Kuma: The Universal Service Mesh

Shriira Press

Preface

The universal Envoy service mesh that connects services across Kubernetes, VMs, and clouds — without leaving Envoy expertise to you.

Welcome to Kuma: The Universal Service Mesh.

Kuma is a modern, Envoy-based service mesh built to give security, observability, routing, and reliable connectivity to services no matter where they run — Kubernetes pods, virtual machines, bare metal, one cluster or fifty across multiple clouds. Originally created by Kong and donated to the Cloud Native Computing Foundation, it pairs a lightweight control plane with bundled Envoy sidecars so you get the power of Envoy without having to master it. This book begins with the problem a service mesh exists to solve and the idea of separating a data plane from a control plane, then builds up Kuma's architecture: the control plane, the data plane proxies, and the Mesh resource that organizes it all. From there it covers automatic mTLS and zero-trust security, the targetRef policy model that drives traffic permissions, timeouts, retries, circuit breakers, and routing, observability through metrics, logs, and traces, and the multi-zone design — global and zone control planes, KDS, zone ingress and egress — that lets one mesh span the globe. It closes with installation, day-two operations, and where Kuma fits in the wider cloud-native landscape.

This title is part of the ShriIra library and is free to read in full, right here — our small contribution to making world-class knowledge easy to reach.

A note on reading it: open the Contents menu at the top of the reader to jump between chapters, use the Aa menu to set a comfortable text size, theme (light, sepia, or night), and single- or two-page layout. Your place is saved automatically, so you can always pick up where you left off.

We hope it serves you well.

— Shriira Press

Contents

  1. Chapter 1 — Why a Service Mesh
  2. Chapter 2 — Meet Kuma
  3. Chapter 3 — Architecture: Control Plane and Data Plane
  4. Chapter 4 — The Mesh and the Universal Model
  5. Chapter 5 — Security and mTLS
  6. Chapter 6 — The Policy Model
  7. Chapter 7 — Traffic Management and Resilience
  8. Chapter 8 — Observability
  9. Chapter 9 — Going Multi-Zone
  10. Chapter 10 — Kuma in Practice
0%
1/1