{"id":54208,"date":"2019-12-20T00:00:00","date_gmt":"2019-12-19T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/seriya-postov-po-istio-service-mesh"},"modified":"2020-02-18T14:02:12","modified_gmt":"2020-02-18T11:02:12","slug":"seriya-postov-po-istio-service-mesh","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/seriya-postov-po-istio-service-mesh","title":{"rendered":"Series of posts on Istio Service Mesh","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>We are starting a series of posts where we will demonstrate some of the many capabilities of the Istio Service Mesh in conjunction with Red Hat OpenShift and Kubernetes.<\/p>\n<p><img decoding=\"async\" alt=\"Series of posts on Istio Service Mesh\" src=\"\/wp-content\/uploads\/2019\/12\/b7cc06e1451763db78fdf84764af4b69.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nPart one, today: <\/p>\n<ul>\n<li>We will explain the concept of Kubernetes sidecar containers and outline the theme of this series of posts: <b>\"You don't need to change anything in your code\"<\/b>.<\/li>\n<li>Let's introduce the fundamental aspect of Istio \u2013 routing rules. All other capabilities of Istio are built upon these rules, as they allow traffic to be directed to microservices using YAML files external to the service code. We will also consider the Canary Deployment scheme. As a New Year's bonus \u2013 10 interactive sessions on Istio.<\/li>\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nPart two, which will be out soon, will tell you: <\/p>\n<ul>\n<li>How Istio implements Pool Ejection in conjunction with Circuit Breakers and demonstrate how Istio allows you to remove a non-functional or poorly performing pod from the load-balancing scheme.<\/li>\n<li>We will also revisit the Circuit Breaker topic from the first post to see how Istio can be applied here. We will show how to route traffic and handle network errors using YAML configuration files and terminal commands without making any changes to the service code.<\/li>\n<\/ul>\n<p>\nPart three: <\/p>\n<ul>\n<li>A discussion on tracing and monitoring, which are already built-in or easily added to Istio. We will demonstrate how to use tools like Prometheus, Jaeger, and Grafana alongside OpenShift scaling to manage microservice architecture effortlessly.<\/li>\n<li>We will shift from monitoring and error handling to intentionally introducing errors into the system. In other words, we will learn how to perform fault injection without changing the source code, which is crucial for testing \u2014 as altering the code for this purpose risks introducing additional errors.<\/li>\n<\/ul>\n<p>\nFinally, in the concluding post on Istio Service Mesh:<\/p>\n<ul>\n<li>We will venture to the Dark Side. More precisely, we will learn how to use the Dark Launch scheme, where code is deployed and tested directly on production data without affecting system operations. Here, Istio's ability to split traffic comes in handy. The capacity to test on live production data without impacting the operational system is the most convincing method of validation.<\/li>\n<li>Building on Dark Launch, we will show how to use the Canary Deployment model to reduce risks and simplify the introduction of new code. While Canary Deployment itself is not a new concept, Istio allows the implementation of this scheme using simple YAML files.<\/li>\n<li>In conclusion, we will demonstrate how to use Istio Egress to provide access to services for those outside your clusters, leveraging Istio's capabilities when working with the internet.<\/li>\n<\/ul>\n<p>\nSo, let's get started...<\/p>\n<p><b>Monitoring and management tools of Istio \u2013 everything you need for coordinating microservices in a service mesh. <noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/topics\/service-mesh\/\">service mesh<\/a><\/noindex>.<\/b><\/p>\n<h3>What is Istio service mesh<\/h3>\n<p>\nThe service mesh implements features for a set of services, such as traffic monitoring, access control, discovery, security, resilience, and other useful functionalities. Istio allows you to achieve all this without any changes in the service code itself. What\u2019s the magic secret? Istio attaches its proxy to each service in the form of a sidecar container, after which all traffic to that service goes through the proxy, which, guided by predefined policies, decides how, when, and whether this traffic should reach the service. Istio also enables advanced DevOps techniques like canary deployments, circuit breakers, fault injection, and many more.