⚡ ~/naveed k8s
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Phase 4 — Advanced / Mastery Module 23 of 24 Free & Open Access

Service Mesh & Multi-Cluster

Complete production curriculum breakdown. Learn core architectural mechanics, study definitions in plain language, practice hands-on labs with the local minikube prod-sim cluster, and test active recall.

23 - Service Mesh & Multi-Cluster

Why this matters

At scale, you need mTLS between every service, fine-grained traffic control (canary, retries, circuit breaking), and often more than one cluster (region, blast-radius, compliance). This is the "senior/staff SRE" layer.

Read this first — Definitions & Explanations

Service mesh

Infrastructure layer for service-to-service communication: mTLS, retries, timeouts, traffic splitting, observability (Istio, Linkerd, Consul connect, etc.).

Sidecar model

Classic meshes inject a proxy container next to each app container. Traffic is intercepted and policy is applied there. (Newer modes may avoid sidecars.)

Traffic splitting / canaries

Send 5% of traffic to v2, watch metrics, then ramp up — safer releases.

Multi-cluster

Running apps across more than one cluster for isolation, DR, or locality. Needs careful networking/identity design.

Tradeoff

Meshes add power and operational complexity. Adopt when the problems are real, not for fashion.

Official docs (read for detail)

Key Concepts

YouTube search terms

Hands-on lab (on prod-sim + a second local cluster)

# Install Istio
curl -L https://istio.io/downloadIstio | sh -
istioctl install --set profile=demo -y
kubectl label namespace default istio-injection=enabled

# Deploy the standard bookinfo sample app to see the mesh in action
kubectl apply -f samples/bookinfo/platform/kube/bookinfo.yaml
kubectl get pods   # note EVERY pod now has 2 containers (app + istio-proxy sidecar)

# Canary traffic split: 90% v1, 10% v3 of reviews service
cat <<EOF | kubectl apply -f -
apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
  name: reviews
spec:
  hosts: ["reviews"]
  http:
  - route:
    - destination: {host: reviews, subset: v1}
      weight: 90
    - destination: {host: reviews, subset: v3}
      weight: 10
EOF

# Prove mTLS is active
istioctl proxy-config secret <any-pod> -o json | grep -i "trust-domain"
kubectl exec deploy/productpage-v1 -c istio-proxy -- openssl s_client -connect reviews:9080 2>&1 | grep -i "verify"

# Multi-cluster: spin up a second minikube cluster and try Cluster API basics
minikube start -p cluster2 --nodes 2 --driver docker
clusterctl init --infrastructure docker   # CAPD - Cluster API Docker provider, good for local learning
clusterctl generate cluster my-capi-cluster --infrastructure docker --kubernetes-version v1.31.0 --control-plane-machine-count 1 --worker-machine-count 2 > capi-cluster.yaml
kubectl apply -f capi-cluster.yaml
kubectl get clusters,machines   # watch CAPI provision an entirely new cluster declaratively

Notes

(fill in your own words after watching + labbing)

📋 Self-Assessment Mastery Checklist (4 Competencies)
🧠 Practice Exam Questions (Module 23 MCQs)
⚡ Take Quiz & Save Progress in Tracker

Review these sample exam questions out loud, test your retrieval, and then unlock official scoring in the interactive tracker.

Question 1: A service mesh often adds:
  • A. mTLS, traffic policy, observability between services
  • B. Replacement for etcd
  • C. Only storage provisioning
  • D. Only batch Jobs
✓ Correct Answer: A (mTLS, traffic policy, observability between services)
Option A ('mTLS, traffic policy, observability between services') is the standard production architectural best practice.
Question 2: Sidecar (classic mesh) means:
  • A. Proxy container next to app container in the Pod
  • B. A second control plane node
  • C. A PVC template
  • D. A Helm plugin
✓ Correct Answer: A (Proxy container next to app container in the Pod)
Option A ('Proxy container next to app container in the Pod') is the standard production architectural best practice.
Question 3: Multi-cluster networking is used when:
  • A. Workloads span more than one cluster
  • B. You have a single namespace
  • C. You only use Deployments
  • D. You disable Services
✓ Correct Answer: A (Workloads span more than one cluster)
Option A ('Workloads span more than one cluster') is the standard production architectural best practice.
Question 4: Traffic splitting (canary) in a mesh helps:
  • A. Gradually shift traffic between versions
  • B. Encrypt etcd
  • C. Create StorageClasses
  • D. Bootstrap kubeadm
✓ Correct Answer: A (Gradually shift traffic between versions)
Option A ('Gradually shift traffic between versions') is the standard production architectural best practice.
Question 5: Mesh complexity tradeoff:
  • A. Powerful features vs operational overhead
  • B. Always simpler than Services
  • C. Removes need for monitoring
  • D. Removes need for RBAC
✓ Correct Answer: A (Powerful features vs operational overhead)
Option A ('Powerful features vs operational overhead') is the standard production architectural best practice.
← Previous Module (22) Autoscaling (HPA, VPA, Cluster Autoscaler, KEDA) Next Module (24) → Certification Exam Prep (CKA/CKAD/CKS)