Interview Istio & Service Mesh

What is istiod, and what does it do?

Istio & Service Mesh · Basic level

Answer

istiod is Istio's main control-plane service. It combines service discovery, configuration translation, certificate authority functions, and sidecar-injection support so the mesh proxies receive the right configuration and workload identity.

Technical explanation

istiod watches Kubernetes Services, Endpoints, pods, namespaces, and Istio CRDs.

It pushes Envoy configuration through xDS, including listeners, routes, clusters, endpoints, and secrets.

It also supports workload certificate issuance and rotation so mTLS can be automatic rather than manually managed per service.

Hands-on example

Useful commands:

$ kubectl -n istio-system get deploy,svc,pods -l app=istiod

$ kubectl -n istio-system logs deploy/istiod --tail=100

$ istioctl proxy-status

When proxies are stale or rejected, compare istiod logs with the proxy-status output before changing application code.

Preparing for an interview?

Check how well your resume matches the role with our free resume checker— match score, ATS check, and the skills you're missing.

More Istio & Service Mesh interview questions

← All Istio & Service Mesh questions