『How Kubernetes Service Mesh mTLS Rotation Causes Pod Restarts』のカバーアート

How Kubernetes Service Mesh mTLS Rotation Causes Pod Restarts

How Kubernetes Service Mesh mTLS Rotation Causes Pod Restarts

無料で聴く

ポッドキャストの詳細を見る
In this episode of DevOps Daily, Lucas and Luna dive into a subtle but dangerous issue in Kubernetes service meshes: automatic mTLS certificate rotation. When the Istio or Linkerd control plane rotates certificates, badly configured sidecar proxies can restart mid-request, causing connection drops, retry storms, and degraded latency. The hosts walk through a real incident at a mid-size fintech where a 24-hour certificate rotation window triggered cascading failures across 200 microservices. They explain the root cause—a mismatch between the certificate refresh interval and the envoy hot-restart mechanism—and the fix: aligning secrets mount propagation with proxy startup probes. Listeners get a concrete checklist to audit their own mesh configurations before the next rotation hits. #Kubernetes #ServiceMesh #mTLS #Istio #Linkerd #CertificateRotation #EnvoyProxy #CI/CD #DevOps #SiteReliabilityEngineering #CloudNative #SidecarProxy #PodRestarts #Security #Technology #FexingoBusiness #BusinessPodcast #DevOpsDaily Keep every episode free: buymeacoffee.com/fexingo
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません