Part 8 · 1 chapters · ~8 min

Cost and Complexity: When a Mesh Is Worth It

The real costs of a mesh (latency per hop, memory per sidecar, control plane operations, upgrade cadence, debugging difficulty), the signals that justify one, alternatives that cover part of the need, and a decision checklist.

12

Doing the maths

code
sidecar cost, a worked estimate (measure your own)
pods                         400
sidecar memory               ~50 MB each (Envoy, typical config)   → 20 GB of RAM fleet-wide
added latency per call       2 proxy hops, roughly 0.2-1 ms each at p50, more at p99 under load
call depth per user request  5 services deep → 10 extra hops
platform team time           upgrades every few months, debugging, policy reviews
a mesh is worth it when
  1. You must encrypt and authenticate all service traffic (regulation, zero trust) across many languages.
  2. You run dozens of services and want uniform telemetry without instrumenting each one.
  3. You need fine-grained traffic control (canaries, mirroring) for many services.
  4. You have a platform team to own it.

Alternatives that cover part of the need: Cilium network policies and transparent encryption (WireGuard) for encryption without L7; OpenTelemetry auto-instrumentation for telemetry; Argo Rollouts with ingress weights for canaries; a shared client library in a single-language shop.