⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All AWS & Cloud Architecture Interview Questions Scenario 186 of 186 in AWS & Cloud Architecture
Staff Cloud Architect Multi-Cloud Service Mesh & Zero Trust Service Mesh Architecture

Q: Your microservices architecture spans AWS EKS and Azure AKS with distinct VPC/VNet subnets. Services in AWS need to discover and securely call services in Azure over encrypted mTLS without exposing internal APIs to the public internet. How do you design and deploy Istio multi-primary multi-network service mesh across AWS and Azure?

Production guide for engineering a secure cross-cloud service mesh connecting AWS EKS and Azure AKS using Istio Multi-Primary on different networks with East-West Ingress Gateways and mutual TLS (mTLS).

#Multi-Cloud #Istio #Service Mesh #EKS #AKS #mTLS #Zero Trust
🎙️ Candidate Opening & Architectural Context
"Direct cross-cloud service-to-service communication often devolves into public REST endpoints protected only by fragile API keys. We engineered an Istio multi-primary multi-network mesh across EKS and AKS, providing transparent mutual TLS encryption and cross-cluster service discovery."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Establish Shared Root Certificate Authority (CA) Across Clouds

Create cryptographic mutual trust between Istio control planes in AWS and Azure:

  • Shared Root CA: Generated an offline enterprise root CA certificate and intermediate CAs for aws-cluster and azure-cluster.
  • Secret Injection: Injected intermediate CA certs into istio-system namespace as cacerts Kubernetes Secret in both EKS and AKS.
Pro Tip: Pods in AWS and Azure can only validate each other's mTLS SPIFFE identities if both Istio control planes chain up to the identical root CA.
2️⃣

Deploy Istio East-West Gateways in Each Cluster

Establish dedicated perimeter ingress gateways for cross-cluster traffic:

  • East-West Deployment: Deployed istio-eastwestgateway in EKS and AKS with internal/cross-cloud network load balancers.
  • Expose Services: Applied expose-services.yaml configuring the East-West gateway to proxy SNI passthrough traffic for internal *.global services.
Pro Tip: East-West gateways handle cross-cluster mTLS traffic without decrypting the payload, preserving end-to-end pod-to-pod encryption.
3️⃣

Configure Remote Cluster Endpoint Discovery via Istio Secret

Enable Istiod in AWS to discover pods running in Azure and vice-versa:

  • Generate Remote Secret: Executed istioctl create-remote-secret --context=aks-context --name=azure-cluster | kubectl apply -f - --context=eks-context.
  • Service Endpoint Sync: Istiod watches API server endpoints in both clusters, dynamically programming Envoy sidecars with endpoints in both clouds.
Pro Tip: Remote secrets grant read-only access to endpoints and namespaces, enabling automatic cross-cloud service discovery.
4️⃣

Execute Cross-Cloud Request & Validate End-to-End mTLS

Call an Azure service directly from an AWS pod using standard Kubernetes DNS:

  • DNS Invocation: Pod in AWS EKS sends HTTP request to http://payment-service.payments.svc.cluster.local.
  • Envoy Routing: Local Envoy sidecar intercepts call, detects endpoint resides in Azure, establishes mTLS connection via Azure East-West Gateway, and delivers packet directly to target pod in AKS.
  • Telemetry: Inspected mTLS connection in Kiali dashboard: confirmed 100% mTLS cipher suites and zero plain-text packet exposure.
Pro Tip: Developers write standard Kubernetes DNS names with zero code awareness that target microservices are executing in a completely different cloud provider.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Istio Multi-Primary on different networks connects AWS EKS and Azure AKS with transparent mTLS, cross-cluster service discovery, and East-West gateways without requiring flat network IP peering."
⚡ 60-Second Elevator Pitch Talking Points
  • Establish a shared enterprise root CA across both AWS EKS and Azure AKS Istio deployments.
  • Deploy Istio East-West Gateways with SNI passthrough to bridge cross-cloud network boundaries.
  • Configure remote secrets to allow Istiod to discover cross-cloud endpoints automatically.
  • Achieve seamless, transparent pod-to-pod mTLS communication across clouds using standard K8s DNS.
Advertisement
Want more AWS & Cloud Architecture scenarios?
Explore our complete collection of scenario-based AWS & Cloud Architecture interview runbooks.
Browse All AWS & Cloud Architecture Questions →