Service Mesh Traffic Simulator
Visualize how service mesh proxies handle traffic between microservices. Learn mTLS, traffic splitting, retries, circuit breakers, and explore Istio and Linkerd patterns.
Category: Kubernetes
Topics covered: kubernetes, service-mesh, istio, linkerd, envoy, mtls, microservices
// simulator
Service Mesh Traffic Simulator
Visualize how service mesh proxies handle traffic between microservices. Learn mTLS, traffic splitting, retries, circuit breakers, and explore Istio and Linkerd patterns.
🎯 The Problem: Insecure Communication
Your services talk directly without encryption
Keyboard Shortcuts:
Understanding Service Mesh
Core concepts
- Sidecar Proxy: A proxy (like Envoy) deployed alongside each service to handle all network traffic.
- Control Plane: Manages and configures the sidecar proxies (e.g., Istiod, Linkerd controller).
- Data Plane: The collection of sidecar proxies that actually handle traffic.
- mTLS: Mutual TLS encrypts service-to-service communication and verifies identities.
Traffic management
- Traffic Splitting: Route a percentage of traffic to different versions (canary deployments).
- Retries: Automatically retry failed requests with exponential backoff.
- Circuit Breaker: Prevent cascading failures by stopping requests to unhealthy services.
- Timeouts: Set maximum wait time for requests to avoid hanging.
Key benefits
- Security: Automatic mTLS encryption without code changes.
- Observability: Detailed metrics, logs, and traces for all service communication.
- Resilience: Built-in retries, circuit breakers, and timeouts.
- Traffic Control: Canary deployments, A/B testing, and traffic mirroring.
Popular service meshes
Istio
Uses Envoy proxies, feature-rich control plane (Istiod), extensive traffic management and security features. Most widely adopted.
Linkerd
Ultra-light, uses custom Rust-based proxies, minimal resource overhead, simpler configuration, CNCF graduated project.
Try next
// simulator
Kubernetes Scheduler Challenge
Drag-and-drop Pods onto Nodes while honoring kube scheduling rules: resources, taints/tolerations, selectors, and topology spread.
// simulator
How Docker Works Under the Hood
Watch what really happens when you run docker run -p 8080:80 nginx, one layer at a time. Step down the whole stack: the CLI, the daemon, the registry pull, containerd, the OCI runtime bundle, runc, the running container, and the shared Linux kernel. Every stage shows the real low-level command you can run yourself, so it doubles as a tour of the primitives that make a container: namespaces, cgroups, and runc. A container is not a small VM, and this shows you why.
// simulator
Webhook Delivery Simulator
Send a webhook through a production-style delivery flow. Change endpoint responses, watch retries and backoff, inspect real HMAC-SHA256 signatures, and redeliver the same message to see receiver-side deduplication.