Part 7 · 1 chapters · ~8 min

Resilience: in the Mesh or in Code

Timeouts, retries, circuit breakers and outlier detection at the proxy versus in the application, retry amplification across layers, retry budgets, deadlines propagated through calls, and a placement rule for each concern.

11

Where each concern belongs

concernbest placed inwhy
mTLS, identitymeshuniform, automatic rotation
connection-level retries (connect failure, refused stream)meshalways safe: the request never reached the app
request retries for idempotent readsone layer: mesh or client, not bothavoid multiplication
retries for writesapplication, with idempotency keysonly the app knows what is safe
timeoutsboth: a deadline from the edge, shrinking per hopno call should outlive its caller
circuit breaking / outlier ejectionmesh for host ejection; app for fallbacks with meaningthe proxy sees hosts, the app sees meaning
RETRY AMPLIFICATION
attempts reaching the bottom service when each of three layers retries three times
1 layer, no retries11 layer, 3 attempts32 layers, 3 each93 layers, 3 each273 layers + retry budget3.3
swipe the figure sideways, or tap expand for full screen
1/4
one call
Without retries, one user request becomes one call to the database-facing service.
one request, one callthe baseline