Citrix has linked the Istio control plane service mesh to its ADC platform to more tightly secure and optimize traffic with a microservices-based application environment. The move is also the latest victory for the rapidly evolving service mesh platform.
Citrix’s ADC platform is a product suite that is targeted at helping companies migrate and manage microservices-based applications. It includes single-pane management across hybrid and multi-cloud environments; Layer 3 through Layer 7 security for applications and APIs; and it integrates with Kubernetes and other open source tools.
That last component is key to the new Istio integration. Istio sits at the network level and uses a substrate for microservices development and maintenance. This allows for the decoupling of management from application development. While it’s not officially part of the Cloud Native Computing Foundation (CNCF) ecosystem that houses Kubernetes, Istio is linked to the Envoy service proxy that is part of CNCF.
Istio acts as the control plane for management of the service mesh. It can handle the deployment of Envoy sidecars – where Envoy sits next to a running container pod – and coordinate that deployment through the container orchestration layer working with platforms like Kubernetes or Apache Mesos.
Citrix is offering Istio in two ways: as an ingress gateway for north-south traffic into the service mesh environment, and as a sidecar proxy to control inter-microservice communication. Those two models can be used separately or combined to provide a unified data plane option.
Pankaj Gupta, senior director for product marketing for networking at Citrix, explained in an email to SDxCentral that with Istio, the Citrix ADC "can act as an ingress and/or sidecar proxy in the data plane." It can also act as an ingress gateway for services deployed with or without a sidecar, and that sidecar can be ADC is its CPX container form factor or using Envoy. "Citrix CPX offers low latency, high performance, and ease of deployment with Istio and Citrix [application delivery management]," he added.
Istio Ho!Istio was established two years ago to provide developers with visibility into microservices without the need to change application code. Google, Lyft, and IBM were the initial backers of the Envoy-based platform, but it has since drawn support from a number of vendors.
The platform recently hit its 1.3 release that included a focus on easing the use of the service mesh, which has become one of its bigger adoption hurdles.
Those hurdles stemmed from what many thought was as premature 1.0 release last year that was still hard to integrate into production environments.
“I would say it was premature,” noted Christian Posta, senior principal architect at Red Hat, on the 1.0 release. “On the other hand, until you hit 1.0 people don’t give something a lot of attention. Even through it could have benefited from a few more months of work, at some point you have to ship it.”
That hiccup has kept open the door for alternatives to seep into the market. Those include Kong’s recently launched Kuma service mesh, Containous’ Maesh platform, and Linkerd.
Tom Petrocelli, a research fellow at Amalgam Insights, recently noted that while the service mesh space remains open at this point, Istio’s alignment with major organizations “is causing supporting vendors to pour resources into Istio/Envoy which practically ensures that Istio/Envoy will succeed.”
Gupta noted that "Istio is maturing," and that the most recent 1.3 release was a "step forward to make Istio simpler and to accelerate Istio adoption."
Comments