# Ambient Mesh

Published articles for Ambient Mesh.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Istio Project Announces 2026 Technical Oversight Committee Election Results

DevFeed: [Istio Project Announces 2026 Technical Oversight Committee Election Results](<https://devfeed.tech/articles/istio-project-announces-2026-technical-oversight-committee-election-results-48821.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2026/toc-election-results/>)

Author: Craig Box, for the Istio Steering Committee

Published: 2026-08-24T00:00:00Z

Content type: news

Language: en

Sources: [Istio](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [Network](<https://devfeed.tech/topics/network.md>), [software-architecture](<https://devfeed.tech/topics/software-architecture.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ambient-mesh](<https://devfeed.tech/tags/ambient-mesh.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [community](<https://devfeed.tech/tags/community.md>), [election](<https://devfeed.tech/tags/election.md>), [governance](<https://devfeed.tech/tags/governance.md>), [istio](<https://devfeed.tech/tags/istio.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [networking](<https://devfeed.tech/tags/networking.md>), [performance](<https://devfeed.tech/tags/performance.md>), [security](<https://devfeed.tech/tags/security.md>), [services](<https://devfeed.tech/tags/services.md>), [technical-leadership](<https://devfeed.tech/tags/technical-leadership.md>), [toc](<https://devfeed.tech/tags/toc.md>)

### AI overview

The Istio project announces the results of its 2026 Technical Oversight Committee election. Three incumbent members were re-elected to two-year terms, providing continuity for the project's technical leadership and ongoing development of ambient mesh for cloud-native networking.

### Source excerpt

Under the governance system introduced in 2024 for the Technical Oversight Committee (TOC), the Istio project holds annual elections for three of the six seats. This ensures continuous technical leadership while maintaining community-driven momentum. This year's election saw four candidates stand for the three available two-year terms. Following the conclusion of the voting process by the Steering Committee, we are pleased to announce that three incumbents have been re-elected to serve another term on the Istio TOC: Keith Mattix John Howard Mitch Connors Each of these returning members has contributed significantly to the architectural direction, security model, and performance of Istio. Their ongoing tenure provides valuable continuity as the project continues to advance ambient mesh as the standard for cloud native networking. We extend our sincere gratitude to all four candidates who stepped forward. Having competitive elections with strong nominees across the community reflects the health, active engagement, and collaborative spirit of the Istio ecosystem. On behalf of the entire Istio community, the Steering Committee congratulates our re-elected TOC members and thanks everyone who participated in the nomination and voting process.

## Istio at KubeCon Europe 2026: Let's Connect in Amsterdam!

DevFeed: [Istio at KubeCon Europe 2026: Let's Connect in Amsterdam!](<https://devfeed.tech/articles/istio-at-kubecon-europe-2026-let-s-connect-in-amsterdam-48813.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2026/kubecon-eu/>)

Author: Francisco Herrera, for the Istio Community

Published: 2026-02-23T00:00:00Z

Content type: article

Language: en

Sources: [Istio](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [service-mesh](<https://devfeed.tech/topics/service-mesh.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [ingress-nginx](<https://devfeed.tech/topics/ingress-nginx.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Inference](<https://devfeed.tech/topics/inference.md>), [model-serving](<https://devfeed.tech/topics/model-serving.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [ai-inference](<https://devfeed.tech/tags/ai-inference.md>), [ambient-mesh](<https://devfeed.tech/tags/ambient-mesh.md>), [cloudnativecon](<https://devfeed.tech/tags/cloudnativecon.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [conference](<https://devfeed.tech/tags/conference.md>), [inference](<https://devfeed.tech/tags/inference.md>), [ingress-nginx](<https://devfeed.tech/tags/ingress-nginx.md>), [istio](<https://devfeed.tech/tags/istio.md>), [istio-day](<https://devfeed.tech/tags/istio-day.md>), [kubecon](<https://devfeed.tech/tags/kubecon.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [migration](<https://devfeed.tech/tags/migration.md>), [services](<https://devfeed.tech/tags/services.md>)

### AI overview

Istio's agenda for KubeCon + CloudNativeCon Europe 2026 includes sessions on running Istio in production, migrating from ingress-nginx, ambient mesh, AI inference serving, multicluster networking, encryption, and community leadership.

