Project Lightning Talk: What's New in Istio? - Mitch Connors, Maintainer

Mitch Connors, Maintainer

KubeCon + CloudNativeCon Europe 2025 · Project Lightning Talk

Overview

This talk, initially framed as "What's New in Istio?", quickly pivots to a more fundamental exploration: "What is Istio?". Delivered by Mitch Connors, a Principal Engineer at Microsoft and a long-standing maintainer of the Istio project for approximately seven years, the session serves as an accessible introduction for individuals new to the service mesh paradigm. Recognizing that only about 20% of the audience were current Istio users, Connors tailored his presentation to demystify Istio, articulate its core value proposition, and guide newcomers on how to get started with this widely adopted cloud-native technology.

Watch on YouTube

Visual summary for Project Lightning Talk: What's New in Istio? - Mitch Connors, Maintainer by Mitch Connors, Maintainer
Visual summary for Project Lightning Talk: What's New in Istio? - Mitch Connors, Maintainer by Mitch Connors, Maintainer

Key moments

  1. 0:00 Introduction and redefining the talk's focus
  2. 0:40 What is a service mesh? Core functions
  3. 1:00 Key security features of a service mesh
  4. 2:00 Understanding service mesh connectivity and routing
  5. 3:20 Why Istio? The power of its community
  6. 4:05 Istio's new ambient mode for ease of use
  7. 4:25 Quick start: Istio's simplified onboarding process
  8. 4:45 How to learn more about Istio and resources

Project Lightning Talk: What's New in Istio? - Mitch Connors, Maintainer

Speakers: Mitch Connors, Principal Engineer, Microsoft; Maintainer

Conference: KubeCon EU

YouTube: https://www.youtube.com/watch?v=B7lpXPZPFoI

Overview

This talk, initially framed as "What's New in Istio?", quickly pivots to a more fundamental exploration: "What is Istio?". Delivered by Mitch Connors, a Principal Engineer at Microsoft and a long-standing maintainer of the Istio project for approximately seven years, the session serves as an accessible introduction for individuals new to the service mesh paradigm. Recognizing that only about 20% of the audience were current Istio users, Connors tailored his presentation to demystify Istio, articulate its core value proposition, and guide newcomers on how to get started with this widely adopted cloud-native technology.

The talk emphasizes Istio's foundational role in managing connectivity, enhancing security, and providing deep observability for modern distributed applications. Connors meticulously breaks down these three pillars, detailing how Istio facilitates secure, resilient, and transparent communication between various software components, whether they reside in pods, virtual machines, or WebAssembly (WASM) containers. A significant focus is placed on Istio's robust community-driven development and the recent advancements, such as Ambient mode, that dramatically improve its ease of use and operational efficiency, making it an increasingly attractive option for organizations navigating complex microservices architectures.

This article delves into the technical specifics and strategic advantages presented by Connors, highlighting why Istio remains a critical component in the cloud-native ecosystem. It will explore the nuanced security mechanisms like mutual TLS and cryptographic identity, the sophisticated traffic management capabilities, and the comprehensive telemetry that Istio provides out-of-the-box. Furthermore, it will examine the implications of these features for both developers and security professionals, offering insights into how Istio can streamline operations, bolster security postures, and accelerate the adoption of resilient, observable microservices.

Background

▶ Watch: Introduction and redefining the talk's focus (0:00)

The proliferation of microservices architectures and containerization, particularly within Kubernetes environments, has introduced significant operational complexities. While these architectures offer agility and scalability, they also present challenges in managing inter-service communication, enforcing security policies, and gaining visibility into application behavior. This is the problem space that service meshes are designed to address. A service mesh acts as a dedicated infrastructure layer for handling service-to-service communication, abstracting away much of the complexity from individual applications.

Before the advent of service meshes, developers often had to implement cross-cutting concerns like traffic management, security, and observability directly within their application code. This led to duplicated effort, inconsistent implementations, and tightly coupled services. Alternatively, network-level solutions like traditional firewalls and load balancers were often too coarse-grained or difficult to dynamically configure in highly ephemeral containerized environments. The need for a more programmatic, application-aware network layer became apparent.

