TNS
VOXPOP
AI-Aided Coding
On average, how much time do you think you save per week by an AI-powered coding assistant such as GitHub Copilot or JetBrains AI Assistant?
I don’t use an AI coding assistant.
0%
Up to 1 hour/week
0%
1-3 hours
0%
3-5 hours
0%
5-8 hours
0%
More than 8 hours
0%
I don’t save any time, yet!
0%
Security

Ambient Mesh: No Sidecar Required

At CloudNative SecurityCon, Solo.io's Marino Wijay and Jim Barton share how service mesh technologies have matured, especially now with the removal of sidecars in Ambient Mesh.
Feb 22nd, 2023 4:24pm by
Featued image for: Ambient Mesh: No Sidecar Required

SEATTLE — At Cloud Native Security Con, we sat down for an On the Road episode of The New Stack Makers podcast with Solo.io’s Marino Wijay and Jim Barton, who discussed how service mesh technologies have matured, especially now with the removal of sidecars in Ambient Mesh, which Solo developed with Google.

Ambient Mesh is “a new proxy architecture that, according to the Solo.io site, “moves the proxy to the node level for mTLS and identity.” It also allows a policy-enforcement policy to manage Layer 7 security filters and policies.

Ambient Mesh: No Sidecar Required

A sidecar is a mini-proxy, a mini-firewall, like an all-in-one router, said Wijay, who does developer relations and advocacy for Solo. A sidecar receives instructions from an upstream control plane.

“Now, one of the things that we started to realize with different workloads and different patterns of communication is that not all these workloads need a sidecar or can take advantage of the sidecar,” Wijay said. “Some better operate without the sidecar.”

Security Mesh Matures

Ambient Mesh reflects the maturity of service mesh and the difference between Day 1 and Day 2 operations, said Barton, a field engineer with Solo.

“Day 1 operations are a lot about understanding concepts, enabling developers, initial configurations, that sort of thing,” Barton said. “The community is really much more focused and Ambient Mesh is a good example of this on Day 2 concerns.

“How do I scale this? How do I make it perform in large environments? How can I expand this across clusters, clusters in multiple zones in multiple regions, that sort of thing? Those are the kinds of initiatives that we’re really seeing come to the forefront at this point.”

With the maturity of service mesh comes the users. In the context of security, Barton said, that means the developer security operations person. It’s not the developer’s job to connect services. Their job is to build out the services.

“It’s up to the platform operator, or DevSecOps engineers to create that, that fundamental plane or foundation for where you can deploy your services, and then provide the security on top of it,” Barton said.

The engineers then have to configure it and think it through, he added:”How do I know who’s doing what and who’s talking to who, so that I can start forming my zero trust posture?”

Group Created with Sketch.
TNS owner Insight Partners is an investor in: Pragma.
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.