Interview Istio & Service Mesh

What is the difference between an Istio ingress gateway and an egress gateway?

Istio & Service Mesh · Basic level

Answer

An ingress gateway controls traffic entering the mesh from outside, while an egress gateway controls traffic leaving the mesh to external services. Ingress is about exposing internal services safely; egress is about centralizing and auditing outbound access.

Technical explanation

Ingress gateway concerns include TLS termination, WAF/load-balancer integration, host routing, and external client authentication.

Egress gateway concerns include restricting destinations, consistent TLS origination, network allowlisting, and audit logs for outbound calls.

Both are data-plane proxies, but their security boundaries and operational runbooks are different.

Hands-on example

Egress use case:

Only the istio-egressgateway has firewall access to api.partner.com.

Workloads call the external host through ServiceEntry and VirtualService.

Network teams allow outbound internet only from the egress gateway nodes or security group, giving a single audited path.

Preparing for an interview?

Check how well your resume matches the role with our free resume checker— match score, ATS check, and the skills you're missing.

More Istio & Service Mesh interview questions

← All Istio & Service Mesh questions