Calico Cluster Mesh: Secure Microservices Communication, Simplified

By Greg Tavarez, TMCnet Editor  |  June 25, 2024

The following is an analogy I have used occasionally in my articles. Let's get into it.

Managing microservices environments is a double-edged sword. On one hand, breaking down applications into independent services offers scalability and easier maintenance. But on the other hand, the web of interactions between these services becomes overwhelming.

Traditional methods of managing these interactions often involve code modifications within each microservice. However, this leads to redundancies and inconsistencies, especially as the number of services grows. Additionally, troubleshooting issues becomes more complex as faults can cascade across services.

Service meshes are a promising solution, but they're not a silver bullet. Implementing a service mesh adds another layer of infrastructure that requires configuration, operation, and maintenance. This strains already limited resources of platform owners, DevOps teams and SREs.

The ideal solution would simplify all communication between microservices without adding extra complexity. This would allow developers to focus on the core functionalities of each service and reduce the burden on operations teams. Taking its next step toward making that ideal solution is Tigera, the creator of Project Calico.

Tigera provides secure networking and complete protection for containers and Kubernetes. Tigera's Calico Cloud is a container security platform with built-in network security to prevent, detect, troubleshoot and automatically mitigate exposure risks of security breaches.

Tigera recently announced it is delivering its approach to secure microservices communication with Calico Cluster Mesh, a lightweight service mesh. Calico Cluster Mesh delivers the benefits of a service mesh without the added complexity and latency of a traditional service mesh solution.

Tigera's approach has proven effective, with one of the largest options exchanges globally using Calico Cluster Mesh to ensure low-latency networking and security for multi-cluster Kubernetes deployment.

Calico enables a single-pane-of-glass unified control to address three popular service mesh use cases — security, observability and control — with an operationally simpler approach.

Calico Cluster Mesh simplifies managing complex microservice deployments across multiple clusters. It eliminates the need for complex network configuration by offering a smooth service-to-service connectivity. Developers can use workload communication that works across various network types, along with a choice of TOR or Overlay VXLAN networking for added flexibility. Additionally, Calico Cluster Mesh simplifies cross-cluster communication with built-in DNS connectivity.

Furthermore, Calico Cluster Mesh equips users with comprehensive service discovery and security features. It enables the discovery of remote services across clusters and facilitates secure interaction between them. The lightweight service mesh enforces consistent network security controls.

Calico Cluster Mesh also provides centralized observability and troubleshooting across clusters. This allows users to visualize workload communication, identify security gaps and enforce network security controls efficiently.

"Calico Cluster Mesh empowers today's IT and security teams with the capabilities they need to achieve their goals, without adding complexities or costs," said Amit Gupta, Chief Product Officer, Tigera. "Tigera's lightweight service mesh approach, delivered through Calico Cluster Mesh, reinforces our dedication to providing simple, scalable, cost-effective solutions."

With Calico, users easily achieve full-stack observability and security, deploy highly performant encryption and tightly integrate with existing security infrastructure like firewalls.




Edited by Alex Passett
Get stories like this delivered straight to your inbox. [Free eNews Subscription]