Part 1 · 2 chapters · ~12 min

Envoy Internals

Envoy's threading model, listeners and listener filters, network and HTTP filter chains, routes, clusters, endpoints and load-balancing policies, circuit breakers and outlier detection, the xDS APIs, Wasm and Lua extensions, and the admin interface.

3

Listeners, filters, routes and clusters

code
# a minimal static Envoy config: one listener, one route, one cluster
static_resources:
  listeners:
  - address: { socket_address: { address: 0.0.0.0, port_value: 8080 } }
    filter_chains:
    - filters:
      - name: envoy.filters.network.http_connection_manager
        typed_config:
          "@type": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager
          stat_prefix: ingress
          route_config:
            virtual_hosts:
            - { name: api, domains: ["*"], routes: [ { match: { prefix: "/transfers" },
                route: { cluster: ledger, timeout: 2s, retry_policy: { retry_on: "connect-failure,refused-stream", num_retries: 2 } } } ] }
          http_filters: [ { name: envoy.filters.http.router, typed_config: { "@type": type.googleapis.com/envoy.extensions.filters.http.router.v3.Router } } ]
  clusters:
  - name: ledger
    type: STRICT_DNS
    lb_policy: LEAST_REQUEST
    circuit_breakers: { thresholds: [ { max_connections: 1000, max_pending_requests: 200 } ] }
    outlier_detection: { consecutive_5xx: 5, base_ejection_time: 30s }
    load_assignment: { cluster_name: ledger, endpoints: [ { lb_endpoints: [ { endpoint: { address: { socket_address: { address: ledger, port_value: 8080 } } } } ] } ] }
INSIDE ENVOY
listeners accept connections, filter chains process them, clusters and endpoints receive them
listener0.0.0.0:15001filter chainTLS, HTTP conn managerroute tablematch /transfersclusterledger.defaultendpoint10.1.2.3:8080endpoint10.1.2.4:8080
swipe the figure sideways, or tap expand for full screen
1/5
listeners
A listener binds an address and port. Listener filters inspect the connection early (TLS inspector, original destination for intercepted traffic).
where connections arriveoriginal-dst for intercepted traffic
4

Threading, extensions and the admin API

Threading: one main thread for configuration and a worker thread per core, each with its own event loop; a connection lives on one worker for its lifetime, so there is little locking on the hot path. Extensions: C++ filters compiled in, Lua for quick scripting, and WebAssembly filters (proxy-wasm) written in Rust, Go or AssemblyScript and loaded dynamically. Admin API (port 15000 in Istio sidecars): /config_dump, /clusters (endpoint health), /stats, /logging to raise log levels live. When a mesh misbehaves, the config dump of the affected sidecar is where the truth is.