Istio Traffic Management

by wshobson46891e7e60daNo licenseListed Oct 8, 2026Updated Oct 8, 2026

Configure Istio traffic management including routing, load balancing, circuit breakers, and canary deployments. Use when implementing service mesh traffic policies, progressive delivery, or resilience patterns.

Instructions onlyDevOps & Cloud
AI-generated overview

Guide for configuring Istio traffic management: routing, load balancing, circuit breakers, and canary deployments.

What it does
This skill provides reference guidance and YAML templates for Istio traffic management in a service mesh. It covers VirtualService, DestinationRule, Gateway, and ServiceEntry resources, with templates for basic routing, canary releases, circuit breakers, retries and timeouts, traffic mirroring, fault injection, and ingress gateways. It also lists load balancing strategies, best practices, and istioctl debugging commands.
When to use it
Use it when configuring service-to-service routing, progressive delivery such as canary or blue-green rollouts, resilience patterns like circuit breakers and retries, or traffic mirroring and fault injection. It is aimed at production service mesh traffic policy work.
Requirements
No scripts are included; it is instructions and YAML templates only. Applying the configurations requires an Istio service mesh and kubectl or istioctl access to a cluster.

Istio Traffic Management

Comprehensive guide to Istio traffic management for production service mesh deployments.

When to Use This Skill

  • Configuring service-to-service routing
  • Implementing canary or blue-green deployments
  • Setting up circuit breakers and retries
  • Load balancing configuration
  • Traffic mirroring for testing
  • Fault injection for chaos engineering

Core Concepts

1. Traffic Management Resources

ResourcePurposeScope
VirtualServiceRoute traffic to destinationsHost-based
DestinationRuleDefine policies after routingService-based
GatewayConfigure ingress/egressCluster edge
ServiceEntryAdd external servicesMesh-wide

2. Traffic Flow

Client → Gateway → VirtualService → DestinationRule → Service                   (routing)        (policies)        (pods)

Templates

Template 1: Basic Routing

yaml
apiVersion: networking.istio.io/v1beta1kind: VirtualServicemetadata:  name: reviews-route  namespace: bookinfospec:  hosts:    - reviews  http:    - match:        - headers:            end-user:              exact: jason      route:        - destination:            host: reviews            subset: v2    - route:        - destination:            host: reviews            subset: v1---apiVersion: networking.istio.io/v1beta1kind: DestinationRulemetadata:  name: reviews-destination  namespace: bookinfospec:  host: reviews  subsets:    - name: v1      labels:        version: v1    - name: v2      labels:        version: v2    - name: v3      labels:        version: v3

Template 2: Canary Deployment

yaml
apiVersion: networking.istio.io/v1beta1kind: VirtualServicemetadata:  name: my-service-canaryspec:  hosts:    - my-service  http:    - route:        - destination:            host: my-service            subset: stable          weight: 90        - destination:            host: my-service            subset: canary          weight: 10---apiVersion: networking.istio.io/v1beta1kind: DestinationRulemetadata:  name: my-service-drspec:  host: my-service  trafficPolicy:    connectionPool:      tcp:        maxConnections: 100      http:        h2UpgradePolicy: UPGRADE        http1MaxPendingRequests: 100        http2MaxRequests: 1000  subsets:    - name: stable      labels:        version: stable    - name: canary      labels:        version: canary

Template 3: Circuit Breaker

yaml
apiVersion: networking.istio.io/v1beta1kind: DestinationRulemetadata:  name: circuit-breakerspec:  host: my-service  trafficPolicy:    connectionPool:      tcp:        maxConnections: 100      http:        http1MaxPendingRequests: 100        http2MaxRequests: 1000        maxRequestsPerConnection: 10        maxRetries: 3    outlierDetection:      consecutive5xxErrors: 5      interval: 30s      baseEjectionTime: 30s      maxEjectionPercent: 50      minHealthPercent: 30

Template 4: Retry and Timeout

yaml
apiVersion: networking.istio.io/v1beta1kind: VirtualServicemetadata:  name: ratings-retryspec:  hosts:    - ratings  http:    - route:        - destination:            host: ratings      timeout: 10s      retries:        attempts: 3        perTryTimeout: 3s        retryOn: connect-failure,refused-stream,unavailable,cancelled,retriable-4xx,503        retryRemoteLocalities: true

Template 5: Traffic Mirroring

yaml
apiVersion: networking.istio.io/v1beta1kind: VirtualServicemetadata:  name: mirror-trafficspec:  hosts:    - my-service  http:    - route:        - destination:            host: my-service            subset: v1      mirror:        host: my-service        subset: v2      mirrorPercentage:        value: 100.0

Template 6: Fault Injection

yaml
apiVersion: networking.istio.io/v1beta1kind: VirtualServicemetadata:  name: fault-injectionspec:  hosts:    - ratings  http:    - fault:        delay:          percentage:            value: 10          fixedDelay: 5s        abort:          percentage:            value: 5          httpStatus: 503      route:        - destination:            host: ratings

Template 7: Ingress Gateway

yaml
apiVersion: networking.istio.io/v1beta1kind: Gatewaymetadata:  name: my-gatewayspec:  selector:    istio: ingressgateway  servers:    - port:        number: 443        name: https        protocol: HTTPS      tls:        mode: SIMPLE        credentialName: my-tls-secret      hosts:        - "*.example.com"---apiVersion: networking.istio.io/v1beta1kind: VirtualServicemetadata:  name: my-vsspec:  hosts:    - "api.example.com"  gateways:    - my-gateway  http:    - match:        - uri:            prefix: /api/v1      route:        - destination:            host: api-service            port:              number: 8080

Load Balancing Strategies

yaml
apiVersion: networking.istio.io/v1beta1kind: DestinationRulemetadata:  name: load-balancingspec:  host: my-service  trafficPolicy:    loadBalancer:      simple: ROUND_ROBIN # or LEAST_CONN, RANDOM, PASSTHROUGH---# Consistent hashing for sticky sessionsapiVersion: networking.istio.io/v1beta1kind: DestinationRulemetadata:  name: sticky-sessionsspec:  host: my-service  trafficPolicy:    loadBalancer:      consistentHash:        httpHeaderName: x-user-id        # or: httpCookie, useSourceIp, httpQueryParameterName

Best Practices

Do's

  • Start simple - Add complexity incrementally
  • Use subsets - Version your services clearly
  • Set timeouts - Always configure reasonable timeouts
  • Enable retries - But with backoff and limits
  • Monitor - Use Kiali and Jaeger for visibility

Don'ts

  • Don't over-retry - Can cause cascading failures
  • Don't ignore outlier detection - Enable circuit breakers
  • Don't mirror to production - Mirror to test environments
  • Don't skip canary - Test with small traffic percentage first

Debugging Commands

bash
# Check VirtualService configurationistioctl analyze
# View effective routesistioctl proxy-config routes deploy/my-app -o json
# Check endpoint discoveryistioctl proxy-config endpoints deploy/my-app
# Debug trafficistioctl proxy-config log deploy/my-app --level debug

Source and attribution

Source:wshobson/agentsinplugins/cloud-infrastructure/skills/istio-traffic-managementat commit46891e7

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal