Q: Your microservices architecture spans AWS EKS and Azure AKS with distinct VPC/VNet subnets. Services in AWS need to discover and securely call services in Azure over encrypted mTLS without exposing internal APIs to the public internet. How do you design and deploy Istio multi-primary multi-network service mesh across AWS and Azure?
Production guide for engineering a secure cross-cloud service mesh connecting AWS EKS and Azure AKS using Istio Multi-Primary on different networks with East-West Ingress Gateways and mutual TLS (mTLS).
Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Establish Shared Root Certificate Authority (CA) Across Clouds
Create cryptographic mutual trust between Istio control planes in AWS and Azure:
- Shared Root CA: Generated an offline enterprise root CA certificate and intermediate CAs for
aws-clusterandazure-cluster. - Secret Injection: Injected intermediate CA certs into
istio-systemnamespace ascacertsKubernetes Secret in both EKS and AKS.
Deploy Istio East-West Gateways in Each Cluster
Establish dedicated perimeter ingress gateways for cross-cluster traffic:
- East-West Deployment: Deployed
istio-eastwestgatewayin EKS and AKS with internal/cross-cloud network load balancers. - Expose Services: Applied
expose-services.yamlconfiguring the East-West gateway to proxy SNI passthrough traffic for internal*.globalservices.
Configure Remote Cluster Endpoint Discovery via Istio Secret
Enable Istiod in AWS to discover pods running in Azure and vice-versa:
- Generate Remote Secret: Executed
istioctl create-remote-secret --context=aks-context --name=azure-cluster | kubectl apply -f - --context=eks-context. - Service Endpoint Sync: Istiod watches API server endpoints in both clusters, dynamically programming Envoy sidecars with endpoints in both clouds.
Execute Cross-Cloud Request & Validate End-to-End mTLS
Call an Azure service directly from an AWS pod using standard Kubernetes DNS:
- DNS Invocation: Pod in AWS EKS sends HTTP request to
http://payment-service.payments.svc.cluster.local. - Envoy Routing: Local Envoy sidecar intercepts call, detects endpoint resides in Azure, establishes mTLS connection via Azure East-West Gateway, and delivers packet directly to target pod in AKS.
- Telemetry: Inspected mTLS connection in Kiali dashboard: confirmed 100% mTLS cipher suites and zero plain-text packet exposure.
- Establish a shared enterprise root CA across both AWS EKS and Azure AKS Istio deployments.
- Deploy Istio East-West Gateways with SNI passthrough to bridge cross-cloud network boundaries.
- Configure remote secrets to allow Istiod to discover cross-cloud endpoints automatically.
- Achieve seamless, transparent pod-to-pod mTLS communication across clouds using standard K8s DNS.