Skip to content

Istio

Summary

Istio is the CNCF-graduated, Envoy-based service mesh for Kubernetes. It provides mTLS with SPIFFE identities, L7 traffic management, authorization, and telemetry through two data plane modes: classic Envoy sidecars, and ambient mode (GA since 1.24, November 2024), which uses a per-node Rust proxy (ztunnel) for L4 and optional Envoy waypoints for L7. The current release line is 1.31 (latest patch 1.31.1, 2026-09-21), with 1.30 and 1.29 also supported. Recent releases focus on ambient multicluster (beta for multi-network), Gateway API v1.5/v1.6, AI inference and agent traffic (Inference Extension beta, experimental agentgateway), and moving release artifacts off Google Cloud hosting.

Key Facts

Attribute Detail
Website istio.io
Repository github.com/istio/istio (ztunnel: istio/ztunnel)
Stars ~36k+ (recorded by 2026-08)
Latest Version 1.31.1 (2026-09-21); 1.31.0 announced 2026-08-31
Supported releases 1.31 (EOL ~Feb 2027), 1.30 (EOL ~Dec 2026, latest 1.30.5), 1.29 (EOL 2026-10-12, latest 1.29.8)
Release cadence ~Quarterly minors; each supported until 6 weeks after the N+2 minor
Kubernetes 1.31 and 1.30 support Kubernetes 1.32-1.36; 1.29 supports 1.31-1.35
Data plane Envoy (1.31 uses Envoy release/v1.39) for sidecars, gateways, waypoints; ztunnel (Rust) for ambient L4
Gateway API Built against v1.6.0 (1.31), v1.5.1 (1.30); CRDs installed separately
Language Go (control plane), C++ (Envoy), Rust (ztunnel)
License Apache 2.0
Governance CNCF Graduated (2023-07-12; Incubating 2022-09-30); founded 2017 by Google, IBM and Lyft

Sources: Supported releases, 1.31.1 announcement, CNCF graduation announcement. Full matrices in Reference.

Evaluation

Pros Cons
Ambient mode: no sidecars, no restarts to enrol, much lower per-pod overhead Complex; steep learning curve and large API surface
Automatic mTLS with SPIFFE identities istiod needs tuning and scoping at large scale
Rich L7 traffic management (retries, fault injection, mirroring, locality/zone-aware LB) Ambient multicluster is beta and multi-network/multi-primary only
Gateway API native (ingress, waypoints, GAMMA mesh routing) No EnvoyFilter on waypoints; VMs still need sidecars
AI routing: Gateway API Inference Extension (beta), agentgateway (experimental) Envoy config debugging is hard; frequent Envoy CVE patch releases
CNCF Graduated, multi-vendor maintainers (Google, Solo.io, Red Hat, Microsoft, Tetrate and others) Upgrades need care (revisions, Gateway API CRD versions, 1.31 artifact moves)

When Istio fits

  • You need zero-trust mTLS and identity-based policy across many services, and want to add L7 policy only where needed (ambient).
  • You need advanced traffic management (canaries, fault injection, failover, egress control) or Gateway API ingress plus mesh in one control plane.
  • You run multi-cluster or hybrid meshes (multi-primary; sidecars for VMs).

Consider Linkerd for a smaller, simpler sidecar mesh, or Envoy Gateway when you only need north-south ingress.

Architecture Overview

Compact view of Istio's two data plane modes under one istiod; details in Explanation.

flowchart TB
    subgraph CP["Control plane"]
        Istiod["istiod<br/>xDS server, CA, webhooks"]
    end

    subgraph SC["Sidecar mode"]
        App1["App container"] --- Envoy1["Envoy sidecar<br/>L4 + L7"]
    end

    subgraph AM["Ambient mode (per node)"]
        CNI["istio-cni agent<br/>in-pod redirect"]
        Ztunnel["ztunnel DaemonSet<br/>mTLS, L4 policy"]
        WP["Waypoint (Envoy)<br/>L7 routing and policy"]
        Pod2["Ambient pod"]
    end

    CNI -.->|"redirect rules"| Pod2
    Pod2 -->|"captured"| Ztunnel
    Ztunnel -->|"HBONE :15008"| WP
    Istiod -->|"xDS + certs"| Envoy1
    Istiod -->|"WDS + certs"| Ztunnel
    Istiod -->|"xDS"| WP

    style CP fill:#5f6caf,color:#fff
    style Ztunnel fill:#2e7d32,color:#fff
    style WP fill:#e65100,color:#fff

Recent Releases

Release Date Highlights
1.31 2026-08-31 agentgateway as waypoint (experimental); weighted waypoint canaries; zone-aware LB; mesh-wide defaultTrafficPolicy; ALLOW_ANY_DYNAMIC_DNS; FIPS 140-3 policy; Gateway API v1.6; artifacts leave GCP hosting
1.30 2026-05-18 Experimental agentgateway gateway; TLSRoute termination; Gateway API v1.5.1 (CRD upgrade required); TrafficExtension API; Helm v4; sidecar-to-ambient migration guide; XDS debug endpoint auth
1.29 2026-02-16 Ambient multi-network multicluster beta; Inference Extension beta; ambient DNS capture and iptables reconciliation on by default; ztunnel CRL; optional NetworkPolicies
1.28 (EOL 2026-07-01) 2025-11-05 Native nftables in ambient; dual-stack beta
1.27 (EOL 2026-04-07) 2025-08-11 Ambient multicluster alpha; Inference Extension; native sidecars by default; nftables in sidecar mode
1.24 2024-11-07 Ambient mode GA (ztunnel, waypoints, APIs stable)

Security

Six security bulletins shipped between March and August 2026, mostly Envoy CVEs plus Istio issues such as a JWKS auth bypass (CVSS 8.7, fixed via ISTIO-SECURITY-2026-001), an AuthorizationPolicy service-account regex bypass, an EnvoyFilter control-plane DoS, and a BackendTLSPolicy plaintext fail-open (fixed in 1.31.1/1.30.4/1.29.7). Run the latest patch of a supported minor. See Reference: Security Bulletins.

Topic Map

Sources

Questions

Open

  • When will ambient multicluster reach stable, and when will primary-remote and single-network topologies be supported? See Reference: Feature Maturity Timeline.
  • When will waypoints support EnvoyFilter-equivalent customization beyond TrafficExtension/Wasm, and when will ambient support VMs?
  • Will agentgateway graduate from experimental, and will it become a default waypoint option for AI/MCP traffic?
  • When will zero-downtime sidecar-to-ambient migration with L7 policies be possible? See How-to: Migrate from Sidecar to Ambient.
  • Upstream data inconsistencies: istio.io lists 1.31/1.30 release dates (Aug 27 / May 14) that differ from the announcement dates (Aug 31 / May 18), and its "no known CVEs" table is stale.

Answered

  • Ambient or sidecar for new deployments? Istio's docs position ambient as the lower-cost default for meshes that start with L4 zero-trust and add L7 selectively. Choose sidecars for VMs, EnvoyFilter users, per-pod proxy customization, or unsupported multicluster topologies. See Explanation: Choosing Sidecar or Ambient.
  • Is ambient production-ready? Yes for single cluster since 1.24 (GA, 2024-11-07); multi-network multicluster ambient is beta since 1.29.