Skip to content
Back to skills

Service Mesh Istio Cilium

ASecurity

Architect, configure, and secure cloud-native service meshes using Istio and Cilium eBPF. Implement mutual TLS (mTLS STRICT), traffic splitting, canary rollouts, circuit breaking, fault injection, rate limiting, and kernel-level eBPF L7 observability. Trigger when configuring Kubernetes network policies, service-to-service encryption, or advanced ingress/egress routing.

  • 8 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 29, 2026
ai-agentsgonodekubernetesapifrontendbackendsecurity

Works with

  • api

Security analysis

A100/100

Scanned September 29, 2026

npx -y skills add hamzabellouch/agent-skills --skill service-mesh-istio-cilium --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Service Mesh Istio Cilium?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Service Mesh Istio Cilium
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hamzabellouch-service-mesh-istio-cilium/badge)](https://www.skillsdirectory.com/skills/hamzabellouch-service-mesh-istio-cilium)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: service-mesh-istio-cilium
metadata:
  category: Network Engineering and Edge Routing
description: Architect, configure, and secure cloud-native service meshes using Istio and Cilium eBPF. Implement mutual TLS (mTLS STRICT), traffic splitting, canary rollouts, circuit breaking, fault injection, rate limiting, and kernel-level eBPF L7 observability. Trigger when configuring Kubernetes network policies, service-to-service encryption, or advanced ingress/egress routing.
compatibility: Kubernetes 1.28+, Istio 1.20+, Cilium 1.15+
---

# Service Mesh (Istio & Cilium eBPF) Skill Guide

This skill guides engineering teams through designing and maintaining secure, observable service-to-service networks using Istio control plane and Cilium eBPF kernel datapath.

---

## 1. Dual-Engine Architecture: Cilium eBPF + Istio

```text
[ Kubernetes Pod A ]                     [ Kubernetes Pod B ]
        |                                        ^
        v (Envoy Sidecar / Ambient)              |
[ Istio L7 Policy Engine ]                       |
  - mTLS Encryption (SPIFFE / SPIRE)             |
  - Circuit Breakers & Retries                   |
        |                                        |
        v                                        |
+-------------------------------------------------------------+
| Linux Kernel eBPF (Cilium Datapath)                         |
| - Sockops socket-level acceleration (bypass TCP/IP stack)   |
| - L3/L4 NetworkPolicy enforcement                           |
| - Hubble Flow Observability & DNS proxy                     |
+-------------------------------------------------------------+
```

---

## 2. Production Manifests & Configuration

### A. Strict Mutual TLS (mTLS) PeerAuthentication

```yaml
apiVersion: security.istio.io/v1beta1
kind: PeerAuthentication
metadata:
  name: default
  namespace: production
spec:
  mtls:
    mode: STRICT # Rejects all non-mTLS plaintext connections
---
apiVersion: security.istio.io/v1beta1
kind: AuthorizationPolicy
metadata:
  name: order-service-authz
  namespace: production
spec:
  selector:
    matchLabels:
      app: order-service
  action: ALLOW
  rules:
  - from:
    - source:
        principals: ["cluster.local/ns/production/sa/frontend-service-account"]
    to:
    - operation:
        methods: ["GET", "POST"]
        paths: ["/api/v1/orders*"]
```

### B. Canary Traffic Splitting & Circuit Breaking

```yaml
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: payment-service-vs
  namespace: production
spec:
  hosts:
  - payment-service
  http:
  - route:
    - destination:
        host: payment-service
        subset: v1
      weight: 90
    - destination:
        host: payment-service
        subset: v2-canary
      weight: 10
    timeout: 3s
    retries:
      attempts: 3
      perTryTimeout: 1s
      retryOn: "5xx,connect-failure,refused-stream"
---
apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
  name: payment-service-dr
  namespace: production
spec:
  host: payment-service
  subsets:
  - name: v1
    labels:
      version: v1
  - name: v2-canary
    labels:
      version: v2
  trafficPolicy:
    connectionPool:
      tcp:
        maxConnections: 100
      http:
        http1MaxPendingRequests: 50
        maxRequestsPerConnection: 10
    outlierDetection: # Circuit Breaker
      consecutive5xxErrors: 3
      interval: 10s
      baseEjectionTime: 30s
      maxEjectionPercent: 50
```

### C. Cilium eBPF L3/L4 Network Policy with DNS Inspection

```yaml
apiVersion: "cilium.io/v2"
kind: CiliumNetworkPolicy
metadata:
  name: secure-backend-egress
  namespace: production
spec:
  endpointSelector:
    matchLabels:
      app: backend-worker
  egress:
  # Allow internal DNS queries
  - toEndpoints:
    - matchLabels:
        "k8s:io.kubernetes.pod.namespace": kube-system
        k8s-app: kube-dns
    toPorts:
    - ports:
      - port: "53"
        protocol: UDP
      rules:
        dns:
        - matchPattern: "*"
  # Restrict external egress to authorized payment gateway
  - toFQDNs:
    - matchName: "api.stripe.com"
    toPorts:
    - ports:
    - port: "443"
      protocol: TCP
```

---

## 3. Best Practices & Troubleshooting

1. **Verify mTLS:** Use `istioctl proxy-status` and `istioctl authn tls-check <pod-name>` to verify cryptographic identity handshakes.
2. **eBPF Acceleration:** Enable Cilium `sockops` (`sockops.enabled=true`) to bypass the host TCP stack for co-located pods, cutting intra-node latency by up to 40%.
3. **Hubble Observability:** Run `hubble observe --namespace production --verdict DROPPED` to troubleshoot blocked network packets in real time.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…