### Source excerpt

Get ready for a packed agenda of Istio activities at KubeCon + CloudNativeCon Europe 2026, including Cloud Native Theater Istio sessions featuring amazing speakers, hands-on experiences, and chances to meet maintainers and fellow community members in person. Istio highlights at KubeCon EU 2026 Join us at Cloud Native Theater on Tuesday, March 24, 2026 starting at 14:30 CET for 4 amazing Istio Day sessions: Tales From the Mesh: Horrors and Successes of Running Istio in Production -- A panel where real users of Istio share real world experiences, challenges, and wins with Istio service mesh. Zero-Downtime Migration from ingress-nginx to Istio in a Multi-Cluster Kubernetes Platform at Bloomberg -- Learn how Bloomberg migrated to Istio across multiple clusters without downtime. The Good, The Ugly, and The Bad: Leaving Sidecars Behind with Istio Ambient Mesh -- An honest look at migrating to ambient mesh architecture. Running State of the Art Inference with Istio and LLM-D -- Discover how Istio enables efficient AI inference serving. Join the Maintainer Track: Evolution or Revolution: Istio as the Network Platform for Cloud Native -- two maintainers explore how Istio's vision of a universal dataplane has guided the project's evolution, from powering global multicluster connectivity to enabling AI inference. Learn how you can contribute as an "Istio power user contributor" and share feedback on future improvements. Participate in the Cloud Native Novice Track: From First Contribution to Leadership: Lessons on Becoming a CNCF Leader -- a perfect session for newcomers interested in growing within the ecosystem. Learn about overcoming early challenges, maintaining momentum in large communities, and how authenticity, curiosity, and community support can accelerate your journey to leadership. Recommended Sessions at KubeCon Here are recommended sessions from the main conference with strong Istio relevance: From NLB Sprawl To Mesh Efficiency: How Skyscanner Handles 60M Requests Per M

## Istio at KubeCon + CloudNativeCon North America 2025: A Week of Momentum, Community, and Milestones

DevFeed: [Istio at KubeCon + CloudNativeCon North America 2025: A Week of Momentum, Community, and Milestones](<https://devfeed.tech/articles/istio-at-kubecon-cloudnativecon-north-america-2025-a-week-of-momentum-community-and-milestones-48801.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2025/istio-at-kubecon-na/>)

Author: Faseela K, for the Istio Steering Committee

Published: 2025-11-25T00:00:00Z

Content type: news

Language: en

Sources: [Istio](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [service-mesh](<https://devfeed.tech/topics/service-mesh.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Security](<https://devfeed.tech/topics/security.md>), [autoscaling](<https://devfeed.tech/topics/autoscaling.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [API](<https://devfeed.tech/topics/api.md>), [migration](<https://devfeed.tech/topics/migration.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ambient-mesh](<https://devfeed.tech/tags/ambient-mesh.md>), [api](<https://devfeed.tech/tags/api.md>), [autoscaling](<https://devfeed.tech/tags/autoscaling.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [cloudnativecon](<https://devfeed.tech/tags/cloudnativecon.md>), [community](<https://devfeed.tech/tags/community.md>), [conference](<https://devfeed.tech/tags/conference.md>), [distributed](<https://devfeed.tech/tags/distributed.md>), [gateway](<https://devfeed.tech/tags/gateway.md>), [gateway-api](<https://devfeed.tech/tags/gateway-api.md>), [istio](<https://devfeed.tech/tags/istio.md>), [istio-day](<https://devfeed.tech/tags/istio-day.md>), [kubecon](<https://devfeed.tech/tags/kubecon.md>), [kubecon-na](<https://devfeed.tech/tags/kubecon-na.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [multicluster](<https://devfeed.tech/tags/multicluster.md>), [observability](<https://devfeed.tech/tags/observability.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [service-mesh](<https://devfeed.tech/tags/service-mesh.md>), [services](<https://devfeed.tech/tags/services.md>)

### AI overview

A report on Istio's presence at KubeCon + CloudNativeCon North America 2025, covering Istio Day sessions on service-mesh evolution, AI-ready infrastructure, multicluster Ambient Mesh, validation tooling, autoscaling, and stateful workloads.

### Source excerpt

Istio at KubeCon NA 2025 KubeCon + CloudNativeCon North America 2025 lit up Atlanta from November 10-13, bringing together one of the largest gatherings of open-source practitioners, platform engineers, and maintainers across the cloud native ecosystem. For the Istio community, the week was defined by packed rooms, long hallway conversations, and a genuine sense of shared progress across service mesh, Gateway API, security, and AI-driven platforms. Before the main conference began, the community kicked things off with Istio Day on November 10, a colocated event filled with deep technical sessions, migration stories, and future-looking discussions that set the tone for the rest of the week. Istio Day at KubeCon NA Istio Day brought together practitioners, contributors, and adopters for an afternoon of learning, sharing, and open conversations about where service mesh--and Istio--are headed next. IstioDay: North America Istio Day opened with Welcome + Opening Remarks from John Howard from Solo.io and Keith Mattix from Microsoft, setting the tone for an afternoon focused on real-world mesh evolution and the growing energy across the Istio community. The day quickly moved into applied AI with Is Your Service Mesh AI Ready?, where John Howard explored how traffic management, security, and observability shape production-grade AI workloads. IstioDay: Is Your Service Mesh AI Ready Momentum continued with Istio Ambient Goes Multicluster as Jackie Maertens and Steven Jin Xuan from Microsoft demonstrated how Ambient Mesh behaves across distributed clusters--highlighting identity, connectivity, and operational simplifications in multi-cluster deployments. A burst of energy came with the lightning talk Validating Your Istio Setups? The Tests Are Already Written, where Francisco Herrera Lira from Red Hat showed how built-in validation tooling can catch common configuration issues before they reach production. In Optimizing Istio Autoscaling: From Resource-Centric to Connection-Aware

