Project Lightning Talk: Optimize Sidecarless Service Mesh With A Brand-New Rust-Base... Zengzeng Yao
About this talk
This talk covers the optimization of sidecar service meshes through the introduction of Kmesh, an eBPF-based sidecar traffic management engine developed by Huawei. The speaker discusses the challenges posed by traditional sidecar meshes, including high resource overhead and increased latency. Kmesh offers a dual engine mode that combines kernel native processing for L4 with user space handling for L7 tasks, utilizing the waypoint proxy. The Orion proxy, built in Rust, is presented as a lightweight and memory-safe alternative to Envoy, designed to remove unnecessary complexity and leverage modern capabilities. Benchmarks show that Orion achieves significantly higher performance and lower latency than Envoy, making it a suitable replacement for Kuma's needs. The integration of Kmesh and Orion aims to provide a service mesh solution that maximizes performance across all layers while eliminating C++ safety risks.
Full transcript
Hello everyone. I'm Youting Ding from Huawei. And my topic today is optimized sidecar service mesh with a brand new rust based uh proxy. As we know, traditional sidecar mesh paved the way. But they brought uh heavy trade-offs, tighter tight application coupling, massive resources overhead at scale, and the latency from extra network hoops to solve this uh problem. We built Kmesh, an eBPF based sidecar traffic management engine
that delivers high performance with low overhead. Kmesh has has two modes, uh kernel native for absolute best performance, and a dual engine mode. Today, we are diving into the dual Uh by offloading L4 uh to the kernel and uh keeping L7 in user space, uh it provides the the perfect balance of versatility and the performance for most environments. Let's jump in. Uh Kmesh is sidecarless, but we
still need L4 L7 processing. Enter the waypoint proxy. eBPF handle L4 uh at native speeds, and we only route complex L7 uh tasks to the waypoint if it's necessary. Currently, we use Envoy as our waypoint. Envoy is an amazing project, but looking ahead, it presents uh three hurdles for us. First, it's written in C++, uh carrying inherent memory safety risks. Second, it's a heavy and a uh
due to years of historical baggage. And the third, the architecture yeah, shouldn't wasn't built for to deeply integrate with eBPF in an side car less world. So, we built Orion in Huawei. Orion proxy is a high performance and memory safe implementation of proxy. Orion is implemented in Rust using high quality open source components. Uh when designing Orion, we made a conscious choice not to implement every single
Envoy API and filter. Uh while Envoy is powerful, it has also massive, highly complex, and it carries some legacy baggage uh that most modern meshes uh simply don't need. Instead, we took a pragmatic approach. Uh we implemented only the essential APIs and filters. Uh this laser focus uh keeps Orion incredibly lightweight, uh simple to maintain, and uh highly performant. To validate our approach, we ran comprehensive benchmarks
comparing Orion directly against Envoy. Uh the results clearly shows uh payoff of a simple design. Orion delivers 2x to 4x high performance high throughput along with dramatically early lower latency. In the near future, Orion is Kuma's purpose-built Rust replacement for Envoy uh as a L7 waypoint proxy. Compared to Envoy, the key advantages uh are performance, memory safety, and a much lighter footprint. And there's a freedom to
optimize uh specifically specifically for the Kuma's use case without carrying Envoy's the kid of legacy complexity. For replacement process progress, the end-to-end path is already working. Orion runs in a real Kmesh cluster alongside Istio D. Performance and integrate natively with Kmesh's eBPF layer. As the next phase is performance tuning and hardening for production. The big picture is the company combination. Kmesh already achieved extreme L4 performance via
eBPF in the kernel. With Orion on the L7 side, we complete the picture a service mesh where every layer operates at its theoretical performance ceiling with no C++ C++ safety baggage anywhere in the data path. And uh thank you. And uh welcome to join the Kmesh community.
More from this event
See all 436 talks →
Best of KubeCon + CloudNativeCon Amsterdam 2026
2:17
The Quiet Work of Forever: Sustaining Open Source Communities - O. Hope Amaechi-Okorie, JSON Schema
26:24
Evolving KServe: The Unified Model Inference Platform for Both Predictive and... F. Spolti & J. Lee
32:40
Preventing S3 Cost Storms: Applying Cortex’s Efficiency Lessons to I/O-Heav... A. Fishman-Lichterman
5:32