PluginBench
Skill
Pass
Audit score 90

istio-traffic-management

wshobson/agents

Configure Istio service mesh traffic routing, load balancing, circuit breakers, and canary deployments.

What is istio-traffic-management?

Istio Traffic Management provides comprehensive configuration for service-to-service routing, progressive delivery patterns, and resilience policies within a service mesh. Use this skill when implementing traffic policies, canary or blue-green deployments, circuit breakers, retries, or fault injection for production Kubernetes environments.

  • Define routing rules with VirtualService resources for header-based and weighted traffic splitting
  • Configure DestinationRule policies including load balancing, connection pools, and outlier detection
  • Implement canary deployments by splitting traffic between service versions with configurable weights
  • Set up circuit breakers with connection limits, request thresholds, and automatic pod ejection
  • Enable traffic mirroring to shadow production traffic to test environments without affecting users
  • Inject faults (delays and aborts) for chaos engineering and resilience testing

How to install istio-traffic-management

npx skills add https://github.com/wshobson/agents --skill istio-traffic-management
Prerequisites
  • Istio installed and running on Kubernetes cluster
  • Services deployed with sidecar proxies injected
  • kubectl access to the cluster
  • Understanding of Kubernetes labels and namespaces
Claude Code
Cursor
Windsurf
Cline

How to use istio-traffic-management

  1. 1.Create a DestinationRule to define service subsets with version labels matching your pod labels
  2. 2.Create a VirtualService to specify routing rules, weights, and policies for traffic to those subsets
  3. 3.Apply the YAML manifests using kubectl apply
  4. 4.Verify configuration with istioctl analyze and istioctl proxy-config routes
  5. 5.Monitor traffic flow using Kiali dashboard or Jaeger tracing
  6. 6.Adjust weights and policies incrementally to test canary deployments

Use cases

Good for
  • Route traffic to different service versions based on user headers or request properties
  • Gradually roll out new versions by sending 10% traffic to canary while keeping 90% on stable
  • Automatically eject unhealthy pods when they exceed consecutive error thresholds
  • Mirror live traffic to a staging environment to validate new code before full rollout
  • Inject 5% abort errors to test client retry logic and circuit breaker behavior
Who it's for
  • Platform engineers managing Kubernetes service mesh deployments
  • DevOps teams implementing progressive delivery and canary releases
  • SREs designing resilience patterns and chaos engineering tests
  • Application teams configuring traffic policies between microservices

istio-traffic-management FAQ

What's the difference between VirtualService and DestinationRule?

VirtualService defines how traffic is routed to a destination (which subset gets traffic and how much). DestinationRule defines policies applied after routing, such as load balancing, connection pools, and circuit breaker settings.

How do I implement a canary deployment?

Create a VirtualService with weighted routing: send 90% of traffic to the stable subset and 10% to the canary subset. Monitor metrics, then gradually increase canary weight as confidence grows.

What is outlier detection and when should I use it?

Outlier detection automatically ejects unhealthy pods from the load balancer when they exceed error thresholds. Use it to improve resilience by removing failing instances without manual intervention.

Can I mirror traffic to production services?

Traffic mirroring should target non-production environments to avoid side effects. Mirror to a staging or shadow environment to validate changes before full rollout.

How do retries and timeouts interact?

Timeout is the total time allowed for a request. Retries happen within that timeout window. Set perTryTimeout lower than the overall timeout to allow multiple attempts.

Full instructions (SKILL.md)

Source of truth, from wshobson/agents.


name: istio-traffic-management description: Configure Istio traffic management including routing, load balancing, circuit breakers, and canary deployments. Use when implementing service mesh traffic policies, progressive delivery, or resilience patterns.

Istio Traffic Management

Comprehensive guide to Istio traffic management for production service mesh deployments.

When to Use This Skill

  • Configuring service-to-service routing
  • Implementing canary or blue-green deployments
  • Setting up circuit breakers and retries
  • Load balancing configuration
  • Traffic mirroring for testing
  • Fault injection for chaos engineering

Core Concepts

1. Traffic Management Resources

ResourcePurposeScope
VirtualServiceRoute traffic to destinationsHost-based
DestinationRuleDefine policies after routingService-based
GatewayConfigure ingress/egressCluster edge
ServiceEntryAdd external servicesMesh-wide

2. Traffic Flow

Client → Gateway → VirtualService → DestinationRule → Service
                   (routing)        (policies)        (pods)