Istio emerged as a leading service mesh solution within the Cloud Native Computing Foundation (CNCF) ecosystem. It builds upon existing cloud-native primitives, notably Kubernetes, to provide a consistent and powerful way to manage the network interactions of microservices. While other service mesh technologies exist within the CNCF landscape, Istio distinguishes itself through its comprehensive feature set, robust community support, and continuous innovation aimed at improving usability and performance. Its core objective is to ensure that all traffic between software components—whether they are Kubernetes pods, virtual machines, or emerging technologies like WASM containers—is managed with consistent policies for connectivity, security, and observability, thereby enabling developers to focus on business logic rather than infrastructure concerns.

Key Findings

▶ Watch: Key security features of a service mesh (1:00)

Mitch Connors' talk effectively articulates Istio's core value proposition by breaking down its functionalities into three primary pillars: security, connectivity, and observability. Beyond these technical capabilities, a significant "key finding" highlighted by Connors is the strength of the Istio project's community and its ongoing commitment to ease of use, particularly through the introduction of Ambient mode.

Security

Istio's security features are designed to provide a robust, automated, and scalable solution for protecting inter-service communication:

  • FIPS Compliant Encryption: All traffic between services within the mesh is encrypted using FIPS-compliant algorithms, ensuring a high standard of cryptographic security.
  • Automated PKI Management: Istio automates the rotation of PKI (Public Key Infrastructure) credentials, eliminating the need for manual certificate management and reducing the risk of expired or compromised certificates. It integrates with existing PKI solutions, offering flexibility.
  • Cryptographic Identity: Crucially, Istio uses certificates to uniquely identify both the client and server for every connection. This cryptographic identity replaces reliance on ephemeral IP addresses for policy enforcement, providing a more secure and scalable authorization model. Data planes can simply check client and server certificates against allowed connection lists, rather than managing complex IP-based rules.
  • Scalable Policy Enforcement: By leveraging cryptographic identities, Istio enables scalable authorization policies, ensuring that only authorized services can communicate, regardless of their network location or IP address.

Connectivity

Istio offers sophisticated controls over how services connect and interact:

  • L4/L7 Load Balancing: It provides advanced Layer 4 (TCP) and Layer 7 (HTTP) load balancing capabilities, including weighted round-robin, least connections, and other algorithms, allowing fine-grained control over traffic distribution.
  • HTTP Attribute-Based Routing: Services can route traffic based on HTTP attributes such as paths, headers, or query parameters. This is particularly powerful for implementing advanced deployment strategies like canary releases or A/B testing, extending ingress-like routing capabilities to internal service-to-service communication.
  • Unified Traffic Control: Istio manages ingress (traffic entering the cluster), egress (traffic leaving the cluster), and east-west (traffic within the cluster) traffic, providing a consistent control plane for all network flows.
  • Advanced Traffic Patterns: It supports advanced patterns like traffic mirroring for debugging, automated retries to improve resilience, and fault injection for chaos engineering, enabling more robust and reliable applications.
  • Multi-cluster Routing and Discovery: Istio facilitates seamless communication and service discovery across multiple Kubernetes clusters, supporting hybrid and multi-cloud deployments.

Observability

Comprehensive telemetry is a cornerstone of Istio's offering:

  • Request Telemetry: It automatically collects telemetry data for every request within the mesh, including metrics, logs, and traces.
  • Configurable Access Logs: Detailed access logs provide insights into traffic patterns and potential issues, with configurable levels of detail.
  • Distributed Trace Sampling: Istio supports distributed tracing, enabling developers to visualize the full path of a request through multiple services, with configurable sampling rates to manage overhead. All of this comes "more or less out of the box."

Why Choose Istio?

Beyond its technical features, Connors highlights two significant differentiators for Istio:

  • Robust Community: Istio boasts an exceptionally strong and diverse community. The steering committee comprises nine different companies, and the technical oversight committee includes three. Over the past two years, more than 25 different companies have contributed over 100 pull requests to the project. This broad corporate backing ensures the project's longevity and continued innovation, emphasizing that users are "betting on the community," not a single vendor.
  • Ease of Use (with Ambient Mode): Addressing a historical perception of complexity, Connors underscores that Istio's ease of use has significantly improved. The new Ambient mode, generally available since November, allows users to run "only the proxies you need." This significantly simplifies onboarding: users install Istio with one command, label desired namespaces or pods with another, and applications are immediately captured without requiring restarts. This innovation dramatically reduces the operational overhead traditionally associated with service meshes.