<\/p>\n<h3>How Istio works with containers and Kubernetes<\/h3>\n<p>\nIstio service mesh is a sidecar implementation of everything needed to create and manage microservices: monitoring, tracing, circuit breakers, routing, load balancing, fault injection, retries, timeouts, mirroring, access control, rate limiting, and much more. And while there are many libraries to implement these functions directly in code today, with Istio, you can achieve all of this without changing your code.<\/p>\n<p>According to the sidecar model, Istio runs in a Linux container located in the same <noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/topics\/kubernetes\/\">Kubernetes<\/a><\/noindex>-pod as the controlled service and injects and extracts functionality and information according to the given configuration. Let\u2019s emphasize that this is your own configuration, and it resides outside your code. Therefore, the code becomes much simpler and shorter.<\/p>\n<p>What is also important is that the operational component of microservices is not tied to the code itself, meaning IT specialists can manage their operation smoothly. Indeed, why should a developer be responsible for circuit breakers and fault injection? They should react, yes, but handle and create them? If all of this is removed from the code, programmers can fully concentrate on application functionality. The code itself will also become shorter and simpler.<\/p>\n<h3>Service Mesh<\/h3>\n<p>\nIstio, which implements microservice management functions outside their code, embodies the concept of a Service Mesh. In other words, it is a coordinated group of one or more binaries that form a network of network functions.<\/p>\n<h3>How Istio Works with Microservices<\/h3>\n<p>\nHere\u2019s how sidecar containers work in conjunction with <noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/topics\/kubernetes\/\">Kubernetes<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openshift.org\/minishift\/\">Minishift<\/a><\/noindex> from a bird's-eye view: you launch a Minishift instance, create a project for Istio (let's call it 'istio-system'), and install and run all components related to Istio. Then, as you create projects and pods, you add configuration details to your deployments, and your pods start using Istio. A simplified diagram looks like this:<\/p>\n<p><img decoding=\"async\" alt=\"Series of posts on Istio Service Mesh\" src=\"\/wp-content\/uploads\/2019\/12\/feb36ba35442307a8136c395ccae4fd2.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>You can now modify Istio settings to implement fault injection, support <noindex><a rel=\"nofollow\" href=\"https:\/\/istio.io\/blog\/2017\/0.1-canary.html\">Canary Deployment<\/a><\/noindex> or other Istio capabilities\u2014without ever touching the code of the applications themselves. For instance, if you want to redirect all web traffic from users of your largest client (Foo Corporation) to the new version of the site, all you need to do is create an Istio routing rule that looks for @foocorporation.com in the user ID and performs the corresponding redirect. For all other users, nothing will change. Meanwhile, you can quietly test the new version of the site. And note, you don\u2019t need to involve developers at all.<\/p>\n<h3>Will it be expensive?<\/h3>\n<p>\nNot at all. Istio works quite quickly; it is written in <noindex><a rel=\"nofollow\" href=\"https:\/\/golang.org\/\">Go<\/a><\/noindex> and creates very little overhead. Moreover, any potential loss in online performance is compensated by increased developer productivity. At least in theory: remember that developer time is expensive. As for software costs, Istio is open-source, so it can be obtained and used for free.<\/p>\n<h3>Learn it yourself<\/h3>\n<p>\nThe Red Hat Developer Experience Team has developed a comprehensive practical <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/redhat-developer-demos\/istio-tutorial\">guide<\/a><\/noindex> on Istio (in English). It works on Linux, MacOS, and Windows, with code examples in Java and Node.js.<\/p>\n<h3>10 interactive sessions on Istio<\/h3>\n<p><\/p>\n<h4>Block 1 \u2014 For beginners<\/h4>\n<p>\n<b>Introduction to Istio<\/b><br \/>\n30 minutes <br \/>\nGetting acquainted with Service Mesh, learning to install Istio in an OpenShift Kubernetes cluster.<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/courses\/service-mesh\/istio-introduction\/\">Start<\/a><\/noindex> <\/p>\n<p><b>Deploying microservices in Istio<\/b><br \/>\n30 minutes<br \/>\nUsing Istio to deploy three microservices with Spring Boot and Vert.x.