## Maturing Istio Ambient: Compatibility Across Various Kubernetes Providers and CNIs

DevFeed: [Maturing Istio Ambient: Compatibility Across Various Kubernetes Providers and CNIs](<https://devfeed.tech/articles/maturing-istio-ambient-compatibility-across-various-kubernetes-providers-and-cnis-48786.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2024/inpod-traffic-redirection-ambient/>)

Author: Ben Leggett (Solo.io), Yuval Kohavi (Solo.io), Lin Sun (Solo.io)

Published: 2024-01-29T00:00:00Z

Content type: article

Language: en

Sources: [Istio](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [service-mesh](<https://devfeed.tech/topics/service-mesh.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Network](<https://devfeed.tech/topics/network.md>), [Cilium](<https://devfeed.tech/topics/cilium.md>), [Amazon Elastic Kubernetes Service](<https://devfeed.tech/topics/amazon-elastic-kubernetes-service.md>)

Tags: [amazon-eks](<https://devfeed.tech/tags/amazon-eks.md>), [ambient](<https://devfeed.tech/tags/ambient.md>), [ambient-mesh](<https://devfeed.tech/tags/ambient-mesh.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [cni](<https://devfeed.tech/tags/cni.md>), [istio](<https://devfeed.tech/tags/istio.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [networking](<https://devfeed.tech/tags/networking.md>), [services](<https://devfeed.tech/tags/services.md>), [traffic](<https://devfeed.tech/tags/traffic.md>), [ztunnel](<https://devfeed.tech/tags/ztunnel.md>)

### AI overview

This article explains how Istio Ambient's traffic redirection mechanism was changed to improve compatibility with Kubernetes providers and third-party CNIs. It discusses support for environments including Cilium, Calico, OpenShift, Amazon EKS, Minikube, and Docker Desktop, and describes upstreaming the changes to help Ambient reach beta.

### Source excerpt

The Istio project announced ambient mesh - its new sidecar-less dataplane mode in 2022, and released an alpha implementation in early 2023. Our alpha was focused on proving out the value of the ambient data plane mode under limited configurations and environments. However, the conditions were quite limited. Ambient mode relies on transparently redirecting traffic between workload pods and ztunnel, and the initial mechanism we used to do that conflicted with several categories of 3rd-party Container Networking Interface (CNI) implementations. Through GitHub issues and Slack discussions, we heard our users wanted to be able to use ambient mode in minikube and Docker Desktop, with CNI implementations like Cilium and Calico, and on services that ship in-house CNI implementations like OpenShift and Amazon EKS. Getting broad support for Kubernetes anywhere has become the No. 1 requirement for ambient mesh moving to beta -- people have come to expect Istio to work on any Kubernetes platform and with any CNI implementation. After all, ambient wouldn't be ambient without being all around you! At Solo, we've been integrating ambient mode into our Gloo Mesh product, and came up with an innovative solution to this problem. We decided to upstream our changes in late 2023 to help ambient reach beta faster, so more users can operate ambient in Istio 1.21 or newer, and enjoy the benefits of ambient sidecar-less mesh in their platforms regardless of their existing or preferred CNI implementation. How did we get here? Service meshes and CNIs: it's complicated Istio is a service mesh, and all service meshes by strict definition are not CNI implementations - service meshes require a spec-compliant, primary CNI implementation to be present in every Kubernetes cluster, and rest on top of that. This primary CNI implementation may be provided by your cloud provider (AKS, GKE, and EKS all ship their own), or by third-party CNI implementations like Calico and Cilium. Some service meshes may a

## IstioCon China 2023 wrap-up

DevFeed: [IstioCon China 2023 wrap-up](<https://devfeed.tech/articles/istiocon-china-2023-wrap-up-48768.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2023/istiocon-china/>)

Author: IstioCon China 2023 Program Committee

Published: 2023-09-29T00:00:00Z

Content type: article

Language: en

Sources: [Istio](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [service-mesh](<https://devfeed.tech/topics/service-mesh.md>), [eBPF](<https://devfeed.tech/topics/ebpf.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Latency](<https://devfeed.tech/topics/latency.md>), [Network](<https://devfeed.tech/topics/network.md>), [software-architecture](<https://devfeed.tech/topics/software-architecture.md>)

Tags: [alibaba](<https://devfeed.tech/tags/alibaba.md>), [ambient](<https://devfeed.tech/tags/ambient.md>), [ambient-mesh](<https://devfeed.tech/tags/ambient-mesh.md>), [cloudnativecon](<https://devfeed.tech/tags/cloudnativecon.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [conference](<https://devfeed.tech/tags/conference.md>), [huawei](<https://devfeed.tech/tags/huawei.md>), [intel](<https://devfeed.tech/tags/intel.md>), [istio](<https://devfeed.tech/tags/istio.md>), [istio-day](<https://devfeed.tech/tags/istio-day.md>), [istiocon](<https://devfeed.tech/tags/istiocon.md>), [kubecon](<https://devfeed.tech/tags/kubecon.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [network](<https://devfeed.tech/tags/network.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [services](<https://devfeed.tech/tags/services.md>)

### AI overview

A recap of IstioCon China 2023 in Shanghai, covering the event program, the focus on Istio ambient mesh, and talks about ambient and sidecar coexistence, eBPF-based data planes, traffic redirection, and Istio development.

