DevNet Associate (DEVASC) v1.0Application Deployment and SecurityMedium

A development team is designing a new microservice architecture where services need to communicate with each other over HTTP/HTTPS. They want to implement fine-grained access control and enforce policy-based routing between services without modifying the application code. Which architectural pattern or tool is best suited for this requirement?

  1. ALoad Balancer
  2. BAPI Gateway
  3. CMessage Queue
  4. DService Mesh
Show answer & explanation

Correct answer: D. Service Mesh

A service mesh, such as Istio or Linkerd, provides capabilities like traffic management, policy enforcement, and mutual TLS between services without requiring changes to the application code. It operates at the infrastructure layer, using sidecar proxies to intercept and manage all network communication between services.

Why the other options are wrong

  • A. A Load Balancer distributes incoming traffic to multiple instances of a service but lacks the advanced policy enforcement and fine-grained control capabilities of a service mesh.
  • B. An API Gateway handles ingress traffic and authentication/authorization at the edge but doesn't typically manage inter-service communication policies within the cluster.
  • C. A Message Queue is used for asynchronous communication and decoupling services, not for enforcing network policies or routing HTTP/HTTPS traffic directly.

Service Mesh

A service mesh is a dedicated infrastructure layer that handles inter-service communication, providing capabilities like traffic management, observability, security (e.g., mTLS), and policy enforcement without modifying application code.

  • Manages inter-service communication.
  • Uses sidecar proxies.
  • Provides traffic management, security, observability.
  • Decouples application logic from network concerns.

Memory trick: Mesh manages all service traffic, like a smart network.

More Application Deployment and Security questions