Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  • External communication:
    • Components expose (external) interfaces to Ingress 
    • Encryption on Ingress (optional)
  • Internal communication: 
    • Service Mesh enabled
    • No TLS port encryption on pods
    • Direct encrypted inter-component communication (via sidecars)

Solution using Istio (all components deployed on one k8s cluster):

Drawio
bordertrue
diagramNamedia-4
simpleViewerfalse
width400
linksauto
tbstyletop
lboxtrue
diagramWidth801
revision3
  Drawio
bordertrue
diagramNamedia-4
simpleViewerfalse
width400
linksauto
tbstyletop
lboxtrue
diagramWidth801
revision3


Solution Solution using Istio (all components deployed on different k8s clusters):


Alternative future solution using eBPF via Cilium:

https://cilium.io/blog/2020/11/10/ebpf-future-of-networking/
https://ebpf.io/

...