Istiovs
Asana


Asana: Manage your team's work, projects, & tasks online

A Kubernetes service mesh that adds mutual TLS, traffic control and telemetry between services without changing application code.
As of 30 August 2026, Istio is free to use. Istio puts an Envoy proxy in front of every workload so that encryption, retries, traffic splitting and per-request metrics are configured centrally rather than written into each service. Softwr lists it under Technology.
Overview
Istio is a service mesh for Kubernetes, originally created by Google, IBM and Lyft, and now a graduated project of the Cloud Native Computing Foundation, licensed under Apache 2.0. It uses Envoy as its data plane and a control plane component, istiod, that issues workload identities, distributes certificates and translates its custom resources into Envoy configuration. In the classic sidecar mode an Envoy container is injected into every pod; ambient mode, which reached general availability in Istio 1.24, replaces that with a per-node ztunnel for L4 and optional waypoint proxies for L7. It supports both its own API and the Kubernetes Gateway API. What distinguishes it is that it moves cross-cutting network behaviour out of application code and into infrastructure that a platform team owns. Mutual TLS with automatic certificate rotation, retries with budgets, timeouts, circuit breaking, canary traffic splitting by weight or header, and identical golden metrics and distributed traces for every service arrive without a library in any language. In a polyglot estate that is the commercial argument in full: without a mesh, each of those behaviours has to be implemented and kept current in every language your teams use, and it never is. With one, the security team can assert that all service-to-service traffic is encrypted and authenticated as a property of the platform. The organisations for which this works have a dedicated platform team, dozens or hundreds of services, and a compliance or reliability requirement that justifies the machinery. The trade-off is that the mesh becomes infrastructure you now operate. Upgrades require revisioned control planes and restarting every workload, misconfiguration surfaces as an opaque 503 rather than a validation failure, and below a certain scale a cloud load balancer or Linkerd delivers most of the benefit with far fewer moving parts, which is why the mesh so often becomes the largest single source of incidents in a small estate.
The honest half
Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about Istio.
Cross-shopped
Each pairing was judged by two reviewers asking whether a buyer would genuinely weigh the two against each other. The ones that failed were deleted rather than published.


Asana: Manage your team's work, projects, & tasks online


ClickUp: One app to replace them all


Linear: The issue tracking tool you'll enjoy using


Figma: The collaborative interface design tool
Pricing
Taken from the vendor's own pricing page. Prices move, so check before you buy.
Open Source
Free
Capabilities
Automatic mutual TLS
Encrypts and authenticates service-to-service traffic with issued workload identities and rotating certificates, without code changes
Traffic splitting
Shifts a percentage of requests, or requests matching a header, to a new version for canary and blue-green releases
Resilience policies
Per-route timeouts, retries with budgets, circuit breakers and outlier detection applied centrally
Authorization policies
Allow and deny rules on service-to-service calls based on workload identity, namespace, method and path
Uniform telemetry
Consistent request metrics, distributed tracing spans and access logs for every workload regardless of language
Ambient mode
A sidecar-free architecture using a per-node ztunnel for L4 and waypoint proxies only where L7 features are needed
Gateway API support
Implements the Kubernetes Gateway API alongside its own Gateway and VirtualService resources
Multi-cluster mesh
Joins several Kubernetes clusters into one mesh with shared identity and cross-cluster service discovery
Answered, with sources
Each answer names the page it came from, so you can check it rather than take our word for it.
Only if you have enough services, or a compliance requirement, that implementing mTLS, retries and tracing per language has become unmanageable. Below roughly a few dozen services, an ingress controller plus good client libraries usually delivers more reliability for less operational cost.
Ambient removes the per-pod proxy and its startup ordering problems and costs less at high pod counts, but it is a newer architecture and does not cover every sidecar feature. New deployments should evaluate ambient first; existing sidecar meshes should treat the move as a migration project.
Linkerd is deliberately smaller, uses its own Rust proxy rather than Envoy, and is quicker to operate; Istio has a far larger feature surface, multi-cluster and VM support, and broader vendor backing. Note that Linkerd's stable distribution builds are commercially licensed by Buoyant, whereas Istio's releases are freely available.
Solo.io and Tetrate sell supported distributions and control planes, and Google offers Cloud Service Mesh as a managed option. The upstream project itself is CNCF-governed with community support.
Partly. Virtual machine workloads can be added to a mesh, but the tooling, documentation and community experience are heavily Kubernetes-centred, so a VM-majority estate is fighting the grain of the project.
Keep looking
A high-performance L7 proxy written in C++ that is configured by an API rather than a config file, and is usually deployed under a control plane.
Cloud native core banking where products are written as smart contracts
A distributed key-value store using Raft consensus, built for cluster coordination rather than application data.
A distributed SQL engine that queries data where it already lives, across object storage, warehouses and operational databases.
The single platform to analyze, test, observe, and deploy new features
Google's browser, built on Chromium, with the largest market share and the strictest limits on what extensions may do.
An independent web browser with its own rendering engine, funded almost entirely by search placement deals.
Softwr does not host reviews and shows no star rating for Istio, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.
What people switch to, and what they give up
Every tier, and where the cost actually lands
Put it head to head with anything we hold
Its rating, and an embed for your own site
Secure access for everyone
The digital analytics platform to understand your users
Apple's WebKit browser, available only on Apple operating systems and updated only with them.
free