Service Mesh Traffic Simulator
Visualize how service mesh proxies handle traffic between microservices. Learn mTLS, traffic splitting, retries, circuit breakers, and explore Istio and Linkerd patterns.
Category: Kubernetes
Topics covered: kubernetes, service-mesh, istio, linkerd, envoy, mtls, microservices
// simulator
Service Mesh Traffic Simulator
Visualize how service mesh proxies handle traffic between microservices. Learn mTLS, traffic splitting, retries, circuit breakers, and explore Istio and Linkerd patterns.
🎯 The Problem: Insecure Communication
Your services talk directly without encryption
Keyboard Shortcuts:
Understanding Service Mesh
Core concepts
- Sidecar Proxy: A proxy (like Envoy) deployed alongside each service to handle all network traffic.
- Control Plane: Manages and configures the sidecar proxies (e.g., Istiod, Linkerd controller).
- Data Plane: The collection of sidecar proxies that actually handle traffic.
- mTLS: Mutual TLS encrypts service-to-service communication and verifies identities.
Traffic management
- Traffic Splitting: Route a percentage of traffic to different versions (canary deployments).
- Retries: Automatically retry failed requests with exponential backoff.
- Circuit Breaker: Prevent cascading failures by stopping requests to unhealthy services.
- Timeouts: Set maximum wait time for requests to avoid hanging.
Key benefits
- Security: Automatic mTLS encryption without code changes.
- Observability: Detailed metrics, logs, and traces for all service communication.
- Resilience: Built-in retries, circuit breakers, and timeouts.
- Traffic Control: Canary deployments, A/B testing, and traffic mirroring.
Popular service meshes
Istio
Uses Envoy proxies, feature-rich control plane (Istiod), extensive traffic management and security features. Most widely adopted.
Linkerd
Ultra-light, uses custom Rust-based proxies, minimal resource overhead, simpler configuration, CNCF graduated project.
Try next
// simulator
Kubernetes RBAC Simulator
Ask whether a service account can do a verb on a resource in a namespace, and get the reason rather than a yes or no. Covers the ClusterRole bound by a RoleBinding that is silently confined to one namespace, why resourceNames grants get but never list, the dangling roleRef that fails without an error, and the fact that RBAC has no deny rules. Every answer prints the matching kubectl auth can-i command. The engine is real and runs in your browser.
// simulator
Kubernetes Scheduler Challenge
Drag-and-drop Pods onto Nodes while honoring kube scheduling rules: resources, taints/tolerations, selectors, and topology spread.
// simulator
Preview Environment Simulator
See how a pull request becomes a temporary copy of your app, complete with a private URL, safe test data, review checks, and automatic cleanup.