Technical Deep Dive

▶ Watch: Why Istio? The power of its community (3:20)

Istio's architectural design revolves around a control plane and a data plane. The control plane manages and configures the proxies that make up the data plane, which intercepts and controls all network traffic. Traditionally, the data plane was primarily composed of Envoy proxy sidecars injected into every application pod. However, with the introduction of Ambient mode, this model has evolved to offer more flexible and efficient deployment options.

Data Plane Evolution: Sidecars to Ambient Mode

In the traditional sidecar model, an Envoy proxy runs alongside each application container within the same pod. This proxy intercepts all incoming and outgoing network traffic for that application, applying Istio's policies for security, routing, and observability. While powerful, this model can introduce operational overhead due to the resource consumption of numerous proxies and the need for pod restarts during injection or upgrades.

Ambient mode represents a significant technical advancement, addressing these challenges by offering a sidecar-less approach for the majority of use cases. Instead of a proxy per application instance, Ambient mode introduces two new components:

  1. ztunnel (zero-trust tunnel): This lightweight, per-node proxy handles Layer 4 (TCP) traffic. It's responsible for establishing mTLS (mutual TLS) connections, enforcing L4 authorization policies, and securely tunneling traffic between workloads. By operating at the node level, ztunnel eliminates the need for sidecars for basic security, reducing resource consumption and simplifying application deployment. It handles the FIPS-compliant encryption and automated PKI rotation, ensuring all connections are cryptographically identified.
  2. waypoint proxy: For advanced Layer 7 (HTTP/gRPC) features like HTTP attribute-based routing, traffic mirroring, or fault injection, a waypoint proxy is deployed. These proxies are typically deployed per namespace or per service account, rather than per pod. Workloads in Ambient mode that require L7 capabilities can direct their traffic through a waypoint proxy, which then applies the sophisticated L7 policies. This allows users to opt-in to L7 features only where needed, providing a more granular and efficient resource allocation.

This architectural shift in Ambient mode means that security (mTLS, cryptographic identity, L4 policies) is applied broadly and efficiently at the node level via ztunnel, while advanced traffic management (L7 policies) can be selectively enabled via waypoint proxies. This "only running the proxies you need" philosophy simplifies Istio's footprint and reduces friction for adoption.

Security Mechanisms in Detail

Istio's security model is built on the principle of zero trust, where no service is inherently trusted.

  • Mutual TLS (mTLS): All service-to-service communication within the mesh is automatically upgraded to mTLS. This means both the client and server cryptographically verify each other's identity before establishing a connection. The ztunnel in Ambient mode (or the Envoy sidecar in traditional mode) handles the TLS handshake and certificate management transparently to the application.
  • Istio Certificate Authority (CA): Istio includes its own CA, which issues short-lived, frequently rotated X.509 certificates to each workload. These certificates embed SPIFFE (Secure Production Identity Framework for Everyone) identities, providing a strong, cryptographically verifiable identity for each service (e.g., spiffe://cluster.local/ns/default/sa/my-service-account).
  • Authorization Policies: Instead of relying on network-level constructs like IP addresses, Istio's authorization policies leverage these cryptographic identities. A policy can specify that "service A (identified by its SPIFFE ID) is allowed to call service B (identified by its SPIFFE ID) on port X with HTTP method Y." This decouples authorization from network topology, making policies more robust, portable, and scalable. The data plane proxies (ztunnel or Envoy) inspect the client and server certificates for each connection and enforce these policies in real-time.

Connectivity and Traffic Management

Istio's connectivity features provide granular control over the flow of requests:

  • Virtual Services and Destination Rules: These custom resources are central to Istio's traffic management. Virtual Services define how to route traffic to a set of destination workloads based on various criteria (e.g., HTTP headers, paths, weights). Destination Rules define policies that apply to traffic after it has been routed by a Virtual Service (e.g., load balancing algorithms, connection pool settings, outlier detection).
  • Ingress and Egress Gateways: Istio provides dedicated gateway components (often based on Envoy) to manage traffic entering (ingress) and leaving (egress) the service mesh. This ensures a consistent policy enforcement point for all external communications.
  • Fault Tolerance: Features like automatic retries (re-sending failed requests), circuit breaking (preventing cascading failures by limiting requests to unhealthy services), and timeout configurations enhance application resilience.
  • Traffic Mirroring: For debugging or testing new versions, Istio can mirror a percentage of live traffic to a separate service, allowing real-world testing without impacting production users.
  • Fault Injection: This feature allows developers to inject artificial delays or aborts into specific requests, enabling chaos engineering practices to test application resilience under adverse conditions.

