DVO-410 Advanced ⏱ 8 weeks

Service Meshes: Consul, Linkerd & Istio

Master service meshes end to end — from sidecars and mTLS to running a zero-trust, multi-cluster mesh in production. Learn all three (Consul, Linkerd, Istio) deeply, then how to choose, secure, operate and scale them. 100+ slides, hands-on labs, beginner to super-expert.

Prerequisites: DVO-201 Docker & Kubernetes

Syllabus

Module 1 — Service mesh fundamentals

  • Sidecars & the data/control plane
  • Automatic mTLS & zero-trust
  • L4 vs L7 and the proxy (Envoy vs micro-proxy)
  • Connect · Secure · Observe
  • The honest costs & when NOT to use a mesh

Module 2 — Consul

  • Service discovery, health & KV
  • Connect mesh, SPIFFE identity & the CA
  • Intentions (zero-trust authorization)
  • L7 traffic: router / splitter / resolver
  • Gateways, multi-datacenter & cluster peering
  • Hybrid VM + Kubernetes meshing

Module 3 — Linkerd

  • The minimal, secure-by-default mesh
  • Automatic mTLS & ServiceAccount identity
  • Golden metrics & live `tap`
  • Retries (budgets), splits & Flagger canaries
  • Authorization policy & multicluster

Module 4 — Istio

  • istiod, Envoy & xDS
  • VirtualService / DestinationRule / Gateway / ServiceEntry
  • PeerAuthentication, AuthorizationPolicy & JWT
  • Kiali / Jaeger observability
  • Ambient mesh, multi-cluster & extensibility (WASM)

Module 5 — Expert & super-expert

  • Choosing a mesh: the decision matrix
  • SPIFFE/SPIRE & zero-trust architecture
  • eBPF & the sidecar-less future
  • Progressive delivery, GitOps & observability at scale
  • Performance, security hardening & migrating between meshes
  • Capstone: design & defend a mesh