2V0-71.23 Question 37
Select 4An organization is deploying a Tanzu Kubernetes cluster and wants to enable a service mesh to enhance its microservices architecture. The team is particularly concerned with securing service-to-service communication, monitoring traffic between services, and ensuring fault tolerance. Which features provided by a service mesh directly address these concerns?
- A
Mutual TLS (mTLS) for securing communication between services
- B
Load balancing to distribute requests across service replicas
- C
Automatic scaling of pods based on resource utilization
- D
Observability through metrics, tracing, and logging of service traffic
- E
Service discovery for locating services within the cluster
- F
Traffic shaping and resiliency mechanisms such as retries and timeouts
Show answer and explanation
Correct answers: A, B, D, F
Explanation
Service meshes like Tanzu Service Mesh provide features such as mutual TLS for securing service-to-service communication, observability for monitoring traffic, load balancing to improve reliability, and resiliency mechanisms to handle faults. These features are essential for managing microservices at scale and addressing concerns related to security, monitoring, and fault tolerance. However, certain functions like pod scaling and service discovery are not directly provided by a service mesh and are typically handled by Kubernetes or related systems.
- A. Correct.
Mutual TLS (mTLS) is a core feature of a service mesh that ensures secure communication between services by encrypting data in transit and authenticating service identities.
- B. Correct.
Load balancing is often implemented by a service mesh to distribute traffic across service replicas, improving fault tolerance and availability.
- C. Incorrect.
Pod scaling is not a direct feature of a service mesh; it is typically handled by Kubernetes through Horizontal Pod Autoscalers (HPA).
- D. Correct.
Observability is a key feature of service meshes, providing insights into service traffic, latency, and errors through metrics, distributed tracing, and logging.
- E. Incorrect.
Service discovery is typically managed by Kubernetes itself or external tools, not specifically by a service mesh.
- F. Correct.
Traffic shaping and resiliency mechanisms like retries, timeouts, and circuit breaking are integral to service meshes, helping to ensure fault tolerance and maintain service reliability.