Observability

Istio's observability capabilities are built on standard cloud-native tooling:

  • Metrics: Proxies automatically emit a rich set of metrics (e.g., request rates, latencies, error rates) for every service interaction. These metrics can be collected by Prometheus and visualized in tools like Grafana.
  • Distributed Tracing: Istio integrates with tracing systems like Jaeger or Zipkin. By injecting trace headers into requests and propagating them across services, Istio allows users to visualize the entire path of a request, identifying bottlenecks or failures across a distributed system. The speaker mentions configurable sampling to manage the volume of trace data.
  • Access Logs: Detailed access logs for each request provide valuable information for debugging, auditing, and security analysis. These logs can be configured to include specific request attributes, aiding in troubleshooting.

The comprehensive nature of Istio's technical features, combined with the simplified deployment model offered by Ambient mode, positions it as a powerful and increasingly user-friendly solution for managing complex microservices environments.

Demo / Proof of Concept

▶ Watch: Istio's new ambient mode for ease of use (4:05)

The talk by Mitch Connors did not include a live demonstration or a detailed proof of concept of Istio's features. Instead, the speaker focused on explaining the core concepts, benefits, and the simplified onboarding process. He did, however, allude to the ease of getting started with Istio's new Ambient mode, stating that users can "install Istio with one command" and then "label whatever namespaces or pods you want captured with another command," after which "you're done." This description serves as a high-level guide to the practical steps involved in initiating an Istio deployment rather than a technical demonstration of its capabilities.

Defensive Implications

▶ Watch: How to learn more about Istio and resources (4:45)

Istio's comprehensive feature set offers significant advantages for security defenders, transforming how security is implemented and managed in cloud-native environments. By abstracting network and security concerns into an infrastructure layer, Istio empowers organizations to build more resilient and secure applications with less effort.

  1. Automated Zero-Trust Security with mTLS: The most profound defensive implication is the automatic enforcement of mutual TLS (mTLS) for all service-to-service communication. This eliminates the need for developers to manually implement TLS within their applications, reducing the attack surface by ensuring all internal traffic is encrypted and authenticated. From a defensive standpoint, this means:
  • Reduced Lateral Movement Risk: Encrypted internal traffic makes it significantly harder for attackers to sniff sensitive data if they gain a foothold within the network.
  • Authenticated Service Identity: mTLS ensures that only legitimate, cryptographically verified services can communicate, preventing unauthorized services from impersonating others. This is a foundational element of a zero-trust architecture.
  • Simplified Compliance: For regulated industries, the automatic FIPS-compliant encryption and robust identity management can significantly aid in meeting compliance requirements related to data in transit and access control.
  1. Granular, Cryptographic Identity-Based Authorization: Istio shifts authorization from fragile, IP-based network rules to strong, cryptographically verifiable service identities. This has several defensive benefits:
  • Least Privilege Enforcement: Defenders can define precise policies (e.g., "Service A can only call method X on Service B") based on service identity, ensuring that services only have access to what they explicitly need, even within the same subnet.
  • Resilience to Network Changes: Policies remain valid even if service IPs or network topologies change, reducing configuration drift and potential security gaps.
  • Improved Auditability: Authorization decisions are tied to specific service identities, providing clearer audit trails of who (which service) accessed what.
  1. Unified Traffic Control and Network Segmentation: By managing ingress, egress, and east-west traffic, Istio provides a single control plane for enforcing network boundaries and segmentation.
  • Consistent Policy Enforcement: Security policies are applied consistently across all traffic types, reducing the chance of misconfigurations at different network layers.
  • Micro-segmentation: Istio enables fine-grained network segmentation down to the individual service level, far beyond what traditional network firewalls can achieve in dynamic cloud environments. This limits the blast radius of a compromise.
  • Egress Control: Strict egress policies can prevent compromised internal services from communicating with unauthorized external destinations (e.g., command-and-control servers).
  1. Enhanced Observability for Threat Detection: The out-of-the-box telemetry (metrics, logs, distributed traces) provided by Istio is invaluable for security monitoring and incident response.
  • Anomaly Detection: Defenders can monitor request rates, error rates, and latency for deviations that might indicate an attack (e.g., a sudden spike in requests to an unusual endpoint, an increase in authentication failures).
  • Incident Response and Forensics: Detailed access logs and distributed traces provide critical context for understanding the scope and impact of an incident, allowing security teams to quickly identify affected services and communication paths.
  • Policy Violation Alerts: Istio can be configured to alert on policy violations, providing real-time notification of unauthorized access attempts.
  1. Simplified Security Operations with Ambient Mode: The introduction of Ambient mode directly addresses operational friction, which can often lead to security shortcuts or incomplete deployments.
  • Reduced Overhead: By simplifying proxy deployment and management, Ambient mode makes it easier for organizations to adopt and maintain Istio, ensuring that security features are consistently applied across the entire fleet.
  • Faster Adoption of Security Best Practices: The ease of onboarding means security teams can enforce mTLS and policy enforcement more broadly and rapidly, improving the overall security posture without significant developer burden.

