<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Service-Mesh on IT Comparison</title><link>https://comparison.metacog.co.kr/tags/service-mesh/</link><description>Recent content in Service-Mesh on IT Comparison</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 03 Aug 2026 05:32:13 +0900</lastBuildDate><atom:link href="https://comparison.metacog.co.kr/tags/service-mesh/index.xml" rel="self" type="application/rss+xml"/><item><title>Sidecar Pattern vs Ambassador Pattern: General-Purpose Helper vs Network Proxy</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-sidecar-pattern-vs-ambassador-pattern-general-purpose-helper/</link><pubDate>Mon, 03 Aug 2026 05:32:13 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-sidecar-pattern-vs-ambassador-pattern-general-purpose-helper/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;The &lt;strong class="kw"&gt;Sidecar Pattern&lt;/strong&gt; is the general technique of running a helper container alongside your app in the same pod to add any cross-cutting capability — logging, metrics, config sync, or a mesh proxy. The &lt;strong class="kw"&gt;Ambassador Pattern&lt;/strong&gt; is a specific flavor of that sidecar dedicated to one job: sitting between the app and the network, so the app talks to localhost while the ambassador handles the real, often messy, connection to an external service.&lt;/p&gt;</description></item><item><title>Service Mesh vs API Gateway: North-South vs East-West Traffic</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-service-mesh-vs-api-gateway-north-south-vs-east-west-traffic/</link><pubDate>Mon, 03 Aug 2026 05:19:35 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-service-mesh-vs-api-gateway-north-south-vs-east-west-traffic/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;An &lt;strong class="kw"&gt;API gateway&lt;/strong&gt; sits at the edge of your system, managing traffic between external clients and your services. A &lt;strong class="kw"&gt;service mesh&lt;/strong&gt; operates inside the cluster, managing traffic between services themselves. Confusing the two leads teams to either duplicate cross-cutting concerns or push edge-only features into infrastructure that was never designed for public-facing traffic.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="235" y="24" text-anchor="middle" font-size="16" font-weight="bold" style="fill:var(--compare-a)"&gt;API Gateway&lt;/text&gt;&lt;text x="480" y="24" text-anchor="middle" font-size="16" font-weight="bold" style="fill:var(--compare-b)"&gt;Service Mesh&lt;/text&gt;&lt;rect x="20" y="160" width="80" height="50" rx="6" style="fill:none;stroke:var(--content)" stroke-width="1.5"/&gt;&lt;text x="60" y="190" text-anchor="middle" font-size="13" style="fill:var(--content)"&gt;Client&lt;/text&gt;&lt;line x1="100" y1="185" x2="165" y2="185" style="stroke:var(--content)" stroke-width="1.5"/&gt;&lt;polygon points="165,180 175,185 165,190" style="fill:var(--content)"/&gt;&lt;rect x="175" y="130" width="120" height="110" rx="8" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="235" y="158" text-anchor="middle" font-size="12" font-weight="bold" style="fill:var(--compare-a)"&gt;API Gateway&lt;/text&gt;&lt;text x="235" y="178" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;authN · rate limit&lt;/text&gt;&lt;text x="235" y="194" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;routing · transform&lt;/text&gt;&lt;line x1="295" y1="185" x2="335" y2="185" style="stroke:var(--content)" stroke-width="1.5"/&gt;&lt;polygon points="335,180 345,185 335,190" style="fill:var(--content)"/&gt;&lt;rect x="345" y="45" width="270" height="280" rx="10" style="fill:none;stroke:var(--border)" stroke-width="1.5" stroke-dasharray="6,4"/&gt;&lt;text x="480" y="64" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;cluster&lt;/text&gt;&lt;rect x="380" y="85" width="90" height="45" rx="6" style="fill:none;stroke:var(--content)" stroke-width="1.5"/&gt;&lt;text x="425" y="111" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Service A&lt;/text&gt;&lt;rect x="475" y="95" width="22" height="22" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;rect x="380" y="165" width="90" height="45" rx="6" style="fill:none;stroke:var(--content)" stroke-width="1.5"/&gt;&lt;text