### Source excerpt

It's great to be able to safely get together in person again. After two years of only running virtual events, we have filled the calendar for 2023. Istio Day Europe was held in April, and Istio Day North America is coming this November. IstioCon is committed to the industry-leading service mesh that provides a platform to explore insights gained from real-world Istio deployments, engage in interactive hands-on activities, and connect with maintainers across the entire Istio ecosystem. Alongside our virtual IstioCon 2023 event, IstioCon China 2023 was held on September 26 in Shanghai, China. Part of the KubeCon + CloudNativeCon + Open Source Summit China, the event was arranged and hosted by the Istio maintainers and the CNCF. We were very proud to have a strong program for IstioCon in Shanghai and pleased to bring together members of the Chinese Istio community. The event was a testament to Istio's immense popularity in the Asia-Pacific ecosystem. IstioCon China 2023 IstioCon China kicked off with an opening keynote from Program Committee members Jimmy Song and Zhonghu Xu. The event was packed with great content, ranging from new features to end user talks, with major focus on the new Istio ambient mesh. IstioCon China 2023, Welcome The welcome speech was followed by a sponsored keynote from Justin Pettit from Google, on "Istio Ambient Mesh as a Managed Infrastructure" which highlighted the importance and priority of the ambient model in the Istio community, especially for our top supporters like Google Cloud. IstioCon China 2023, Google Cloud Sponsored Keynote Perfectly placed after the keynote, Huailong Zhang from Intel and Yuxing Zeng from Alibaba discussed configurations for the co-existence of Ambient and Sidecar: a very relevant topic for existing users who want to experiment with the new ambient model. IstioCon China 2023, Deep Dive into Istio Network Flows and Configurations for the co-existence of Ambient and Sidecar Huawei's new Istio data plane based on e

## Announcing Istio's graduation within the CNCF

DevFeed: [Announcing Istio's graduation within the CNCF](<https://devfeed.tech/articles/announcing-istio-s-graduation-within-the-cncf-48767.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2023/istio-graduates-within-cncf/>)

Author: Craig Box, for the Istio Steering Committee

Published: 2023-07-12T00:00:00Z

Content type: news

Language: en

Sources: [Istio](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [service-mesh](<https://devfeed.tech/topics/service-mesh.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>)

Tags: [ambient-mesh](<https://devfeed.tech/tags/ambient-mesh.md>), [announcement](<https://devfeed.tech/tags/announcement.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [google](<https://devfeed.tech/tags/google.md>), [graduation](<https://devfeed.tech/tags/graduation.md>), [ibm](<https://devfeed.tech/tags/ibm.md>), [intel](<https://devfeed.tech/tags/intel.md>), [istio](<https://devfeed.tech/tags/istio.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [red-hat](<https://devfeed.tech/tags/red-hat.md>), [services](<https://devfeed.tech/tags/services.md>)

### AI overview

Istio has graduated within the Cloud Native Computing Foundation after six years of development and collaboration. The announcement also covers ambient mesh progress, upcoming Kubernetes support, and continued community activity.

### Source excerpt

We are delighted to announce that Istio is now a graduated Cloud Native Computing Foundation (CNCF) project. We would like to thank our TOC sponsors Emily Fox and Nikhita Raghunath, and everyone who has collaborated over the past six years on Istio's design, development, and deployment. As before, project work continues uninterrupted. We were excited to bring ambient mesh to Alpha in Istio 1.18 and are continuing to drive it to production readiness. Sidecar deployments remain the recommended method of using Istio, and our 1.19 release will support a new sidecar container feature in Alpha in Kubernetes 1.28. We have been delighted to welcome Microsoft to our community after their decision to archive the Open Service Mesh project and collaborate together on Istio. As the third most active CNCF project in terms of PRs, and with support from over 20 vendors and dozens of contributing companies, there is simply no better choice for a service mesh. We would like to invite the Istio community to submit a talk to the upcoming virtual IstioCon 2023, the companion full day, in-person event co-located with KubeCon China in Shanghai, or Istio Day co-located with KubeCon NA in Chicago. Watch a video In this video for Techstrong TV, I talk about the history of the project, and what graduation means to us. Words of support from our alumni When we announced our incubation, we mentioned that the journey began with Istio's inception in 2016. One of the great things about collaborative open source projects is that people come and go from employers, but their affiliation with a project can remain. Some of our original contributors founded companies based on Istio; some moved to other companies that support it; and some are still working on it at Google or IBM, six years later. The announcement from the CNCF and blog posts from Intel, Red Hat, Solo.io, Tetrate, VMware and DaoCloud summarize the thoughts and feelings of those working on the project today. We also reached out to some cont

