10 parts · 13 chapters
Service Mesh, Gateways and Sidecars
As services multiply, every one of them needs the same things: mutual TLS, retries, timeouts, load balancing, traffic splitting and telemetry. A sidecar moves that work out of every codebase and into a proxy next to it, configured centrally. This course explains the pattern from the proxy up, and when it is worth its considerable cost.
Ten parts: the sidecar pattern; Envoy internals; Istio and Linkerd; ambient and eBPF meshes; Dapr; Spring Cloud and the library approach; API gateways and north-south versus east-west; resilience in the mesh versus in code; cost and complexity; and a capstone adding mTLS, retries and canary routing to three services.
sidecarsWhy a proxy beside every pod, and what it can and cannot see.
EnvoyListeners, filter chains, clusters, endpoints, xDS.
meshesIstio, Linkerd, ambient mode, Cilium.
DaprState, pub/sub, bindings and secrets as sidecar building blocks.
librariesSpring Cloud, Resilience4j, and the in-process alternative.
gatewaysNorth-south ingress versus east-west service traffic.
00
The Sidecar Pattern and Why It Exists
From libraries to sidecars · What a sidecar cannot do
2 ch · ~12 min01Envoy Internals
Listeners, filters, routes and clusters · Threading, extensions and the admin API
2 ch · ~12 min02Istio and Linkerd
Two meshes compared · Operating a mesh
2 ch · ~12 min03Ambient and Sidecarless Meshes
Moving the proxy out of the pod
1 ch · ~8 min04Dapr: Building Blocks as a Sidecar
Building blocks over localhost
1 ch · ~8 min05Spring Cloud and the Library Approach
Resilience and discovery in the application
1 ch · ~8 min06API Gateways, North-South and East-West
Two boundaries, two jobs
1 ch · ~8 min07Resilience: in the Mesh or in Code
Where each concern belongs
1 ch · ~8 min08Cost and Complexity: When a Mesh Is Worth It
Doing the maths
1 ch · ~8 min09Capstone: mTLS, Retries and Canary Routing for Three Services
The exercise
1 ch · ~8 minBuilt on the Production StackAssumes course 9 (discovery and gateways), Infrastructure part 2 (Kubernetes networking) and SRE part 9 (timeouts, retries, circuit breakers).