Lesson 26 / 26

Revision: Cheat Sheet and Self-Check

Review the concepts, policies and operating habits from the whole course.

Cheat sheet

Concepts: gateway = north-south edge policy; mesh = east-west with sidecar data plane + control plane; reverse proxy/LB/Ingress/Gateway API fit around them. Routing: path/host/header, prefix stripping, request ID, weighted canary (9:1 gave 90/10), header opt-in. Security: 401 vs 403, API keys vs JWT/OAuth, token-bucket rate limits with 429 + Retry-After, TLS termination, WAF, CORS. Resilience: explicit shrinking timeouts (504), retries only idempotent and at one layer (amplification 3, 9, 27, 81), circuit breaker closed/open/half-open, outlier detection, least-load and consistent hashing. Mesh: mTLS workload identity, default-deny authz, policy as YAML, golden signals + trace propagation. Ops: thin gateway, HA across zones, config as code + validation, staged upgrades, bypass, failure drills. Delivery: shadow, canary, blue-green, automated promotion.

Questions interviewers ask

Be ready to explain: the difference between an API gateway and a service mesh, what a sidecar does, how mTLS works and why short-lived certificates help, how you would implement a canary, how retries can cause a retry storm and how to prevent it, how a circuit breaker works, and when you would not adopt a mesh.

Quick check: A downstream service is failing. Calls pile up and the gateway runs out of connections. Which combination helps most?

  • Timeouts plus a circuit breaker with a fallback
  • Longer timeouts and more retries
  • Disable health checks
  • Remove rate limits
Answer

Timeouts plus a circuit breaker with a fallback — Fail fast and stop calling the broken dependency so resources are freed.

Quick check: Why is `hash(key) % N` a poor way to pick a cache server when N changes?

  • It makes keys longer
  • It is too slow to compute
  • It is illegal
  • Most keys map to a different server, causing mass cache misses
Answer

Most keys map to a different server, causing mass cache misses — Consistent hashing moves only about 1/N of keys when a node is added.

Quick check: What does a mesh need so that services can trust the identity of callers?

  • Shared passwords in code
  • mTLS with workload certificates issued by the mesh CA
  • IP address allow-lists only
  • Longer DNS names
Answer

mTLS with workload certificates issued by the mesh CA — Cryptographic identities allow policies that do not depend on network location.