Networking
Part 1 of 6 · Sidecar & Service MeshSidecar Pattern & Service Mesh — Out-of-Process Proxies, Architecture & Tradeoffs
A sidecar is an out-of-process data plane next to the app: the workload speaks plain HTTP/gRPC, the proxy owns identity, retries, telemetry, and traffic policy. This hub maps mechanics, proxy choices, control-plane discovery, cloud equivalents, and when not to mesh.
- 1Gist
- 2Maps
- 3Q&A
- 4Sandbox
Voice readout needs Web Speech Synthesis in this browser.
Where cross-cutting policy lives
Prefer
Out-of-process sidecar or mesh when many languages need uniform mTLS, retries, and telemetry
The app speaks plain HTTP/gRPC. The proxy next to the pod applies identity, timeouts, retries, and golden signals. Upgrades do not require every language team to bump an SDK.
- One policy surface across polyglot fleets.
- Control plane pushes config; data plane enforces it on the request path.
- Envoy, nginx, and Linkerd-proxy are interchangeable roles with different depth and ops cost.
Alternative
Library everywhere, or a gateway pretending to be a mesh
In-process SDKs win latency and lose language uniformity. An edge gateway owns north-south auth and rate limits — it does not magically secure east-west plaintext.
- Library version skew is the silent failure mode.
- ALB/NLB are strong ingress tools, weak uniform east-west policy.
- Ambient/eBPF trades per-pod isolation for a node blast radius.
Request path the hub exists to name
Each hop is a later lesson. Interviews start at process boundary, not at Envoy YAML.
- 1
Control plane compiles config
Listeners, clusters, routes, endpoints. Depth: xDS-style discovery. - 2
Capture steals the socket
iptables, eBPF, or explicit localhost. Depth: sidecar mechanics. - 3
Data plane applies policy
mTLS, retries, metrics, route match. Depth: Envoy / nginx / Linkerd-proxy. - 4
Peer proxy delivers
East-west, not the public edge. Gateway still owns north-south. - 5
Or skip the mesh
Library, ambient, Lattice, or ALB/NLB. Depth: cloud equivalents and tradeoffs.
Overview
Interview prompt: why put a proxy next to every pod instead of coding retries, mTLS, and metrics into each language? Seniors are graded on process boundaries and blast radius — not on reciting an Envoy filter list.
A sidecar is an out-of-process data plane. The application container stays a business process. The proxy owns identity, retries, observability, and traffic policy. A service mesh is that pattern at fleet scale: many sidecars plus a control plane that discovers endpoints and pushes config until the fleet converges.
This hub is the map. The five sibling pages are the whiteboard depth.
You should be able to:
- Draw app → sidecar → peer sidecar → app, with a control plane pushing config.
- Say in one sentence why a gateway is not a mesh.
- Refuse a mesh when a library or a cloud load balancer already solves the pain.
Where each layer sits
| Layer | Job | Typical miss |
|---|---|---|
| Sidecar / mesh data plane | Per-workload proxy: mTLS, retries, telemetry without app SDKs | CPU/mem tax, capture bugs, dual-container drain |
| Client library | In-process resilience + metrics | Lowest latency; language lock-in and version skew |
| Edge / API gateway | North-south ingress: authz, rate limits, TLS terminate | Not a substitute for east-west policy |
| Ambient / eBPF node agents | Shared or kernel-path datapath | Fewer sidecars; different blast radius |
| Cloud LB only | ALB L7 / NLB L4 for ingress and some discovery | Weak uniform east-west mTLS and retries |
Rule of thumb: many languages + need uniform mTLS/retries/obs → mesh or sidecar. One stack + latency-critical → library. Public API edge → gateway. Small fleet + ALB/NLB enough → skip mesh.
L4 vs L7 choice at the edge is the load-balancing hub and L4 vs L7 proxies. Sidecars are often L7-capable east-west proxies; that does not license a Maglev/P2C recap here.
Architecture (control vs data plane)
Control plane pushes listeners, clusters, routes, and endpoint updates. Data plane applies policy on the request. Telemetry exports from the proxy; business spans still belong in the app.
Flow
- 1
1 Control plane
- next2 Sidecar A config
- 2
2 Sidecar A config
- next3 App A to sidecar
- 3
3 App A to sidecar
- mTLS + retries4 Sidecar B
- 4
4 Sidecar B
- next5 App B
- 5
5 App B
Lesson map
Sidecar Pattern & Service Mesh — Out-of-Process Proxies, Architecture &
A sidecar is an out-of-process data plane next to the app: the workload speaks plain HTTP/gRPC, the proxy owns identity, retries, telemetry, and traffic policy. This hub maps mechanics, proxy choices, control-plane discovery, cloud equivalents, and when not to mesh.
