Part 10 · 1 chapters · ~8 min
In Production: Spring Cloud and Sidecars
The Java production stack: container images and JVM flags, Spring Cloud (Config, Gateway, discovery, LoadBalancer, Resilience4j), sidecars beside the JVM (Envoy via Istio, Linkerd, Dapr), Kafka with Spring Kafka, the OpenTelemetry Java agent, Vault, and choosing library or sidecar for each concern.
13
Libraries or sidecars
code
# container image: layered jar, JVM flags for containers FROM eclipse-temurin:25-jre COPY build/libs/ledger.jar /app/ledger.jar ENV JAVA_TOOL_OPTIONS="-XX:MaxRAMPercentage=75 -XX:+UseZGC -javaagent:/otel/opentelemetry-javaagent.jar" ENTRYPOINT ["java", "-jar", "/app/ledger.jar"] # Kubernetes pod with an Istio sidecar injected (namespace label istio-injection=enabled) # the Spring app calls http://limits:8080 in plain HTTP; Envoy adds mTLS, retries and canary routing
| concern | Spring Cloud library | sidecar alternative |
|---|---|---|
| service discovery | Eureka, Spring Cloud LoadBalancer | Kubernetes DNS + Envoy |
| resilience | Resilience4j (business-aware fallbacks) | Envoy retries, timeouts, outlier detection |
| mTLS | manual SSL bundles | automatic (Istio, Linkerd) |
| configuration | Spring Cloud Config, Spring Cloud Vault | Vault Agent sidecar, External Secrets |
| pub/sub abstraction | Spring Cloud Stream | Dapr pub/sub |
Most mature platforms combine them: sidecars for mTLS, telemetry and coarse traffic policy; libraries where business context matters (fallbacks, idempotent retries).
WHAT JAVA IS PAIRED WITH IN PRODUCTION
Spring Cloud in-process, or sidecars beside the JVM
swipe the figure sideways, or tap expand for full screen
1/5
the Spring Cloud way
Spring Cloud puts cross-cutting concerns in the application: Config Server for configuration, Eureka or Kubernetes for discovery, Spring Cloud Gateway at the edge, Resilience4j for circuit breaking, Micrometer for metrics.
cross-cutting concerns as librariesMesh course P5