<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/courses\/service-mesh\/deploy-microservices\/\">Start<\/a><\/noindex> <\/p>\n<h4>Block 2 \u2013 Intermediate level <\/h4>\n<p>\n<b>Monitoring and tracing in Istio<\/b><br \/>\n60 minutes <br \/>\nExploring Istio\u2019s built-in monitoring tools, configurable metrics, and OpenTracing through Prometheus and Grafana.<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/courses\/service-mesh\/monitoring-tracing\/\">Start<\/a><\/noindex> <\/p>\n<p><b>Simple routing in Istio<\/b><br \/>\n60 minutes <br \/>\nLearning to manage routing in Istio using simple rules.<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/courses\/service-mesh\/simple-route-rules\/\">Start <\/a><\/noindex><\/p>\n<p><b>Advanced routing rules<\/b><br \/>\n60 minutes <br \/>\nGetting to know smart routing in Istio, access management, load balancing, and rate limiting.<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/courses\/service-mesh\/advanced-routerules\/\">Start<\/a><\/noindex> <\/p>\n<h4>Block 3 \u2013 Advanced user<\/h4>\n<p>\n<b>Fault Injection in Istio<\/b><br \/>\n60 minutes <br \/>\nStudying failure handling scenarios in distributed applications, creating HTTP errors and network delays, and learning to apply chaos engineering for environment recovery.<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/courses\/service-mesh\/fault-injection\/\">Start<\/a><\/noindex> <\/p>\n<p><b>Circuit Breaker in Istio<\/b><br \/>\n30 minutes <br \/>\nInstalling Siege for stress testing websites and learning to ensure backend fault tolerance using retries, circuit breakers, and pool ejection.<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/courses\/service-mesh\/circuit-breaker\/\">Start<\/a><\/noindex> <\/p>\n<p><b>Egress and Istio<\/b><br \/>\n10 minutes <br \/>\nUsing Egress routes to create rules for internal services to interact with external APIs and services.<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/courses\/service-mesh\/egress\/\">Start<\/a><\/noindex> <\/p>\n<p><b>Istio and Kiali<\/b><br \/>\n15 minutes <br \/>\nLearning to use Kiali to get an overview of the service mesh and study request and data flows.<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/courses\/service-mesh\/observe-kiali\/\">Start<\/a><\/noindex> <\/p>\n<p>Mutual TLS in Istio<br \/>\n15 minutes <br \/>\nCreating an Istio Gateway and VirtualService, followed by an in-depth study of mutual TLS (mTLS) and its configurations.<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/courses\/service-mesh\/mtls\/\">Start<\/a><\/noindex> <\/p>\n<h4>Block 3.1 \u2014 Deep dive: Istio Service Mesh for microservices<\/h4>\n<p>\n<img decoding=\"async\" alt=\"Series of posts on Istio Service Mesh\" src=\"\/wp-content\/uploads\/2019\/12\/1a2bb62b0bbd46fa9b42be1ccbfddfa6.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nAbout the book:<\/p>\n<ul>\n<li>What is a service mesh.<\/li>\n<li>The Istio system and its role in microservices architecture.<\/li>\n<li>Using Istio to solve the following challenges:\n<ul>\n<li>Fault tolerance;<\/li>\n<li>Routing;<\/li>\n<li>Chaos testing;<\/li>\n<li>Security;<\/li>\n<li>Telemetry collection using tracing, metrics, and Grafana.<\/li>\n<\/ul>\n<p>\n <\/li>\n<\/ul>\n<p>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/books\/introducing-istio-service-mesh-microservices\/\">Download the book<\/a><\/noindex><\/p>\n<h3>Series of articles on service meshes and Istio<\/h3>\n<p><\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/blog\/2018\/03\/13\/istio-route-rules-service-requests\/\">Istio routing rules: directing service requests where they need to go<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/blog\/2018\/03\/20\/istio-circuit-breaker-pool-ejection\/\">Circuit Breakers in Istio: handling Pool Ejection<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/blog\/2018\/03\/27\/istio-circuit-breaker-when-failure-is-an-option\/\">Circuit Breaker in Istio: when failure is an option<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/blog\/2018\/04\/03\/istio-tracing-monitoring\/\">Tracing and monitoring in Istio: where everything is headed and how fast<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/blog\/2018\/04\/10\/istio-chaos-engineering\/\">Chaos engineering in Istio: it was intended this way<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/blog\/2018\/04\/17\/istio-dark-launch-secret-services\/\">Dark Launch in Istio: secret services<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/blog\/2018\/04\/24\/istio-smart-canary-launch\/\">Canary Deployment in Istio: simplifying rollout<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/blog\/2018\/05\/01\/istio-egress-exit-through-the-gift-shop\/\">Istio Egress: exiting through