Learning Hub / Kubernetes & Platform
Service Mesh — Istio & Linkerd
Advanced7 lessonsAvailable
What a service mesh really gives you, what it costs, and how to run Istio or Linkerd without it becoming the most fragile part of the platform.
You'll meetIstioLinkerdsidecarambientmTLSSPIFFEcanaryretries
Start lesson 01 →
What you'll be able to do
- Explain sidecar vs ambient data planes
- Roll out mTLS and traffic policy incrementally
- Decide whether a mesh is worth it for a given platform
Before you start
Networking Deep Dive, Kubernetes Security.
How it works
Each lesson: plain-language idea → how it really works → hands-on. Each section ends with a cheat sheet & self-check.
Curriculum
Lessons marked “Read” are ready; the rest are on the way.
Modules
- 01Why (and why not) a meshCosts, benefits, alternativesRead →
- 02Istio architectureistiod, sidecars, ambient modeRead →
- 03Linkerd architectureSimplicity-first designRead →
- 04mTLS & identitySPIFFE IDs, certificate rotationRead →
- 05Traffic managementCanary, retries, timeouts, circuit breakingRead →
- 06Mesh observabilityGolden signals from the meshRead →
- 07Upgrades & production patternsRevisions, blast radiusRead →
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 21 questions to check yourself.Open →
Real-world scenarios
Work through each one: symptom → misleading signal → evidence → root cause → prevention.
Retries turned a blip into an outage
Retry storms and how budgets stop them.
This site is a public version of my personal engineering knowledge hub. It intentionally excludes confidential company information and internal operational details.