In essence, Istio transforms security from a manual, application-specific concern into an automated, infrastructure-level capability. This empowers defenders to establish a robust, zero-trust security perimeter around their microservices, significantly enhancing their ability to prevent, detect, and respond to threats in complex cloud-native environments.

Key Takeaways

  • Comprehensive Service Mesh: Istio provides a unified platform for managing connectivity, security, and observability across diverse software components (pods, VMs, WASM containers) in distributed systems.
  • Automated Zero-Trust Security: It offers robust, automated security features including FIPS-compliant mTLS encryption for all traffic, frequently rotated PKI, and cryptographic identity for services, enabling scalable and precise authorization policies that don't rely on IP addresses.
  • Advanced Traffic Management: Istio enables sophisticated control over traffic flow, including L4/L7 load balancing, HTTP attribute-based routing, ingress/egress/east-west traffic control, and advanced patterns like traffic mirroring, retries, and fault injection.
  • Built-in Observability: Out-of-the-box telemetry provides comprehensive metrics, configurable access logs, and distributed trace sampling for every request, offering critical insights into application behavior and performance.
  • Strong Community and Ecosystem: Istio boasts a vibrant, multi-company community (9 steering committee, 3 TOC companies, 25+ companies contributing 100+ PRs in 2 years), ensuring its continued development, support, and resilience.
  • Enhanced Ease of Use with Ambient Mode: The generally available Ambient mode significantly simplifies Istio's deployment and operation by allowing users to run "only the proxies you need," reducing resource overhead and enabling quick, restart-free onboarding for applications.

About the Speaker(s)

Mitch Connors is a Principal Engineer at Microsoft, bringing a wealth of experience and expertise to the cloud-native ecosystem. More notably, he is a dedicated maintainer of the Istio project, a role he has held for approximately seven years. His long-standing involvement underscores his deep technical knowledge and commitment to the Istio community, positioning him as a respected voice in the service mesh domain. His perspective, as both a corporate contributor and a core maintainer, offers valuable insights into the project's direction and practical application.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This talk, delivered by a core Istio maintainer, effectively demystified the service mesh's critical role in security, connectivity, and observability for cloud-native environments. While serving as an introduction for newcomers, the session critically highlighted the novel 'Ambient mode,' a significant architectural evolution that dramatically simplifies Istio's deployment and reduces operational overhead. The speaker's deep technical expertise and focus on actionable, real-world solutions make this a highly valuable session for anyone grappling with microservices complexity and security.

Heather Calloway (CISO) — STRONG ACCEPT

This introductory talk on Istio, while aimed at newcomers, effectively translates the complexity of service mesh into clear value propositions for security leaders and operators. The emphasis on automated zero-trust security through FIPS-compliant mTLS, cryptographic identity, and granular authorization policies directly addresses critical governance and business risks. The operational simplicity introduced by Ambient mode is particularly compelling, as it removes significant barriers to adopting robust platform-level security, enabling organizations to achieve consistent security posture without excessive operational overhead. This isn't just a technical overview; it's a clear signal for…

→ Top-rated talks at KubeCon + CloudNativeCon Europe 2025

All talks from KubeCon + CloudNativeCon Europe 2025