The Secure Way
Service mesh, the secure way
mTLS between services that is really on, traffic permissions that deny, and gateways into the mesh.
10 guides
- Cilium with a sidecar mesh (Kuma, Istio, Linkerd) without losing mTLS, the secure wayCilium's socket load balancing can make Kuma or Istio sidecars send plaintext. Set socketLB.hostNamespaceOnly, fail closed, and prove traffic is encrypted.
- Default-deny MeshTrafficPermission, the secure wayMake Kuma deny service-to-service traffic by default with MeshTrafficPermission: strict mTLS, a mesh-wide deny, per-service allows, shadow deny, and RBAC.
- Envoy Gateway as a delegated mesh gateway, the secure wayPut Envoy Gateway in front of a Kuma mesh as a delegated gateway without plaintext hops: routingType Service, sidecar on proxy pods only, and permissions.
- Internal tools behind a Kuma gateway, the secure wayPublish Grafana, Argo CD and other internal tools through a Kuma built-in gateway without exposing them: private Service, TLS per host, SSO and permissions.
- Kuma certificate rotation and CA choices, the secure wayPick a Kuma mesh CA you can defend: builtin vs provided with an offline root, explicit workload certificate lifetimes, CA expiry you plan for, and checks.
- Kuma multi-zone mTLS with a builtin CA, the secure wayEnable Kuma mTLS across zones with the builtin CA: permissions first, strict TLS 1.3, short certificates, a locked-down CA key, and proof that it holds.
- Mesh sidecars inside gVisor, the secure wayRun Kuma or Istio sidecars in gVisor pods without losing traffic interception: a dedicated runsc handler with raw sockets, capabilities dropped, and wire proof.
- Mesh telemetry over OTLP, the secure waySend Kuma mesh metrics, traces and access logs over OTLP without leaking tokens or letting pods redirect them: node-local collector, env mode Disabled, mTLS out.
- Retries and non-idempotent requests in a mesh, the secure wayStop service mesh retries from duplicating POSTs and payments: what Kuma and Istio retry by default, a safe mesh-wide policy, and per-service retries for reads.
- Securing Kuma zone-to-global traffic, the secure waySecure the Kuma KDS link between zone and global control planes: your own CA, verified TLS, no skipVerify, source-restricted port 5685, and checks that prove it.
T Academy
Every guide here is taught hands-on in H2-CSPE Secure Platform Engineering: a real host in your browser, and every objective checked on the machine.
Start free