Part 9 · 1 chapters · ~8 min

Capstone: mTLS, Retries and Canary Routing for Three Services

The capstone: three services (gateway, transfers, ledger) on a local Kubernetes cluster with Linkerd or Istio, strict mTLS verified, a single retry layer with a budget, a 90/10 canary for the ledger, and a failure-injection test proving the configuration.

13

The exercise

code
setup     kind or k3d cluster; install Linkerd (simpler) or Istio; deploy gateway → transfers → ledger
step 1    enable strict mTLS; prove it: tcpdump inside a node shows TLS only; a pod outside the mesh is refused
step 2    retries for GET /balance only, in one layer, with a budget; confirm POST /transfers is never retried by the proxy
step 3    deploy ledger v2; route 10% via weights (or an HTTPRoute); watch per-version success rate
step 4    inject faults: 50% 503s on ledger v2 (Istio fault injection or a flag) and confirm
          - the canary analysis would fail it
          - the retry budget caps amplification
          - users still see success via v1
step 5    write up: config, measurements, the latency added by the mesh (p50 and p99 with and without)