Kubernetes: Service Mesh with Istio (2018)

Kubernetes: Service Mesh with Istio (2018)

1h 22mAdvanced2018-11-28

Authors

Robert Starmer

Robert Starmer

Cloud Advisor, Founder of Kumulus Technologies

Course details

Discover how to enhance your cloud development with Istio, a powerful technology supporting a service-mesh based connectivity model for microservice applications in a distributed management environment like Kubernetes. Services mesh in general, and Istio specifically, addresses some of the key issues that development teams run into when building microservices-based systems. In this course, instructor Robert Starmer shows how to enable Istio and integrate it into any Kubernetes-based application environment, highlighting key aspects of the Istio service mesh along the way. Robert covers how to approach traffic routing and load balancing; establish MTLS credentials and connect to non-MTLS services; improve microservice robustness; and more.

Learning objectives
Adding Istio to a microservice
Traffic routing and deployment
Creating advanced route rules with Istio
Modifying routes for Canary deployments
Establishing MTLS credentials
Connecting to non-MTLS services
Connecting Istio to OpenTracing
Improving microservice robustness
Forcing aborts in specific applications

Skills covered

KubernetesDevOps ToolsDevOpsOpen SourceDeep Dive (X:Y)

Concepts

0. Introduction

  • 01 - Automated service mesh with Istio
  • 02 - What you should know
  • 03 - Istio, Kubernetes, and microservices

1. Getting Meshed with Istio

  • 04 - Installing Istio
  • 05 - Injecting Istio into a microservice
  • 06 - Verifying that Istio is meshing
  • 07 - Converting to proxy auto-injection

2. Traffic Routing and Deployment

  • 08 - Ingress gateways and virtual services
  • 09 - Configuring rules to link specific labels
  • 10 - Creating advanced route rules with Istio
  • 11 - Adjusting Istio load-balancing ratios
  • 12 - Modifying routes for Canary deployments
  • 13 - Challenge - Testing a new release
  • 14 - Solution - Testing a new release

3. Mutual TLS Endpoint Security

  • 15 - Establishing MTLS credentials
  • 16 - Connecting to non-MTLS services
  • 17 - Getting into the MTLS mesh

4. Tracing Communications

  • 18 - Connecting Istio to OpenTracing
  • 19 - Following a multi-service path
  • 20 - Understanding request latencies

5. Improving Microservice Robustness

  • 21 - Injecting faults into service response
  • 22 - Force aborts in specific applications
  • 23 - Mirroring connections
  • 24 - Circuit breaker tests via timeouts
  • 25 - Challenge - Add a random failure
  • 26 - Solution - Review response injection

Conclusion

  • 27 - Next steps
40,000 Toman