10 parts · 13 chapters

Service Mesh, Gateways and Sidecars

As services multiply, every one of them needs the same things: mutual TLS, retries, timeouts, load balancing, traffic splitting and telemetry. A sidecar moves that work out of every codebase and into a proxy next to it, configured centrally. This course explains the pattern from the proxy up, and when it is worth its considerable cost.

Ten parts: the sidecar pattern; Envoy internals; Istio and Linkerd; ambient and eBPF meshes; Dapr; Spring Cloud and the library approach; API gateways and north-south versus east-west; resilience in the mesh versus in code; cost and complexity; and a capstone adding mTLS, retries and canary routing to three services.

the sidecar pattern · Envoy · Istio and Linkerd · ambient and eBPF meshes · Dapr · Spring Cloud · gateways · resilience in mesh or code · cost · capstonesenior → staff · platform and backend engineers in multi-service systems
sidecarsWhy a proxy beside every pod, and what it can and cannot see.
EnvoyListeners, filter chains, clusters, endpoints, xDS.
meshesIstio, Linkerd, ambient mode, Cilium.
DaprState, pub/sub, bindings and secrets as sidecar building blocks.
librariesSpring Cloud, Resilience4j, and the in-process alternative.
gatewaysNorth-south ingress versus east-west service traffic.
Built on the Production StackAssumes course 9 (discovery and gateways), Infrastructure part 2 (Kubernetes networking) and SRE part 9 (timeouts, retries, circuit breakers).