## Introducing Rust-Based Ztunnel for Istio Ambient Service Mesh

DevFeed: [Introducing Rust-Based Ztunnel for Istio Ambient Service Mesh](<https://devfeed.tech/articles/introducing-rust-based-ztunnel-for-istio-ambient-service-mesh-48773.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2023/rust-based-ztunnel/>)

Author: Lin Sun (Solo.io), John Howard (Google)

Published: 2023-02-28T00:00:00Z

Content type: article

Language: en

Sources: [Istio](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [service-mesh](<https://devfeed.tech/topics/service-mesh.md>), [Rust](<https://devfeed.tech/topics/rust.md>), [proxy](<https://devfeed.tech/topics/proxy.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [control-plane](<https://devfeed.tech/topics/control-plane.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [debugging](<https://devfeed.tech/topics/debugging.md>), [Load Balancing](<https://devfeed.tech/topics/load-balancing.md>)

Tags: [ambient](<https://devfeed.tech/tags/ambient.md>), [ambient-mesh](<https://devfeed.tech/tags/ambient-mesh.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [control-plane](<https://devfeed.tech/tags/control-plane.md>), [debugging](<https://devfeed.tech/tags/debugging.md>), [istio](<https://devfeed.tech/tags/istio.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [load-balancing](<https://devfeed.tech/tags/load-balancing.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [proxy](<https://devfeed.tech/tags/proxy.md>), [rust](<https://devfeed.tech/tags/rust.md>), [service-mesh](<https://devfeed.tech/tags/service-mesh.md>), [services](<https://devfeed.tech/tags/services.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [tls](<https://devfeed.tech/tags/tls.md>), [ztunnel](<https://devfeed.tech/tags/ztunnel.md>)

### AI overview

This article introduces ztunnel, a Rust-based per-node proxy for Istio Ambient Mesh. It explains how ztunnel provides workload authentication, mTLS, L4 authorization, traffic proxying, telemetry, and certificate management while forwarding higher-level functionality to waypoint proxies.

### Source excerpt

The ztunnel (zero trust tunnel) component is a purpose-built per-node proxy for Istio ambient mesh. It is responsible for securely connecting and authenticating workloads within ambient mesh. Ztunnel is designed to focus on a small set of features for your workloads in ambient mesh such as mTLS, authentication, L4 authorization and telemetry, without terminating workload HTTP traffic or parsing workload HTTP headers. The ztunnel ensures traffic is efficiently and securely transported to the waypoint proxies, where the full suite of Istio's functionality, such as HTTP telemetry and load balancing, is implemented. Because ztunnel is designed to run on all of your Kubernetes worker nodes, it is critical to keep its resource footprint small. Ztunnel is designed to be an invisible (or "ambient") part of your service mesh with minimal impact on your workloads. Ztunnel architecture Similar to sidecars, ztunnel also serves as an xDS client and CA client: During startup, it securely connects to the Istiod control plane using its service account token. Once the connection from ztunnel to Istiod is established securely using TLS, it starts to fetch xDS configuration as an xDS client. This works similarly to sidecars or gateways or waypoint proxies, except that Istiod recognizes the request from ztunnel and sends the purpose-built xDS configuration for ztunnel, which you will learn more about soon. It also serves as a CA client to manage and provision mTLS certificates on behalf of all co-located workloads it manages. As traffic comes in or goes out, it serves as a core proxy that handles the inbound and outbound traffic (either out-of-mesh plain text or in-mesh HBONE) for all co-located workloads it manages. It provides L4 telemetry (metrics and logs) along with an admin server with debugging information to help you debug ztunnel if needed. Ztunnel architecture Why not reuse Envoy? When Istio ambient service mesh was announced on Sept 7, 2022, the ztunnel was implemented using

## Istio Ambient Service Mesh Merged to Istio's Main Branch

DevFeed: [Istio Ambient Service Mesh Merged to Istio's Main Branch](<https://devfeed.tech/articles/istio-ambient-service-mesh-merged-to-istio-s-main-branch-48761.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2023/ambient-merged-istio-main/>)

Author: John Howard (Google), Lin Sun (Solo.io)

Published: 2023-02-28T00:00:00Z

Content type: release

Language: en

Sources: [Istio](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [service-mesh](<https://devfeed.tech/topics/service-mesh.md>), [releases](<https://devfeed.tech/topics/releases.md>), [software-architecture](<https://devfeed.tech/topics/software-architecture.md>)

