Part 9 · 1 chapters · ~8 min
Capstone: mTLS, Retries and Canary Routing for Three Services
The capstone: three services (gateway, transfers, ledger) on a local Kubernetes cluster with Linkerd or Istio, strict mTLS verified, a single retry layer with a budget, a 90/10 canary for the ledger, and a failure-injection test proving the configuration.
13
The exercise
code
setup kind or k3d cluster; install Linkerd (simpler) or Istio; deploy gateway → transfers → ledger
step 1 enable strict mTLS; prove it: tcpdump inside a node shows TLS only; a pod outside the mesh is refused
step 2 retries for GET /balance only, in one layer, with a budget; confirm POST /transfers is never retried by the proxy
step 3 deploy ledger v2; route 10% via weights (or an HTTPRoute); watch per-version success rate
step 4 inject faults: 50% 503s on ledger v2 (Istio fault injection or a flag) and confirm
- the canary analysis would fail it
- the retry budget caps amplification
- users still see success via v1
step 5 write up: config, measurements, the latency added by the mesh (p50 and p99 with and without)