istio-traffic-management
wshobson/agents
Configure Istio service mesh traffic routing, load balancing, circuit breakers, and canary deployments.
What is istio-traffic-management?
Istio Traffic Management provides comprehensive configuration for service-to-service routing, progressive delivery patterns, and resilience policies within a service mesh. Use this skill when implementing traffic policies, canary or blue-green deployments, circuit breakers, retries, or fault injection for production Kubernetes environments.
- Define routing rules with VirtualService resources for header-based and weighted traffic splitting
- Configure DestinationRule policies including load balancing, connection pools, and outlier detection
- Implement canary deployments by splitting traffic between service versions with configurable weights
- Set up circuit breakers with connection limits, request thresholds, and automatic pod ejection
- Enable traffic mirroring to shadow production traffic to test environments without affecting users
- Inject faults (delays and aborts) for chaos engineering and resilience testing
How to install istio-traffic-management
npx skills add https://github.com/wshobson/agents --skill istio-traffic-management- Istio installed and running on Kubernetes cluster
- Services deployed with sidecar proxies injected
- kubectl access to the cluster
- Understanding of Kubernetes labels and namespaces
How to use istio-traffic-management
- 1.Create a DestinationRule to define service subsets with version labels matching your pod labels
- 2.Create a VirtualService to specify routing rules, weights, and policies for traffic to those subsets
- 3.Apply the YAML manifests using kubectl apply
- 4.Verify configuration with istioctl analyze and istioctl proxy-config routes
- 5.Monitor traffic flow using Kiali dashboard or Jaeger tracing
- 6.Adjust weights and policies incrementally to test canary deployments
Use cases
- Route traffic to different service versions based on user headers or request properties
- Gradually roll out new versions by sending 10% traffic to canary while keeping 90% on stable
- Automatically eject unhealthy pods when they exceed consecutive error thresholds
- Mirror live traffic to a staging environment to validate new code before full rollout
- Inject 5% abort errors to test client retry logic and circuit breaker behavior
- Platform engineers managing Kubernetes service mesh deployments
- DevOps teams implementing progressive delivery and canary releases
- SREs designing resilience patterns and chaos engineering tests
- Application teams configuring traffic policies between microservices
istio-traffic-management FAQ
VirtualService defines how traffic is routed to a destination (which subset gets traffic and how much). DestinationRule defines policies applied after routing, such as load balancing, connection pools, and circuit breaker settings.
Create a VirtualService with weighted routing: send 90% of traffic to the stable subset and 10% to the canary subset. Monitor metrics, then gradually increase canary weight as confidence grows.
Outlier detection automatically ejects unhealthy pods from the load balancer when they exceed error thresholds. Use it to improve resilience by removing failing instances without manual intervention.
Traffic mirroring should target non-production environments to avoid side effects. Mirror to a staging or shadow environment to validate changes before full rollout.
Timeout is the total time allowed for a request. Retries happen within that timeout window. Set perTryTimeout lower than the overall timeout to allow multiple attempts.
Full instructions (SKILL.md)
Source of truth, from wshobson/agents.
name: istio-traffic-management description: Configure Istio traffic management including routing, load balancing, circuit breakers, and canary deployments. Use when implementing service mesh traffic policies, progressive delivery, or resilience patterns.
Istio Traffic Management
Comprehensive guide to Istio traffic management for production service mesh deployments.
When to Use This Skill
- Configuring service-to-service routing
- Implementing canary or blue-green deployments
- Setting up circuit breakers and retries
- Load balancing configuration
- Traffic mirroring for testing
- Fault injection for chaos engineering
Core Concepts
1. Traffic Management Resources
| Resource | Purpose | Scope |
|---|---|---|
| VirtualService | Route traffic to destinations | Host-based |
| DestinationRule | Define policies after routing | Service-based |
| Gateway | Configure ingress/egress | Cluster edge |
| ServiceEntry | Add external services | Mesh-wide |
2. Traffic Flow
Client → Gateway → VirtualService → DestinationRule → Service
(routing) (policies) (pods)
Templates
Template 1: Basic Routing
apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
name: reviews-route
namespace: bookinfo
