A service mesh is a dedicated infrastructure layer for managing service-to-service communication in distributed systems. Its parameters define two deployment modes: the data plane (sidecar or ambient proxies intercepting all network traffic between services) and the control plane (a manager that configures routing policies, load balancing, service discovery, mutual TLS, and observability). It persists through declarative configuration (CRDs, YAML manifests) and control-plane APIs that continuously reconcile desired state with actual traffic patterns. A service mesh enables traffic splitting, circuit breaking, rate limiting, and distributed tracing without modifying application code.\n\n[formal: reticulum servium | substrate: behavior | horizon: hours | explicit: yes | epoch: 0.01]
Accepted ontology entry
service-mesh
A service mesh is a dedicated infrastructure layer for managing service-to-service communication in distributed systems. Its parameters define two deployment modes: the data plane (sidecar or ambient proxies intercepting all network traffi…
Definition
Why it is in scope
A service mesh is a human-made infrastructure layer in distributed systems — a dedicated network of proxies that manages service-to-service communication without requiring application-level changes. It persists through configuration files and control plane software that orchestrate routing, discovery, and observability across microservices.
Names and aliases
- service-meshen · CANONICAL
Relations from this entry
- cmrdttohs0009p7dyegiuzxpiINSTANCE_OF →
A service mesh is a specific kind of infrastructure — specifically, the network infrastructure layer for inter-service communication. A competent speaker would call a service mesh a type of infrastructure. Direction: specific→general.
- cmro0gqxn03mrd1nlcefypzbgDEPENDS_ON →
A service mesh depends on proxies: its data plane is literally composed of sidecar or ambient proxies that intercept all traffic. Remove proxies and the service mesh stops operating — the mesh HAS NO WORKING without proxy instances.
Relations to this entry
No accepted relations in this direction.
Record identity
- Created
- Aug 7, 2026, 9:11 PM UTC
- Content hash
- c7a5784ceafb68a931ce4fa4f6e4fba1fbcb26e8b8344d9b522a1b124e81121d