Istio intercepts all network traffic between your Kubernetes services and adds security, observability, and traffic control — without changing application code.
What Istio Does
When you install Istio, every pod gets a sidecar proxy (Envoy). All traffic flows through these proxies:
Service A → Envoy Proxy → Network → Envoy Proxy → Service BThe proxies handle: - mTLS — automatic encryption between services - Traffic routing — canary releases, A/B testing, fault injection - Observability — request metrics, distributed tracing, access logs - Resilience — retries, timeouts, circuit breaking
Installation
# Install istioctl
curl -L https://istio.io/downloadIstio | sh -
# Install Istio with the default profile
istioctl install --set profile=default -y
# Enable sidecar injection for a namespace
kubectl label namespace production istio-injection=enabled
# Restart pods to inject sidecars
kubectl rollout restart deployment -n productionAfter this, every new pod in the production namespace gets an Envoy sidecar automatically.
Master this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Automatic mTLS
With Istio installed, all service-to-service traffic is encrypted:
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
name: default
namespace: production
spec:
mtls:
mode: STRICTSTRICT mode means unencrypted traffic is rejected. Every service identity is verified through certificates managed by Istio. No application changes needed.
Traffic Management
Canary Releases
Route 10% of traffic to a new version:
apiVersion: networking.istio.io/v1
kind: VirtualService
metadata:
name: my-app
spec:
hosts: ["my-app"]
http:
- route:
- destination:
host: my-app
subset: stable
weight: 90
- destination:
host: my-app
subset: canary
weight: 10
---
apiVersion: networking.istio.io/v1
kind: DestinationRule
metadata:
name: my-app
spec:
host: my-app
subsets:
- name: stable
labels:
version: v1
- name: canary
labels:
version: v2Gradually shift traffic from 10% to 100% as you gain confidence.
Fault Injection
Test resilience by injecting failures:
apiVersion: networking.istio.io/v1
kind: VirtualService
metadata:
name: payment-service
spec:
hosts: ["payment-service"]
http:
- fault:
delay:
percentage:
value: 10
fixedDelay: 5s
abort:
percentage:
value: 5
httpStatus: 503
route:
- destination:
host: payment-service10% of requests get a 5-second delay. 5% get a 503 error. This tests how your application handles slow or failing dependencies.
Timeouts and Retries
http:
- timeout: 3s
retries:
attempts: 3
perTryTimeout: 1s
retryOn: 5xx,reset,connect-failure
route:
- destination:
host: payment-serviceGet weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Observability
Istio generates metrics for every request without application instrumentation:
# Install Kiali dashboard
kubectl apply -f https://raw.githubusercontent.com/istio/istio/release-1.22/samples/addons/kiali.yaml
# Access the dashboard
istioctl dashboard kialiKiali shows a real-time service graph: which services talk to which, request rates, error rates, and latency — all derived from Envoy proxy data.
The Cost of Istio
Istio adds complexity and resource overhead:
- Memory: Each Envoy sidecar uses 50-100MB
- Latency: 1-3ms per hop (two proxies per request)
- Operational complexity: Control plane, CRDs, certificate management
For a cluster with 100 pods, that is 5-10GB of additional memory just for sidecars.
When to Use Istio
Good fit: - Microservices needing mTLS (compliance, zero-trust) - Complex traffic routing (canary, A/B, blue-green) - Organizations needing service-level observability without code changes - Multi-team clusters where network policies alone are insufficient
Overkill for: - Small clusters (< 20 services) - Monolithic applications - Teams without Kubernetes networking expertise - Environments where Cilium's eBPF mesh is sufficient
Consider Cilium's sidecar-free mesh or Linkerd (lighter weight) if Istio's feature set exceeds your needs.
---
Ready to go deeper? Master Kubernetes networking with hands-on courses at CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Linkerd Lightweight Service Mesh
Linkerd is the lightest Kubernetes service mesh with automatic mTLS, golden metrics, and zero-config retries. Learn how Linkerd compares to Istio and when its.
Cilium Service Mesh Kubernetes
Cilium replaces kube-proxy and sidecar service meshes with eBPF. Learn how Cilium handles networking, observability, and security in Kubernetes.
Grafana Loki Log Aggregation Guide
Grafana Loki indexes log metadata instead of full text, making it cost-effective for Kubernetes log aggregation. Learn how to deploy Loki, query with LogQL.
K3s Lightweight Kubernetes Setup
K3s is a lightweight Kubernetes distribution that runs on edge devices, Raspberry Pis, and VMs with a single binary. Learn how to install K3s, add agents.
Kaniko Rootless Container Builds
Kaniko builds container images inside Kubernetes without Docker daemon or root access. Learn how to use Kaniko in CI/CD pipelines, Tekton, and GitHub Actions.
Karpenter Kubernetes Autoscaler
Karpenter provisions the right Kubernetes nodes in seconds, not minutes. Learn how it replaces Cluster Autoscaler with faster, smarter node provisioning.
Explore topics
Browse more articles on the topics covered here.