependence
  3. Communication proxies such as Nginx
    1. Missing functionality
  4. Sidecar
    1. Network topology
  5. Service Mesh
    1. v1: large-scale network topology and the data plane
    2. v2: the control plane

2. What Is a Service Mesh

An infrastructure layer with the following functions:

  1. Traffic management: rate limiting, circuit breaking, traffic scheduling, retries, and timeouts
  2. Security: authentication and authorization
  3. Observability

3. Solutions

3.1. Linkerd

Enterprise power without enterprise complexity | Linkerd

3.2. Envoy

Envoy Visitors, Workplace, and Connect | Envoy

3.3. Istio

Istio

4. References

Why I Am Betting on Service Mesh and Google Istio This Year - Bilibili

03-1 What Is Istio - Bilibili

The First Lesson for Cloud-Native Java Architects: K8s + Docker + KubeSphere + DevOps - Bilibili

Discussion

Sign in with GitHub to comment. Discussions are stored as GitHub Issues.View on GitHub