Technical Report: Performance Comparison of Service Mesh Frameworks: the MTLS Test Case

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Barr, Anat Bremler, Lavi, Ofek, Naor, Yaniv, Rampal, Sanjeev, Tavori, Jhonatan
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913571271606272
author Barr, Anat Bremler
Lavi, Ofek
Naor, Yaniv
Rampal, Sanjeev
Tavori, Jhonatan
author_facet Barr, Anat Bremler
Lavi, Ofek
Naor, Yaniv
Rampal, Sanjeev
Tavori, Jhonatan
contents Service Mesh has become essential for modern cloud-native applications by abstracting communication between microservices and providing zero-trust security, observability, and advanced traffic control without requiring code changes. This allows developers to leverage new network capabilities and focus on application logic without managing network complexities. However, the additional layer can significantly impact system performance, latency, and resource consumption, posing challenges for cloud managers and operators. In this work, we investigate the impact of the mTLS protocol - a common security and authentication mechanism - on application performance within service meshes. Recognizing that security is a primary motivation for deploying a service mesh, we evaluated the performance overhead introduced by leading service meshes: Istio, Istio Ambient, Linkerd, and Cilium. Our experiments were conducted by testing their performance in service-to-service communications within a Kubernetes cluster. Our experiments reveal significant performance differences (in terms of latency and memory consumption) among the service meshes, rooting from the different architecture of the service mesh, sidecar versus sidecareless, and default extra features hidden in the mTLS implementation. Our results highlight the understanding of the service mesh architecture and its impact on performance.
format Preprint
id arxiv_https___arxiv_org_abs_2411_02267
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Technical Report: Performance Comparison of Service Mesh Frameworks: the MTLS Test Case
Barr, Anat Bremler
Lavi, Ofek
Naor, Yaniv
Rampal, Sanjeev
Tavori, Jhonatan
Networking and Internet Architecture
Service Mesh has become essential for modern cloud-native applications by abstracting communication between microservices and providing zero-trust security, observability, and advanced traffic control without requiring code changes. This allows developers to leverage new network capabilities and focus on application logic without managing network complexities. However, the additional layer can significantly impact system performance, latency, and resource consumption, posing challenges for cloud managers and operators. In this work, we investigate the impact of the mTLS protocol - a common security and authentication mechanism - on application performance within service meshes. Recognizing that security is a primary motivation for deploying a service mesh, we evaluated the performance overhead introduced by leading service meshes: Istio, Istio Ambient, Linkerd, and Cilium. Our experiments were conducted by testing their performance in service-to-service communications within a Kubernetes cluster. Our experiments reveal significant performance differences (in terms of latency and memory consumption) among the service meshes, rooting from the different architecture of the service mesh, sidecar versus sidecareless, and default extra features hidden in the mTLS implementation. Our results highlight the understanding of the service mesh architecture and its impact on performance.
title Technical Report: Performance Comparison of Service Mesh Frameworks: the MTLS Test Case
topic Networking and Internet Architecture
url https://arxiv.org/abs/2411.02267