Kuma: The Universal Service Mesh
Shriira Press
The universal Envoy service mesh that connects services across Kubernetes, VMs, and clouds — without leaving Envoy expertise to you.
Welcome to Kuma: The Universal Service Mesh.
Kuma is a modern, Envoy-based service mesh built to give security, observability, routing, and reliable connectivity to services no matter where they run — Kubernetes pods, virtual machines, bare metal, one cluster or fifty across multiple clouds. Originally created by Kong and donated to the Cloud Native Computing Foundation, it pairs a lightweight control plane with bundled Envoy sidecars so you get the power of Envoy without having to master it. This book begins with the problem a service mesh exists to solve and the idea of separating a data plane from a control plane, then builds up Kuma's architecture: the control plane, the data plane proxies, and the Mesh resource that organizes it all. From there it covers automatic mTLS and zero-trust security, the targetRef policy model that drives traffic permissions, timeouts, retries, circuit breakers, and routing, observability through metrics, logs, and traces, and the multi-zone design — global and zone control planes, KDS, zone ingress and egress — that lets one mesh span the globe. It closes with installation, day-two operations, and where Kuma fits in the wider cloud-native landscape.
This title is part of the ShriIra library and is free to read in full, right here — our small contribution to making world-class knowledge easy to reach.
A note on reading it: open the Contents menu at the top of the reader to jump between chapters, use the Aa menu to set a comfortable text size, theme (light, sepia, or night), and single- or two-page layout. Your place is saved automatically, so you can always pick up where you left off.
We hope it serves you well.
— Shriira Press