Service Mesh Flashcards
7 cards from real KCNA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Service Mesh flashcards as text
Which CNCF project provides a specification for defining service mesh interfaces so applications can work with multiple mesh implementations?
Answer: SMI (Service Mesh Interface)
SMI provides a standard set of Kubernetes CRDs for traffic management, observability, and access control that work across different mesh implementations.
What is 'traffic splitting' in a service mesh primarily used for?
Answer: Distributing traffic between two or more service versions for A/B testing or progressive delivery
Traffic splitting lets you route a defined percentage of requests to different service versions, enabling A/B tests and progressive rollouts.
In service mesh observability, what are the 'golden signals' that SREs typically monitor?
Answer: Latency, traffic, errors, saturation
Google SRE's four golden signals — latency, traffic, errors, and saturation — are the core metrics a service mesh surfaces per service.
Which Flagger feature automatically rolls back a canary deployment when error rate or latency thresholds are exceeded?
Answer: Progressive delivery with automated analysis
Flagger performs automated canary analysis by comparing metrics against thresholds and rolling back if the canary fails.
What is the key advantage of using a service mesh for retries compared to implementing retries in application code?
Answer: The mesh handles retries transparently without modifying application code
Service mesh retries are implemented in the proxy layer, so applications need no changes and retry logic is consistently applied across all services.
In Istio, what does setting outlier detection on a DestinationRule accomplish?
Answer: Automatically ejects unhealthy endpoints from the load balancing pool
Outlier detection monitors upstream hosts and removes those that exceed error thresholds from the load balancing rotation for a cooldown period.
Which statement best describes the difference between a service mesh and a Kubernetes NetworkPolicy?
Answer: Service mesh provides L7 traffic management and observability; NetworkPolicy provides L3/L4 IP/port-based network segmentation
NetworkPolicy enforces IP and port rules at L3/L4, while a service mesh adds L7 capabilities like HTTP routing, retries, tracing, and mTLS identity.