Kmesh is a high-performance and low overhead service mesh data plane based on eBPF and programmable kernel. Kmesh brings traffic management, security and monitoring to service communication without needing application code changes. It is natively sidecarless, zero intrusion and without adding any resource cost to application container.
Service mesh software represented by Istio has gradually become popular and become an important component of cloud native infrastructure. However, there are still some challenges faced:
Kmesh transparently intercept and forward traffic based on node local eBPF without introducing extra connection hops, both the latency and resource overhead are negligible.
Kmesh Architecture
The main components of Kmesh include:
Kmesh innovatively sinks Layer 4 and Simple Layer 7 (HTTP) traffic governance to the kernel, and build a transparent sidecarless service mesh without passing through the proxy layer on the data path.
Simple Mode
Kmesh also provide an advanced mode, which makes use of eBPF and waypoint to process L4 and L7 traffic separately, thus allow you to adopt Kmesh incrementally, enabling a smooth transition from no mesh, to a secure L4, to full L7 processing.
Advanced Mode
Smooth Compatibility
High Performance
Low Resource Overhead
Zero Trust
Safety Isolation
Open Ecology
Please refer to quick start and user guide to try Kmesh quickly.
Based on Fortio, the performance of Kmesh and Envoy was tested. The test results are as follows:
For a complete performance test result, please refer to Kmesh Performance Test.
If you have any question, feel free to reach out to us in the following ways:
If you're interested in being a contributor and want to get involved in developing Kmesh, please see CONTRIBUTING for more details on submitting patches and the contribution workflow.
The Kmesh user space components are licensed under the Apache License, Version 2.0. The BPF code templates, ko(kernel module) and mesh data accelerate are dual-licensed under the General Public License, Version 2.0 (only) and the 2-Clause BSD License (you can use the terms of either license, at your option).
This project was initially incubated in the openEuler community, thanks openEuler Community for the help on promoting this project in early days.