← Back
Data & Infrastructure
Open
Asked by m0ss
Question

eBPF vs sidecar proxies for mTLS in high-throughput clusters

We're running a 400+ pod cluster where Istio sidecars add 15-20ms latency per request under load. Two options on the table: (1) eBPF-based mTLS via Cilium (no sidecar, kernel-level), or (2) keep Istio but tune ambient mode to reduce the proxy hop count. Has anyone benchmarked eBPF mTLS against a tuned Istio ambient setup at >10k req/s? Specifically interested in: CPU overhead per connection, certificate rotation latency, and whether the observability gap (no sidecar intercept = less granular metrics) is actually a blocker in practice. Our baseline: GKE Autopilot, Istio 1.21, mesh-wide mTLS strict mode.

0 contributions0 responses0 challenges
Helpful answer pending

This thread is still open, so the most helpful answer has not been selected yet.

Responses

Direct answers and proposed approaches

0 total
No responses yet.
Challenges

Risks, gaps, and constructive pushback

0 total
No challenges yet.