Tags: [ambient](<https://devfeed.tech/tags/ambient.md>), [ambient-mesh](<https://devfeed.tech/tags/ambient-mesh.md>), [deploy](<https://devfeed.tech/tags/deploy.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [istio](<https://devfeed.tech/tags/istio.md>), [istioctl](<https://devfeed.tech/tags/istioctl.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [releases](<https://devfeed.tech/tags/releases.md>), [rust](<https://devfeed.tech/tags/rust.md>), [service-mesh](<https://devfeed.tech/tags/service-mesh.md>), [services](<https://devfeed.tech/tags/services.md>)

### AI overview

Istio ambient service mesh has graduated from an experimental branch and merged into Istio's main branch. The announcement describes changes to ztunnel and waypoint components, including a Rust rewrite, simpler waypoint configuration, new istioctl commands, and policy binding improvements, ahead of planned inclusion in Istio 1.18.

### Source excerpt

Istio ambient service mesh was launched in Sept 2022 in an experimental branch, introducing a new data plane mode for Istio without sidecars. Through collaboration with the Istio community, across Google, Solo.io, Microsoft, Intel, Aviatrix, Huawei, IBM and others, we are excited to announce that Istio ambient mesh has graduated from the experimental branch and merged to Istio's main branch! This is a significant milestone for ambient mesh, paving the way for releasing ambient in Istio 1.18 and installing it by default in Istio's future releases. Major Changes from the Initial Launch Ambient mesh is designed for simplified operations, broader application compatibility, and reduced infrastructure cost. The ultimate goal of ambient is to be transparent to your applications and we have made a few changes to make the ztunnel and waypoint components simpler and lightweight. The ztunnel component has been rewritten from the ground up to be fast, secure, and lightweight. Refer to Introducing Rust-Based Ztunnel for Istio Ambient Service Mesh for more information. We made significant changes to simplify waypoint proxy's configuration to improve its debuggability and performance. Refer to Istio Ambient Waypoint Proxy Made Simple for more information. Added the istioctl x waypoint command to help you conveniently deploy waypoint proxies, along with istioctl pc workload to help you view workload information. We gave users the ability to explicitly bind Istio policies such as AuthorizationPolicy to waypoint proxies vs selecting the destination workload. Get involved Follow our getting started guide to try the ambient pre-alpha build today. We'd love to hear from you! To learn more about ambient: Join us in the #ambient and #ambient-dev channel in Istio's slack. Attend the weekly ambient contributor meeting on Wednesdays. Check out the Istio and ztunnel repositories, submit issues or PRs!

## Announcing Istio's acceptance as a CNCF project

DevFeed: [Announcing Istio's acceptance as a CNCF project](<https://devfeed.tech/articles/announcing-istio-s-acceptance-as-a-cncf-project-48752.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2022/istio-accepted-into-cncf/>)

Author: Istio Steering Committee

Published: 2022-09-28T00:00:00Z

Content type: release

Language: en

Sources: [Istio](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [Network](<https://devfeed.tech/topics/network.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>)

Tags: [2016](<https://devfeed.tech/tags/2016.md>), [ambient-mesh](<https://devfeed.tech/tags/ambient-mesh.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [conference](<https://devfeed.tech/tags/conference.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [development](<https://devfeed.tech/tags/development.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [istio](<https://devfeed.tech/tags/istio.md>), [kubecon](<https://devfeed.tech/tags/kubecon.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [project](<https://devfeed.tech/tags/project.md>), [release](<https://devfeed.tech/tags/release.md>), [services](<https://devfeed.tech/tags/services.md>), [steering](<https://devfeed.tech/tags/steering.md>)

### AI overview

Istio has been accepted as an official incubating CNCF project after the CNCF Technical Oversight Committee approved its application. The project will transfer trademarks and build infrastructure to CNCF ownership while continuing work toward the 1.16 release, ambient mesh production readiness, and community governance.

### Source excerpt

We are pleased to share that Istio is now an official incubating CNCF project. In April, Istio applied to become a CNCF project. Today, the TOC announced they have voted to accept our application. This journey began with Istio's inception in 2016. We are grateful for all who have collaborated over the last six years on Istio's design, development, and deployment. We especially appreciate the efforts of TOC sponsor Dave Zolotusky, TAG Network, and the engineering teams at Airbnb, Intuit, Splunk, and WP Engine for sharing their feedback as end users. While project work continues uninterrupted, with the acceptance of Istio, we now will begin the processes of transferring trademarks and build infrastructure to CNCF ownership. We are hard at work on our upcoming 1.16 release, while continuing to collect feedback on ambient mesh and driving it to production readiness. Our project members are currently electing our community representatives to the Steering Committee for the next year. As a CNCF project, we will now be much more visible at KubeCon NA in October. Come to the maintainer session, find us in the project pavilion, or grab an Istio t-shirt at the CNCF Store. Watch our Twitter throughout the conference for more exciting updates!