Architecture. Architecture
Select a node to see why it exists, or an edge to see the protocol, direction, effect, and consequence.
Mermaid export
flowchart TB cp["1 Control plane"] sca["2 Sidecar A config"] hop["3 App A to sidecar"] scb["4 Sidecar B"] cp -->|1 Control plane to 2 Sidecar A config| sca sca -->|2 Sidecar A config| hop hop -->|mTLS + retries| scb
Identity after capture is s2s mTLS / SPIFFE — cross-link, do not re-teach OAuth or client-credentials flows.
Decision: mesh vs library vs gateway vs skip
Prefer a decision flow over a product bake-off. Ambient is a later optimization when sidecar density hurts bin-packing.
Decisions
- ?
1 Uniform east-west policy?
- no2 Gateway plus cloud LB
- yes3 Many languages?
- 2
2 Gateway plus cloud LB
- ?
3 Many languages?
- no4 Hop fits p99?
- yes6 Sidecar or mesh
- ?
4 Hop fits p99?
- no5 In-process library
- yes5 Library still ok
- 5
5 In-process library
- 6
5 Library still ok
- 7
6 Sidecar or mesh
Depth: mesh vs library vs gateway and cloud equivalents.
Sandbox: decide mesh vs library vs gateway (Python)
Educational chooser. Not a product picker. Public API with no east-west mTLS mandate stays on a gateway plus cloud LB.
Press Run. Snippets must be self-contained — no network, files, or native modules.
Same idea (TypeScript)
Press Run. Snippets must be self-contained — no network, files, or native modules.
What this cluster covers
- Sidecar mechanics — transparent capture (iptables/eBPF), container lifecycle, drain order.
- Data-plane proxies — what the proxy owns: mTLS, retries, obs, listeners vs clusters.
- Control plane and discovery — xDS-shaped config, endpoints, ACK/NACK, convergence.
- Cloud equivalents — App Mesh, ALB/NLB, VPC Lattice, when not to mesh.
- Mesh vs library vs gateway — latency tax, blast radius, migration.
Health and drain at the LB are health checks. Sticky at the edge is sticky sessions.
Pitfalls
Draw two workloads and a control plane. Where does mTLS terminate? Where do retries live? Now delete the sidecars and put a library in each language — what skews? Put only an ALB in front — what is still plaintext east-west?
Interview Q&A
Why sidecar instead of a library?
Answer
Uniform policy across languages; upgrades without redeploying every app binary; a shared telemetry surface. The cost is extra CPU/mem, an extra hop, capture complexity, and dual-container lifecycle.
What is the cost of a sidecar?
Answer
Per-pod CPU and memory, added latency, iptables/eBPF capture, and start/stop races between app and proxy. Depth: mechanics.
Control plane vs data plane?
Answer
Control plane discovers endpoints and pushes config. Data plane proxies packets and applies policy at request time. Depth: discovery.
Is a mesh required for mTLS?
Answer
No. Libraries or platform TLS can do mTLS. Mesh makes identity and policy consistent at scale. See s2s mTLS / SPIFFE — do not re-teach OAuth here.
Gateway vs mesh?
Answer
Gateway is north-south edge (authz, rate limits, TLS terminate). Mesh is east-west (and often ingress via a gateway API). Different blast radii. Depth: tradeoffs.
Ambient / eBPF vs sidecar?
Answer
Fewer or no per-pod sidecars; node or kernel path; different isolation and upgrade story. You trade per-pod isolation for a node-level blast radius.
When would you not mesh?
Answer
Small fleet, one language, ALB/NLB plus good health checks enough, or a latency budget that forbids the extra hop. Depth: cloud equivalents.
How does this relate to L4 vs L7 load balancing?
Answer
Sidecars are often L7-capable east-west proxies. The public edge may still be ALB (L7) or NLB (L4). Point at the LB cluster — do not re-teach algorithms.
Is Envoy the sidecar?
Answer
No. Envoy is one data-plane example. nginx and Linkerd-proxy play the same role. Depth: proxies.
What must never live only in the app if you chose a mesh?
Answer
Cross-cutting mTLS, uniform retry budgets, and request metrics — otherwise you reintroduce language skew.
How do you migrate toward a mesh?
Answer
Gateway first, libraries on the hottest clients, partial injection for namespaces that need mTLS, full mesh only after golden signals prove the tax is worth it. Depth: tradeoffs.
What does the interviewer want on the whiteboard?
Answer
Process boundary, control vs data plane, capture, convergence, and a clear skip-mesh answer — not a product feature matrix.