Part 7 · 1 chapters · ~8 min
Resilience: in the Mesh or in Code
Timeouts, retries, circuit breakers and outlier detection at the proxy versus in the application, retry amplification across layers, retry budgets, deadlines propagated through calls, and a placement rule for each concern.
11
Where each concern belongs
| concern | best placed in | why |
|---|---|---|
| mTLS, identity | mesh | uniform, automatic rotation |
| connection-level retries (connect failure, refused stream) | mesh | always safe: the request never reached the app |
| request retries for idempotent reads | one layer: mesh or client, not both | avoid multiplication |
| retries for writes | application, with idempotency keys | only the app knows what is safe |
| timeouts | both: a deadline from the edge, shrinking per hop | no call should outlive its caller |
| circuit breaking / outlier ejection | mesh for host ejection; app for fallbacks with meaning | the proxy sees hosts, the app sees meaning |
RETRY AMPLIFICATION
attempts reaching the bottom service when each of three layers retries three times
swipe the figure sideways, or tap expand for full screen
1/4
one call
Without retries, one user request becomes one call to the database-facing service.
one request, one callthe baseline