## Ambient Mode Security Deep Dive

DevFeed: [Ambient Mode Security Deep Dive](<https://devfeed.tech/articles/ambient-mode-security-deep-dive-48746.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2022/ambient-security/>)

Author: Ethan Jackson (Google), Yuval Kohavi (Solo.io), Justin Pettit (Google), Christian Posta (Solo.io)

Published: 2022-09-07T15:00:00Z

Content type: article

Language: en

Sources: [Istio](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [service-mesh](<https://devfeed.tech/topics/service-mesh.md>), [Security](<https://devfeed.tech/topics/security.md>), [software-architecture](<https://devfeed.tech/topics/software-architecture.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [ambient](<https://devfeed.tech/tags/ambient.md>), [ambient-mesh](<https://devfeed.tech/tags/ambient-mesh.md>), [deep-dive](<https://devfeed.tech/tags/deep-dive.md>), [istio](<https://devfeed.tech/tags/istio.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [security](<https://devfeed.tech/tags/security.md>), [service-mesh](<https://devfeed.tech/tags/service-mesh.md>), [services](<https://devfeed.tech/tags/services.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

An in-depth examination of the security implications of Istio ambient mode, a sidecar-less service-mesh data plane. It explains the layered design, including the secure overlay, ztunnel, waypoint proxies, transport security, routing, telemetry, and mTLS, and compares the model with sidecar deployments.

### Source excerpt

We recently announced Istio's new ambient mode, which is a sidecar-less data plane for Istio and the reference implementation of the ambient mesh pattern. As stated in the announcement blog, the top concerns we address with ambient mesh are simplified operations, broader application compatibility, reduced infrastructure costs and improved performance. When designing the ambient data plane, we wanted to carefully balance the concerns around operations, cost, and performance while not sacrificing security or functionality. As the components of ambient mesh run outside of the application pods, the security boundaries have changed - we believe for the better. In this blog, we go into some detail about these changes and how they compare to a sidecar deployment. Layering of ambient mesh data plane To recap, Istio's ambient mode introduces a layered mesh data plane with a secure overlay responsible for transport security and routing, that has the option to add L7 capabilities for namespaces that need them. To understand more, please see the announcement blog and the getting started blog. The secure overlay consists of a node-shared component, the ztunnel, that is responsible for L4 telemetry and mTLS which is deployed as a DaemonSet. The L7 layer of the mesh is provided by waypoint proxies, full L7 Envoy proxies that are deployed per identity/workload type. Some of the core implications of this design include: Separation of application from data plane Components of the secure overlay layer resemble that of a CNI Simplicity of operations is better for security Avoiding multi-tenant L7 proxies Sidecars are still a first-class supported deployment Separation of application and data plane Although the primary goal of ambient mesh is simplifying operations of the service mesh, it does serve to improve security as well. Complexity breeds vulnerabilities and enterprise applications (and their transitive dependencies, libraries, and frameworks) are exceedingly complex and prone to

## Get Started with Istio Ambient Mesh

DevFeed: [Get Started with Istio Ambient Mesh](<https://devfeed.tech/articles/get-started-with-istio-ambient-mesh-48749.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2022/get-started-ambient/>)

Author: Lin Sun (Solo.io), John Howard (Google)

Published: 2022-09-07T14:00:00Z

Content type: tutorial

Language: en

Sources: [Istio](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [service-mesh](<https://devfeed.tech/topics/service-mesh.md>), [istio](<https://devfeed.tech/topics/istio.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [gateway](<https://devfeed.tech/topics/gateway.md>), [kubectl](<https://devfeed.tech/topics/kubectl.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Google](<https://devfeed.tech/topics/google.md>), [IO](<https://devfeed.tech/topics/io.md>)

Tags: [ambient](<https://devfeed.tech/tags/ambient.md>), [ambient-mesh](<https://devfeed.tech/tags/ambient-mesh.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cluster](<https://devfeed.tech/tags/cluster.md>), [cni](<https://devfeed.tech/tags/cni.md>), [core](<https://devfeed.tech/tags/core.md>), [demo](<https://devfeed.tech/tags/demo.md>), [deploy](<https://devfeed.tech/tags/deploy.md>), [don-t](<https://devfeed.tech/tags/don-t.md>), [gateway](<https://devfeed.tech/tags/gateway.md>), [google](<https://devfeed.tech/tags/google.md>), [guide](<https://devfeed.tech/tags/guide.md>), [ingress](<https://devfeed.tech/tags/ingress.md>), [installation](<https://devfeed.tech/tags/installation.md>), [istio](<https://devfeed.tech/tags/istio.md>), [istiod](<https://devfeed.tech/tags/istiod.md>), [kubectl](<https://devfeed.tech/tags/kubectl.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [operations](<https://devfeed.tech/tags/operations.md>), [plugin](<https://devfeed.tech/tags/plugin.md>), [services](<https://devfeed.tech/tags/services.md>), [ztunnel](<https://devfeed.tech/tags/ztunnel.md>)

### AI overview

A step-by-step tutorial for installing Istio Ambient Mesh on a Kubernetes cluster, deploying applications, and understanding how ambient mode uses Istio CNI and ztunnel components to redirect application traffic. It describes supported setup options, including local kind clusters and Google or AWS Cloud.

### Source excerpt

Refer to the latest getting started with ambient mesh doc for updated instructions. Ambient mesh is a new data plane mode for Istio introduced today. Following this getting started guide, you can experience how ambient mesh can simplify your application onboarding, help with ongoing operations, and reduce service mesh infrastructure resource usage. Install Istio with Ambient Mode Download the preview version of Istio with support for ambient mesh. Check out supported environments. We recommend using a Kubernetes cluster that is version 1.21 or newer that has two nodes or more. If you don't have a Kubernetes cluster, you can set up using locally (e.g. using kind as below) or deploy one in Google or AWS Cloud: $ kind create cluster --config=- <<EOF kind: Cluster apiVersion: kind.x-k8s.io/v1alpha4 name: ambient nodes: - role: control-plane - role: worker - role: worker EOF The ambient profile is designed to help you get started with ambient mesh. Install Istio with the ambient profile on your Kubernetes cluster, using the istioctl downloaded above: $ istioctl install --set profile=ambient After running the above command, you'll get the following output that indicates these four components are installed successfully! ✔ Istio core installed ✔ Istiod installed ✔ Ingress gateways installed ✔ CNI installed ✔ Installation complete By default, the ambient profile has the Istio core, Istiod, ingress gateway, zero-trust tunnel agent (ztunnel) and CNI plugin enabled. The Istio CNI plugin is responsible for detecting which application pods are part of the ambient mesh and configuring the traffic redirection between the ztunnels. You'll notice the following pods are installed in the istio-system namespace with the default ambient profile: $ kubectl get pod -n istio-system NAME READY STATUS RESTARTS AGE istio-cni-node-97p9l 1/1 Running 0 29s istio-cni-node-rtnvr 1/1 Running 0 29s istio-cni-node-vkqzv 1/1 Running 0 29s istio-ingressgateway-5dc9759c74-xlp2j 1/1 Running 0 29s istiod-6

## Introducing Ambient Mesh

DevFeed: [Introducing Ambient Mesh](<https://devfeed.tech/articles/introducing-ambient-mesh-48751.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2022/introducing-ambient-mesh/>)

Author: John Howard (Google), Ethan J. Jackson (Google), Yuval Kohavi (Solo.io), Idit Levine (Solo.io), Justin Pettit (Google), Lin Sun (Solo.io)

Published: 2022-09-07T13:00:00Z

Content type: release

Language: en

Sources: [Istio](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [service-mesh](<https://devfeed.tech/topics/service-mesh.md>), [software-architecture](<https://devfeed.tech/topics/software-architecture.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [ambient](<https://devfeed.tech/tags/ambient.md>), [ambient-mesh](<https://devfeed.tech/tags/ambient-mesh.md>), [istio](<https://devfeed.tech/tags/istio.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [services](<https://devfeed.tech/tags/services.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [traffic-management](<https://devfeed.tech/tags/traffic-management.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

Istio introduces Ambient Mesh, a dataplane mode that removes the need for per-application sidecar proxies. It is designed to simplify operations, improve application compatibility, reduce infrastructure cost, and retain Istio features such as zero-trust security, telemetry, and traffic management.

### Source excerpt

Ambient mode is now generally available! Today, we are excited to introduce "ambient mesh", and its reference implementation: a new Istio data plane mode that's designed for simplified operations, broader application compatibility, and reduced infrastructure cost. Ambient mesh gives users the option to forgo sidecar proxies in favor of a data plane that's integrated into their infrastructure, all while maintaining Istio's core features of zero-trust security, telemetry, and traffic management. We are sharing a preview of ambient mesh with the Istio community that we are working to bring to production readiness in the coming months. Istio and sidecars Since its inception, a defining feature of Istio's architecture has been the use of sidecars - programmable proxies deployed alongside application containers. Sidecars allow operators to reap Istio's benefits, without requiring applications to undergo major surgery and its associated costs. Istio's traditional model deploys Envoy proxies as sidecars within the workloads' pods Although sidecars have significant advantages over refactoring applications, they do not provide a perfect separation between applications and the Istio data plane. This results in a few limitations: Invasiveness - Sidecars must be "injected" into applications by modifying their Kubernetes pod spec and redirecting traffic within the pod. As a result, installing or upgrading sidecars requires restarting the application pod, which can be disruptive for workloads. Underutilization of resources - Since the sidecar proxy is dedicated to its associated workload, the CPU and memory resources must be provisioned for worst case usage of each individual pod. This adds up to large reservations that can lead to underutilization of resources across the cluster. Traffic breaking - Traffic capture and HTTP processing, as typically done by Istio's sidecars, is computationally expensive and can break some applications with non-conformant HTTP implementations. While