DVO-410
Advanced
⏱ 8 weeks
Service Meshes: Consul, Linkerd & Istio
Master service meshes end to end — from sidecars and mTLS to running a zero-trust, multi-cluster mesh in production. Learn all three (Consul, Linkerd, Istio) deeply, then how to choose, secure, operate and scale them. 100+ slides, hands-on labs, beginner to super-expert.
Prerequisites: DVO-201 Docker & Kubernetes
Syllabus
Module 1 — Service mesh fundamentals
- Sidecars & the data/control plane
- Automatic mTLS & zero-trust
- L4 vs L7 and the proxy (Envoy vs micro-proxy)
- Connect · Secure · Observe
- The honest costs & when NOT to use a mesh
Module 2 — Consul
- Service discovery, health & KV
- Connect mesh, SPIFFE identity & the CA
- Intentions (zero-trust authorization)
- L7 traffic: router / splitter / resolver
- Gateways, multi-datacenter & cluster peering
- Hybrid VM + Kubernetes meshing
Module 3 — Linkerd
- The minimal, secure-by-default mesh
- Automatic mTLS & ServiceAccount identity
- Golden metrics & live `tap`
- Retries (budgets), splits & Flagger canaries
- Authorization policy & multicluster
Module 4 — Istio
- istiod, Envoy & xDS
- VirtualService / DestinationRule / Gateway / ServiceEntry
- PeerAuthentication, AuthorizationPolicy & JWT
- Kiali / Jaeger observability
- Ambient mesh, multi-cluster & extensibility (WASM)
Module 5 — Expert & super-expert
- Choosing a mesh: the decision matrix
- SPIFFE/SPIRE & zero-trust architecture
- eBPF & the sidecar-less future
- Progressive delivery, GitOps & observability at scale
- Performance, security hardening & migrating between meshes
- Capstone: design & defend a mesh