a souvenir shop<\/a><\/noindex><\/li>\n<\/ul>\n<p><\/p>\n<h3>Try it for yourself<\/h3>\n<p>\nThis series of posts does not aim to provide a deep dive into the world of Istio. We just want to introduce you to the concept and perhaps inspire you to try Istio on your own. You can do this completely for free, and Red Hat provides all the necessary tools to start mastering OpenShift, Kubernetes, Linux containers, and Istio, specifically: <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openshift.com\/products\/container-platform\/trial\/\">Red Hat Developer OpenShift Container Platform<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/redhat-developer-demos\/istio-tutorial\">our guide on Istio<\/a><\/noindex> and other resources on our <noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/topics\/service-mesh\/\">microsite for Service Mesh<\/a><\/noindex>. Don\u2019t wait, start today!<\/p>\n<h3>Istio routing rules: directing service requests where they need to go<\/h3>\n<p>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/products\/openshift\/overview\/\">OpenShift<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/topics\/kubernetes\/\">Kubernetes<\/a><\/noindex> effectively handle requests to <noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/topics\/microservices\/\">microservices<\/a><\/noindex> being routed to the appropriate pods. This is one of the goals of Kubernetes \u2013 routing and load balancing. But what if you need more granular and sophisticated routing? For example, to use two versions of a microservice simultaneously. How can Istio Route Rules help here?<\/p>\n<p>Routing rules are the rules that actually define the routing choice. Regardless of the complexity level of the system, the overall principle of these rules remains simple: requests are routed based on specific parameters and HTTP header values. <br \/>\nLet\u2019s look at examples: <\/p>\n<h3>Kubernetes by default: trivial \"50-50\"<\/h3>\n<p>\nIn our example, we will show how to use two versions of a microservice, which we will call v1 and v2, simultaneously in OpenShift. Each version runs in its own Kubernetes pod, and by default, evenly balanced round-robin routing operates here. Each pod receives its share of requests based on the number of instances of its microservice, in other words, replicas. Istio allows you to manually change this balance.<\/p>\n<p>Suppose we have deployed two versions of our recommendation service on OpenShift, recommendation-v1 and recommendation-v2.<br \/>\nFigure 1 shows that when each service is represented by a single instance, requests alternate evenly between them: 1-2-1-2-... This is how Kubernetes routing works by default:<\/p>\n<p><img decoding=\"async\" alt=\"Series of posts on Istio Service Mesh\" src=\"\/wp-content\/uploads\/2019\/12\/93b00e4845ba930ca4d718b59629377e.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<h3>Weighted distribution between versions<\/h3>\n<p>\nFigure 2 shows what will happen if the number of replicas for the v2 service is increased from one to two (this is done using the command oc scale \u2014replicas=2 deployment\/recommendation-v2). As we can see, requests between v1 and v2 are now distributed in a \"one to three\" ratio: 1-2-2-1-2-2\u2026:<\/p>\n<p><img decoding=\"async\" alt=\"Series of posts on Istio Service Mesh\" src=\"\/wp-content\/uploads\/2019\/12\/a432b1cea0e297c99b041137d33fc107.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<h3>Version ignoring with Istio<\/h3>\n<p>\nIstio makes it easy to change the distribution of requests in the desired way. For example, to send all traffic only to recommendation-v1 using the following Istio yaml file:<\/p>\n<p><img decoding=\"async\" alt=\"Series of posts on Istio Service Mesh\" src=\"\/wp-content\/uploads\/2019\/12\/db4190d495fb6dcc7c50cb8d28a7ef58.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>Take note of the following: pods are selected according to labels. In our example, the label v1 is used. The parameter \"weight: 100\" means that 100% of the traffic will be routed to all pods of the service that have the v1 label.<\/p>\n<h3>Directive distribution between versions (Canary Deployment)<\/h3>\n<p>\nNext, using the weight parameter, we can direct traffic to both pods, ignoring the number of instances of microservices running in each of them. For example, here we are directing 90% of the traffic to v1 and 10% to v2:<\/p>\n<p><img decoding=\"async\" alt=\"Series of posts on Istio Service Mesh\" src=\"\/wp-content\/uploads\/2019\/12\/1a28e76ea7d8306fbefecefaad34c931.