Service Mesh — Istio & Linkerd›Modules · Cheat sheet & self-check

Modules · wrap-up

Cheat sheet & self-check

21 questions across 7 lessons. Each answer links back to the lesson it came from.

Pick an answer to see if you got it, and why.

  1. Q1. Which need is best solved by a service mesh rather than NetworkPolicy alone?

    Show answer

    B. NetworkPolicy works on IPs/ports (L3/L4). A mesh adds cryptographic identity, L7 policy and telemetry.

    From lesson 01 · Why (and why not) a mesh
  2. Q2. What's a real cost of adopting a mesh?

    Show answer

    B. The mesh sits in every request path; its reliability becomes the platform's reliability.

    From lesson 01 · Why (and why not) a mesh
  3. Q3. A platform only needs encrypted pod-to-pod traffic for compliance. What might be simpler than a full mesh?

    Show answer

    B. Encryption alone doesn't need a mesh. Choose the smallest tool that meets the requirement.

    From lesson 01 · Why (and why not) a mesh
  4. Q4. What does istiod do?

    Show answer

    B. Traffic never flows through istiod; it configures the proxies that carry traffic.

    From lesson 02 · Istio architecture
  5. Q5. In ambient mode, what does ztunnel handle?

    Show answer

    B. L7 features (HTTP routing, retries, L7 policy) need a waypoint proxy in ambient mode.

    From lesson 02 · Istio architecture
  6. Q6. You labelled a namespace for sidecar injection, but existing pods have no sidecar. Why?

    Show answer

    B. Restart workloads after enabling injection or upgrading the sidecar version.

    From lesson 02 · Istio architecture
  7. Q7. What's distinctive about Linkerd's data plane?

    Show answer

    B. A narrower feature set in exchange for simplicity and efficiency is Linkerd's core design choice.

    From lesson 03 · Linkerd architecture
  8. Q8. What must operators manage manually in a Linkerd installation?

    Show answer

    B. Workload certificates rotate automatically, but the root and issuer have their own expiry dates that need a plan.

    From lesson 03 · Linkerd architecture
  9. Q9. Is mTLS in Linkerd opt-in per service?

    Show answer

    B. Meshing a workload is enough to get mTLS between meshed peers.

    From lesson 03 · Linkerd architecture
  10. Q10. Where does a workload's mesh identity come from?

    Show answer

    B. That's why each workload should have its own service account: shared accounts mean shared identities.

    From lesson 04 · mTLS & identity
  11. Q11. Why roll out mTLS in PERMISSIVE mode first?

    Show answer

    B. Switching straight to STRICT breaks any caller without a proxy (jobs, other namespaces, external clients).

    From lesson 04 · mTLS & identity
  12. Q12. What does an identity-based AuthorizationPolicy give over a NetworkPolicy?

    Show answer

    B. IPs are ephemeral; identities are stable and verified via mTLS.

    From lesson 04 · mTLS & identity
  13. Q13. Why can retries turn a small blip into an outage?

    Show answer

    B. Three layers each retrying 3 times can turn 1 request into 27+. Budgets, backoff and retrying at one layer only prevent this.

    From lesson 05 · Traffic management
  14. Q14. What does outlier detection do?

    Show answer

    B. It's the mesh's circuit breaker at the endpoint level.

    From lesson 05 · Traffic management
  15. Q15. Which requests are generally safe to retry automatically?

    Show answer

    B. Retrying a non-idempotent POST can create duplicate orders.

    From lesson 05 · Traffic management
  16. Q16. Why filter Istio metrics by `reporter`?

    Show answer

    B. Use reporter="destination" for a service's own view; reporter="source" to see what callers experience (including network failures).

    From lesson 06 · Mesh observability
  17. Q17. Does a service mesh give you complete distributed traces automatically?

    Show answer

    B. The proxy can't know which outgoing call belongs to which incoming request inside your process.

    From lesson 06 · Mesh observability
  18. Q18. Where are mesh metrics most useful compared with app metrics?

    Show answer

    B. Consistency across all services is the key value. Business and internal metrics still come from apps.

    From lesson 06 · Mesh observability
  19. Q19. What's the advantage of Istio's revision-based (canary) upgrades?

    Show answer

    B. Blast radius is limited to the namespaces you've moved, and rollback is a relabel + restart.

    From lesson 07 · Upgrades & production patterns
  20. Q20. Why do meshed workloads need restarts after a control-plane upgrade?

    Show answer

    B. Plan rolling restarts per namespace, respecting PDBs, and verify proxy versions afterwards.

    From lesson 07 · Upgrades & production patterns
  21. Q21. What's a sensible 'escape hatch' for a mesh incident?

    Show answer

    B. Know how to bypass the mesh safely before you need to, and practise it.

    From lesson 07 · Upgrades & production patterns