1 of 17

KCD

BLR

2025

Setting up Hybrid Workloads with

Istio on Kubernetes

Kubestronaut,

DevOps Engineer @ Convin.AI

Sayed Imran

2 of 17

    • Why workloads on VM ?
    • Service Mesh & Istio
    • Gateways in Istio
    • WorkloadGroup & WorkloadEntry
    • Demo + Simulation

Agenda

3 of 17

    • Legacy Applications
      • Due to compatibility constraints and dependencies on traditional infrastructure.
    • Security and Compliance
      • Enhanced control over security and compliance related requirements and policies.
    • Gradual Migration
      • Allowing legacy workloads to transition to modern architectures at their own pace.
    • Handling Stateful Applications
      • Stable environments with persistent storage and networking.

Why Workloads on VM ?

4 of 17

Service Mesh

Istio

5 of 17

A service mesh is a dedicated infrastructure layer that manages service-to-service communication in a microservices architecture.

Service Mesh

    • Security
      • enforcing mTLS encryption, authentication, and fine-grained access control
    • Traffic Management
      • easy to set up important tasks like A/B testing, canary rollouts, and staged rollouts
    • Observability
      • built-in tracing, metrics, and logging for better monitoring
    • Resilience
      • load balancing, retries, failovers, and circuit breakers to prevent cascading failures

6 of 17

Istio extends Kubernetes to establish a programmable, application-aware network and brings standard, universal traffic management, telemetry, and security to complex deployments.

Istio

7 of 17

Gateways in

Istio

8 of 17

Ingress Gateway in Istio manages external traffic entering the mesh, acting as a controlled entry point. It allows users to expose internal services securely using Istio’s Gateway and VirtualService resources.

Ingress Gateway

9 of 17

East-West Gateway enables communication between services across multiple clusters or between Kubernetes and VM workloads. It helps extend Istio’s service mesh beyond a single cluster.

East-West Gateway

10 of 17

WorkloadGroup &

WorkloadEntry

11 of 17

WorkloadGroup describes a collection of workload instances. It provides a specification that the workload instances can use to bootstrap their proxies, including the metadata and identity

WorkloadGroup

WorkloadGroup enables specifying the properties of a single workload for bootstrap and provides a template for WorkloadEntry, similar to how Deployment specifies properties of workloads via Pod templates

12 of 17

WorkloadEntry enables operators to describe the properties of a single non-Kubernetes workload such as a VM or a bare metal server as it is onboarded into the mesh.

WorkloadEntry

13 of 17

Demo Time!

14 of 17

Animal Album App

15 of 17

Live Application

16 of 17

Social Links

17 of 17

THANK YOU