x="425" y="191" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Service B&lt;/text&gt;&lt;rect x="475" y="175" width="22" height="22" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;rect x="380" y="245" width="90" height="45" rx="6" style="fill:none;stroke:var(--content)" stroke-width="1.5"/&gt;&lt;text x="425" y="271" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Service C&lt;/text&gt;&lt;rect x="475" y="255" width="22" height="22" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;line x1="497" y1="106" x2="497" y2="186" style="stroke:var(--compare-b)" stroke-width="1.5" stroke-dasharray="4,3"/&gt;&lt;line x1="497" y1="186" x2="497" y2="266" style="stroke:var(--compare-b)" stroke-width="1.5" stroke-dasharray="4,3"/&gt;&lt;path d="M497,106 C560,150 560,220 497,266" style="fill:none;stroke:var(--compare-b)" stroke-width="1.5" stroke-dasharray="4,3"/&gt;&lt;text x="600" y="100" text-anchor="end" font-size="10" style="fill:var(--secondary)"&gt;sidecar proxy&lt;/text&gt;&lt;text x="600" y="196" text-anchor="end" font-size="10" style="fill:var(--secondary)"&gt;mTLS · retries&lt;/text&gt;&lt;text x="235" y="345" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;north–south: client-to-service&lt;/text&gt;&lt;text x="480" y="345" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;east–west: service-to-service&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;API Gateway&lt;/th&gt;
&lt;th&gt;Service Mesh&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Traffic direction&lt;/td&gt;
&lt;td&gt;North-south: external clients entering the system&lt;/td&gt;
&lt;td&gt;East-west: internal service-to-service calls&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Deployment topology&lt;/td&gt;
&lt;td&gt;Centralized cluster of edge instances fronting all traffic&lt;/td&gt;
&lt;td&gt;Sidecar proxy injected alongside every service instance&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Primary concerns&lt;/td&gt;
&lt;td&gt;AuthN/authZ, rate limiting, request/response transformation, API versioning&lt;/td&gt;
&lt;td&gt;mTLS, load balancing, retries, circuit breaking between services&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Routing basis&lt;/td&gt;
&lt;td&gt;Public API path, host, or version mapped to a backend service&lt;/td&gt;
&lt;td&gt;Service identity and destination within the internal network&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Observability scope&lt;/td&gt;
&lt;td&gt;Per-endpoint metrics: request volume, latency, errors by client&lt;/td&gt;
&lt;td&gt;Full service dependency graph: per-hop latency and error rates&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Failure containment&lt;/td&gt;
&lt;td&gt;Blocks or throttles bad traffic before it reaches any backend&lt;/td&gt;
&lt;td&gt;Isolates failures at individual hops so one bad service doesn&amp;rsquo;t cascade&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Operational overhead&lt;/td&gt;
&lt;td&gt;Few instances to scale and configure centrally&lt;/td&gt;
&lt;td&gt;One proxy per workload, plus a control plane to manage them all&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An &lt;strong class="kw"&gt;API gateway&lt;/strong&gt; is the single entry point clients hit; a &lt;strong class="kw"&gt;service mesh&lt;/strong&gt; has no single entry point, it&amp;rsquo;s woven through every service.&lt;/li&gt;
&lt;li&gt;Gateways enforce policy once at the edge; meshes enforce policy per &lt;strong class="kw"&gt;sidecar&lt;/strong&gt; on every call.&lt;/li&gt;
&lt;li&gt;Gateways typically run as a small number of centralized instances; meshes scale linearly with your &lt;strong class="kw"&gt;service count&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Meshes give you &lt;strong class="kw"&gt;mTLS&lt;/strong&gt; and retries between internal services, something a gateway never sees because that traffic never reaches it.&lt;/li&gt;
&lt;li&gt;Many production systems run both together, not as alternatives, since they solve problems at different layers.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;API Gateway&lt;/strong&gt;&lt;/p&gt;</description></item></channel></rss>