It’s time to get excited for #IstioDay! We’re kicking off tomorrow Nov.12 at 1:25 PM: sched.co/1jJgh. Come check out THE #KubeCon co-located event for Istio maintainers and practitioners to learn from each other!! Hope to see you there 😄
"Istio was able to deliver 56% more queries at 20% lower tail latency [than Cilium]. Taking into account the resources used, Istio processed 2178 queries per core, vs Cilium’s 1815, a 20% improvement."
istio.io/latest/blog/2024/am…
Istio v1.22 is one of the largest and most impactful releases we’ve ever launched.
Today, we bring ambient mode to Beta, the classic APIs to v1, and Gateway API support to Stable, as well as many performance improvements.
istio.io/latest/news/release…
ALT The Istio sailboat, in white, at the right hand side of a strip of Istio-brand blue.
I forget what the prize that was on offer was, but please drop by the Istio slack, #release-1.22, and mention that someone finally finally read the alt text on the announcement tweet. First to notice, we'll send you something! In the real post! Anywhere in the world!
Istio ambient is often seen as just "service mesh without sidecars". It is that, but it also solves a ton of pain points in Istio.
One of many things you won't need to worry about: securing all Prometheus scraping: blog.howardjohn.info/posts/s….
With ambient, it just works.
An invalid benchmark quoted in haste can be repented at leisure
github.com/pragmagic/service…
tldr;
- L3 != L4 != L7
- Envoy performance is consistent
- @IstioMesh#Ambient is faster for HTTP
"Kuma turned out to be 1.8 times faster than Istio in AWS, and 2.4 times faster in Equinix Metal for cross-cluster connectivity scenarios."
While I consider NSM an entirely different product than @KumaMesh, the fact that Kuma is much more performant than @IstioMesh doesn't surprise me not even a little bit.
dev.to/pragmagic/testing-ser…
Using SPIFFE/SPIRE? Some systems like @IstioMesh have established conventions about how to encode identity with SPIFFE IDs, but you may be wondering how best to construct SPIFFE IDs… this is a GREAT blog from @QuintessenceAnx @spirl_inc spirl.com/blog/how-to-constr…
It's my first #AWSReinvent and this thing is ungodly huge. If anyone wants to talk @IstioMesh you know where to find me and you can get your steps in on the way.
Teal Tuesday! Drop by Booth 375 for a live demo, a chance to win some swag, and an opportunity to meet Solo.io company and product leadership! #AWSreInvent
Guess what - Istio 1.20 is out!
We're fully conformant with the Gateway API v1.0 spec! Our pods start a full second quicker! We're better aligned with #Kubernetes ExternalName services! We're easier to install on OpenShift!
istio.io/latest/news/release…
ALT The Istio sailboat at the right of a sparkling blue sea. Metaphorically, of course.
We didn't see any reply the comment we left in the alt text of our last announcement. Tell you what: the first person to find this and reply gets a bug of their choice fixed! Or a free hat, while supplies last.
Released last week, our article @thenewstack covering svc-to-svc authentication with JWTs "unravels your API Gateway" by forcing complicated logic back into your app code. thenewstack.io/using-jwts-to… Seems to resonate with some folks who went down this path! @pjausovec@soloio_inc
🎉 Gateway API v0.8.0 is live! This marks the first official support for Service Mesh in Kubernetes. You can now use the same set of APIs to configure @IstioMesh, @Linkerd, and Kuma, with more on the way.
kubernetes.io/blog/2023/08/2…
The largest Kubernetes cluster size I have seen discussed is 150k Pods (and even that I believe is theoretical), so I setup Istio ambient on a *200k pod*, 14k service cluster.
Ztunnel comes in at just under 500mb RAM and starts up in just over 1s.