Templates

Template 1: Basic Routing

apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
  name: reviews-route
  namespace: bookinfo
spec:
  hosts:
    - reviews
  http:
    - match:
        - headers:
            end-user:
              exact: jason
      route:
        - destination:
            host: reviews
            subset: v2
    - route:
        - destination:
            host: reviews
            subset: v1
---
apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
  name: reviews-destination
  namespace: bookinfo
spec:
  host: reviews
  subsets:
    - name: v1
      labels:
        version: v1
    - name: v2
      labels:
        version: v2
    - name: v3
      labels:
        version: v3

Template 2: Canary Deployment

apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
  name: my-service-canary
spec:
  hosts:
    - my-service
  http:
    - route:
        - destination:
            host: my-service
            subset: stable
          weight: 90
        - destination:
            host: my-service
            subset: canary
          weight: 10
---
apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
  name: my-service-dr
spec:
  host: my-service
  trafficPolicy:
    connectionPool:
      tcp:
        maxConnections: 100
      http:
        h2UpgradePolicy: UPGRADE
        http1MaxPendingRequests: 100
        http2MaxRequests: 1000
  subsets:
    - name: stable
      labels:
        version: stable
    - name: canary
      labels:
        version: canary

Template 3: Circuit Breaker

apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
  name: circuit-breaker
spec:
  host: my-service
  trafficPolicy:
    connectionPool:
      tcp:
        maxConnections: 100
      http:
        http1MaxPendingRequests: 100
        http2MaxRequests: 1000
        maxRequestsPerConnection: 10
        maxRetries: 3
    outlierDetection:
      consecutive5xxErrors: 5
      interval: 30s
      baseEjectionTime: 30s
      maxEjectionPercent: 50
      minHealthPercent: 30

Template 4: Retry and Timeout

apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
  name: ratings-retry
spec:
  hosts:
    - ratings
  http:
    - route:
        - destination:
            host: ratings
      timeout: 10s
      retries:
        attempts: 3
        perTryTimeout: 3s
        retryOn: connect-failure,refused-stream,unavailable,cancelled,retriable-4xx,503
        retryRemoteLocalities: true

Template 5: Traffic Mirroring

apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
  name: mirror-traffic
spec:
  hosts:
    - my-service
  http:
    - route:
        - destination:
            host: my-service
            subset: v1
      mirror:
        host: my-service
        subset: v2
      mirrorPercentage:
        value: 100.0

Template 6: Fault Injection

apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
  name: fault-injection
spec:
  hosts:
    - ratings
  http:
    - fault:
        delay:
          percentage:
            value: 10
          fixedDelay: 5s
        abort:
          percentage:
            value: 5
          httpStatus: 503
      route:
        - destination:
            host: ratings

Template 7: Ingress Gateway

apiVersion: networking.istio.io/v1beta1
kind: Gateway
metadata:
  name: my-gateway
spec:
  selector:
    istio: ingressgateway
  servers:
    - port:
        number: 443
        name: https
        protocol: HTTPS
      tls:
        mode: SIMPLE
        credentialName: my-tls-secret
      hosts:
        - "*.example.com"
---
apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
  name: my-vs
spec:
  hosts:
    - "api.example.com"
  gateways:
    - my-gateway
  http:
    - match:
        - uri:
            prefix: /api/v1
      route:
        - destination:
            host: api-service
            port:
              number: 8080

Load Balancing Strategies

apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
  name: load-balancing
spec:
  host: my-service
  trafficPolicy:
    loadBalancer:
      simple: ROUND_ROBIN # or LEAST_CONN, RANDOM, PASSTHROUGH
---
# Consistent hashing for sticky sessions
apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
  name: sticky-sessions
spec:
  host: my-service
  trafficPolicy:
    loadBalancer:
      consistentHash:
        httpHeaderName: x-user-id
        # or: httpCookie, useSourceIp, httpQueryParameterName

Best Practices

Do's

  • Start simple - Add complexity incrementally
  • Use subsets - Version your services clearly
  • Set timeouts - Always configure reasonable timeouts
  • Enable retries - But with backoff and limits
  • Monitor - Use Kiali and Jaeger for visibility

Don'ts

  • Don't over-retry - Can cause cascading failures
  • Don't ignore outlier detection - Enable circuit breakers
  • Don't mirror to production - Mirror to test environments
  • Don't skip canary - Test with small traffic percentage first

Debugging Commands

# Check VirtualService configuration
istioctl analyze

# View effective routes
istioctl proxy-config routes deploy/my-app -o json

# Check endpoint discovery
istioctl proxy-config endpoints deploy/my-app

# Debug traffic
istioctl proxy-config log deploy/my-app --level debug