
Service Mesh Architecture & Troubleshooting
Diagnose and optimize service mesh configurations with systematic troubleshooting
What You Can Do
This skill helps you systematically analyze service mesh architectures, identify inter-service communication failures, and design optimal routing and security policies. You'll receive step-by-step troubleshooting guidance tailored to your mesh platform (Istio, Linkerd, Consul), configuration validation reports, and architectural recommendations that reduce latency, improve observability, and tighten security posture.
Features
Analyze Istio, Linkerd, or Consul configs for common misconfigurations and policy conflicts
Debug asymmetric routing, circuit breaker issues, and traffic splitting policies
Correlate network metrics with configuration to identify bottlenecks
Verify mutual TLS setup, PeerAuthentication policies, and authorization rules
Resolve connection timeouts, DNS failures, and sidecar injection issues
Visualize communication patterns and identify problematic cross-namespace flows
Parse Envoy sidecar logs and control plane events to pinpoint failures
Design safe migration paths from no-mesh to fully managed architectures
Example Output
Configuration Review Example:
- ❌ Issue: VirtualService 'payment-api' defines retries but no timeout
Risk: Cascading delays during payment processing
Fix: Add timeout: 5s to http route
- ✅ mTLS Status: Properly enforced in production namespace
- ✅ Circuit Breaker: Configured (5 consecutive errors → open)
Troubleshooting Output:
Symptom: Requests to user-service timeout 50% of the time
Root Cause: Uneven traffic distribution to 3 replicas
- Pod 1 healthy, Pod 2 CrashLoopBackOff, Pod 3 healthy
- Mesh still routes to Pod 2 (endpoint stale)
Solution:
1. Fix Pod 2 deployment error (memory limit too low)
2. Kubectl scale replicas to 0, then back to 3
3. Verify all endpoints healthy: kubectl get endpoints user-service
Expected: Even distribution across 3 pods, 99%+ success
What's Included
- SKILL.md: Complete troubleshooting workflow and decision trees
- Configuration templates: Ready-to-use VirtualService, DestinationRule, Gateway, and PeerAuthentication manifests for Istio, Linkerd configs for Consul
- Troubleshooting checklist: Systematic steps to isolate network, sidecar, and policy issues
- Traffic policy examples: Canary deployments, blue-green routing, load balancing strategies
- Security policy templates: mTLS enforcement, authorization policies, egress rules
- Observability integration guide: Prometheus, Jaeger, and log analysis tips
Who It's For
- Platform engineers — Design and maintain mesh infrastructure for teams
- DevOps and SRE teams — Debug production failures and optimize traffic policies
- Microservices architects — Plan mesh adoption and security policies
- Infrastructure engineers — Troubleshoot inter-service communication issues
- Cloud-native development leads — Migrate workloads to managed mesh environments
Best For
- Debugging timeout, connection refused, and 503 errors in containerized services
- Designing traffic routing policies for canary deployments and A/B testing
- Implementing mTLS, authorization policies, and network security hardening
- Diagnosing asymmetric traffic distribution and load balancer issues
- Planning zero-downtime mesh upgrades and sidecar injection rollouts