spec:
hosts:
- reviews
http:
- match:
- headers:
end-user:
exact: jason
route:
- destination:
host: reviews
subset: v2
- route:
- destination:
host: reviews
subset: v1
---
apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
name: reviews-destination
namespace: bookinfo
spec:
host: reviews
subsets:
- name: v1
labels:
version: v1
- name: v2
labels:
version: v2
- name: v3
labels:
version: v3
Template 2: Canary Deployment
apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
name: my-service-canary
spec:
hosts:
- my-service
http:
- route:
- destination:
host: my-service
subset: stable
weight: 90
- destination:
host: my-service
subset: canary
weight: 10
---
apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
name: my-service-dr
spec:
host: my-service
trafficPolicy:
connectionPool:
tcp:
maxConnections: 100
http:
h2UpgradePolicy: UPGRADE
http1MaxPendingRequests: 100
http2MaxRequests: 1000
subsets:
- name: stable
labels:
version: stable
- name: canary
labels:
version: canary
Template 3: Circuit Breaker
apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
name: circuit-breaker
spec:
host: my-service
trafficPolicy:
connectionPool:
tcp:
maxConnections: 100
http:
http1MaxPendingRequests: 100
http2MaxRequests: 1000
maxRequestsPerConnection: 10
maxRetries: 3
outlierDetection:
consecutive5xxErrors: 5
interval: 30s
baseEjectionTime: 30s
maxEjectionPercent: 50
minHealthPercent: 30
Template 4: Retry and Timeout
apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
name: ratings-retry
spec:
hosts:
- ratings
http:
- route:
- destination:
host: ratings
timeout: 10s
retries:
attempts: 3
perTryTimeout: 3s
retryOn: connect-failure,refused-stream,unavailable,cancelled,retriable-4xx,503
retryRemoteLocalities: true
Template 5: Traffic Mirroring
apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
name: mirror-traffic
spec:
hosts:
- my-service
http:
- route:
- destination:
host: my-service
subset: v1
mirror:
host: my-service
subset: v2
mirrorPercentage:
value: 100.0
Template 6: Fault Injection
apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
name: fault-injection
spec:
hosts:
- ratings
http:
- fault:
delay:
percentage:
value: 10
fixedDelay: 5s
abort:
percentage:
value: 5
httpStatus: 503
route:
- destination:
host: ratings
Template 7: Ingress Gateway
apiVersion: networking.istio.io/v1beta1
kind: Gateway
metadata:
name: my-gateway
spec:
selector:
istio: ingressgateway
servers:
- port:
number: 443
name: https
protocol: HTTPS
tls:
mode: SIMPLE
credentialName: my-tls-secret
hosts:
- "*.example.com"
---
apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
name: my-vs
spec:
hosts:
- "api.example.com"
gateways:
- my-gateway
http:
- match:
- uri:
prefix: /api/v1
route:
- destination:
host: api-service
port:
number: 8080
Load Balancing Strategies
apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
name: load-balancing
spec:
host: my-service
trafficPolicy:
loadBalancer:
simple: ROUND_ROBIN # or LEAST_CONN, RANDOM, PASSTHROUGH
---
# Consistent hashing for sticky sessions
apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
name: sticky-sessions
spec:
host: my-service
trafficPolicy:
loadBalancer:
consistentHash:
httpHeaderName: x-user-id
# or: httpCookie, useSourceIp, httpQueryParameterName
Best Practices
Do's
- Start simple - Add complexity incrementally
- Use subsets - Version your services clearly
- Set timeouts - Always configure reasonable timeouts
- Enable retries - But with backoff and limits
- Monitor - Use Kiali and Jaeger for visibility
Don'ts
- Don't over-retry - Can cause cascading failures
- Don't ignore outlier detection - Enable circuit breakers
- Don't mirror to production - Mirror to test environments
- Don't skip canary - Test with small traffic percentage first
Debugging Commands
# Check VirtualService configuration
istioctl analyze
# View effective routes
istioctl proxy-config routes deploy/my-app -o json
# Check endpoint discovery
istioctl proxy-config endpoints deploy/my-app
# Debug traffic
istioctl proxy-config log deploy/my-app --level debug
Related skills
More from wshobson/agents and the wider catalog.

javascript-testing-patterns
Implement comprehensive testing strategies with Jest, Vitest, and Testing Library for JavaScript/TypeScript.

k8s-manifest-generator
Generate production-ready Kubernetes manifests with built-in best practices and security standards.

k8s-security-policies
Implement NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards for production Kubernetes security.

kpi-dashboard-design
Design executive KPI dashboards with metrics selection, visualization patterns, and real-time monitoring best practices.

langchain-architecture
Design LLM applications with LangChain 1.x and LangGraph for agents, memory, and tool integration.

linkerd-patterns
Lightweight, security-first service mesh patterns for Kubernetes with automatic mTLS and traffic control.