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<h3>Separate routing for mobile users<\/h3>\n<p>\nIn conclusion, let\u2019s show how to force route mobile users\u2019 traffic to service v2, while directing all others to v1. For this, we analyze the user-agent value in the request header using regular expressions:<\/p>\n<p><img decoding=\"async\" alt=\"Series of posts on Istio Service Mesh\" src=\"\/wp-content\/uploads\/2019\/12\/efab7f92a1bcfc7e23ae279de57c738e.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<h3>Now it\u2019s your turn<\/h3>\n<p>\nThe example with regular expressions for analyzing headers should motivate you to seek out your own options for applying Istio routing rules. Moreover, the possibilities here are quite extensive, as header values can be formed in the application source code.<\/p>\n<h3>And remember, it\u2019s Ops, not Dev<\/h3>\n<p>\nEverything we've shown in the examples above is done without the slightest changes to the source code, except in cases where special request headers need to be formed. Istio will be useful for both developers, who can apply it during the testing phase, and IT system operations specialists, who will find it very helpful in production.<\/p>\n<p>So let's repeat the main theme of this series of posts: <b>you don\u2019t need to change anything in your code<\/b>There is no need to gather new images or launch new containers. All of this is implemented outside the code.<\/p>\n<h3>Ignite your imagination<\/h3>\n<p>\nJust imagine the opportunities that analyzing headers with regular expressions opens up. Want to redirect your biggest client to a special version of your <noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/topics\/microservices\/\">microservices<\/a><\/noindex>? \u041b\u0435\u0433\u043a\u043e! \u041d\u0443\u0436\u043d\u0430 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u0430\u044f \u0432\u0435\u0440\u0441\u0438\u044f \u0434\u043b\u044f \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0430 Chrome? \u041d\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430! \u0412\u044b \u043c\u043e\u0436\u0435\u0442\u0435 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a \u043f\u0440\u0430\u043a\u0442\u0438\u0447\u0435\u0441\u043a\u0438 \u043f\u043e \u043b\u044e\u0431\u043e\u0439 \u0435\u0433\u043e \u0445\u0430\u0440\u0430\u043a\u0442\u0435\u0440\u0438\u0441\u0442\u0438\u043a\u0435.<\/p>\n<h3>Try it for yourself<\/h3>\n<p>\nReading about Istio, Kubernetes, and OpenShift is one thing, but why not get hands-on experience? The team <noindex><a rel=\"nofollow\" href=\"https:\/\/developers.redhat.com\/\">Red Hat Developer Program<\/a><\/noindex> has prepared a detailed guide (in English) that will help you get up to speed with these technologies as quickly as possible. The guide is also 100% open source and is available to the public. The file works on macOS, Linux, and Windows, and the source code is available in Java and node.js versions (other languages will be available soon). Just open the corresponding git repository in your browser. <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/redhat-developer-demos\/istio-tutorial\">Red Hat Developer Demo<\/a><\/noindex>.<\/p>\n<h3>In the next post: elegantly addressing issues<\/h3>\n<p>\nToday, you saw what Istio's routing rules are capable of. Now imagine all of that applied to error handling. That\u2019s what we will discuss in the next post.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/redhatrussia\/blog\/481182\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041c\u044b \u043d\u0430\u0447\u0438\u043d\u0430\u0435\u043c \u0441\u0435\u0440\u0438\u044e \u043f\u043e\u0441\u0442\u043e\u0432, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043f\u0440\u043e\u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0438\u0440\u0443\u0435\u043c \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0438\u0437 \u043c\u043d\u043e\u0436\u0435\u0441\u0442\u0432\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0435\u0439 \u0441\u0435\u0440\u0432\u0438\u0441\u043d\u043e\u0439 \u0441\u0435\u0442\u043a\u0438 Istio Service Mesh \u0432 \u0441\u043e\u0447\u0435\u0442\u0430\u043d\u0438\u0438 \u0441 Red Hat OpenShift \u0438 Kubernetes. \u0427\u0430\u0441\u0442\u044c \u043f\u0435\u0440\u0432\u0430\u044f, \u0441\u0435\u0433\u043e\u0434\u043d\u044f\u0448\u043d\u044f\u044f: \u041e\u0431\u044a\u044f\u0441\u043d\u0438\u043c \u043a\u043e\u043d\u0446\u0435\u043f\u0446\u0438\u044e sidecar-\u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043e\u0432 Kubernetes \u0438 \u0441\u0444\u043e\u0440\u043c\u0443\u043b\u0438\u0440\u0443\u0435\u043c \u043b\u0435\u0439\u0442\u043c\u043e\u0442\u0438\u0432 \u044d\u0442\u043e\u0439 \u0441\u0435\u0440\u0438\u0438 \u043f\u043e\u0441\u0442\u043e\u0432: \u00ab\u0432\u0430\u043c \u043d\u0435 \u043d\u0430\u0434\u043e \u043d\u0438\u0447\u0435\u0433\u043e \u043c\u0435\u043d\u044f\u0442\u044c \u0432 \u0441\u0432\u043e\u0435\u043c \u043a\u043e\u0434\u0435\u00bb. \u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u043c \u043e\u0441\u043d\u043e\u0432\u043e\u043f\u043e\u043b\u0430\u0433\u0430\u044e\u0449\u0443\u044e \u0432\u0435\u0449\u044c Istio \u2013 \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0446\u0438\u0438. \u041d\u0430 \u043d\u0438\u0445 \u0441\u0442\u0440\u043e\u044f\u0442\u0441\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-54208","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041c\u044b \u043d\u0430\u0447\u0438\u043d\u0430\u0435\u043c \u0441\u0435\u0440\u0438\u044e \u043f\u043e\u0441\u0442\u043e\u0432, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043f\u0440\u043e\u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0438\u0440\u0443\u0435\u043c \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0438\u0437 \u043c\u043d\u043e\u0436\u0435\u0441\u0442\u0432\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0435\u0439 \u0441\u0435\u0440\u0432\u0438\u0441\u043d\u043e\u0439 \u0441\u0435\u0442\u043a\u0438 Istio Service Mesh \u0432 \u0441\u043e\u0447\u0435\u0442\u0430\u043d\u0438\u0438 \u0441 Red Hat OpenShift \u0438 Kubernetes.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/seriya-postov-po-istio-service-mesh\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0421\u0435\u0440\u0438\u044f \u043f\u043e\u0441\u0442\u043e\u0432 \u043f\u043e Istio Service Mesh | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041c\u044b \u043d\u0430\u0447\u0438\u043d\u0430\u0435\u043c \u0441\u0435\u0440\u0438\u044e \u043f\u043e\u0441\u0442\u043e\u0432, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043f\u0440\u043e\u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0438\u0440\u0443\u0435\u043c \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0438\u0437 \u043c\u043d\u043e\u0436\u0435\u0441\u0442\u0432\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0435\u0439 \u0441\u0435\u0440\u0432\u0438\u0441\u043d\u043e\u0439 \u0441\u0435\u0442\u043a\u0438 Istio Service Mesh \u0432 \u0441\u043e\u0447\u0435\u0442\u0430\u043d\u0438\u0438 \u0441 Red Hat OpenShift \u0438 Kubernetes.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/seriya-postov-po-istio-service-mesh\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-12-19T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:02:12+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Series of posts on Istio Service Mesh | ProHoster","description":"We are starting a series of posts where we will demonstrate some of the many capabilities of the Istio Service Mesh in conjunction with Red Hat OpenShift and Kubernetes.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/seriya-postov-po-istio-service-mesh","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0421\u0435\u0440\u0438\u044f \u043f\u043e\u0441\u0442\u043e\u0432 \u043f\u043e Istio Service Mesh | ProHoster","og:description":"\u041c\u044b \u043d\u0430\u0447\u0438\u043d\u0430\u0435\u043c \u0441\u0435\u0440\u0438\u044e \u043f\u043e\u0441\u0442\u043e\u0432, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043f\u0440\u043e\u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0438\u0440\u0443\u0435\u043c \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0438\u0437 \u043c\u043d\u043e\u0436\u0435\u0441\u0442\u0432\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0435\u0439 \u0441\u0435\u0440\u0432\u0438\u0441\u043d\u043e\u0439 \u0441\u0435\u0442\u043a\u0438 Istio Service Mesh \u0432 \u0441\u043e\u0447\u0435\u0442\u0430\u043d\u0438\u0438 \u0441 Red Hat OpenShift \u0438 Kubernetes.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/seriya-postov-po-istio-service-mesh","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-12-19T21:00:00+00:00","article:modified_time":"2020-02-18T11:02:12+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"54208","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 10:27:27","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:10:32","updated":"2026-01-24 10:27:27","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/54208","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=54208"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/54208\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=54208"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=54208"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=54208"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}