Sidecarless service mesh choices in 2026
Istio 1.24 Ambient mesh offers up to 90% memory savings for L4 workloads by replacing per-pod sidecars with ztunnels. Choosing between Istio, Linkerd, and Cilium requires balancing deep L7 traffic management against operational complexity and kernel-level security risks.
The end of per-pod sidecars
Istio 1.24 brings Ambient mesh to General Availability, which replaces per-pod Envoy sidecars with node-level ztunnels and namespace-level waypoints. This architecture provides up to 90% memory savings for L4-only workloads, though savings drop to 80% when waypoints are included for L7 traffic. The ztunnel handles mTLS and basic L4 routing for every pod on a node using cryptographic identity, while waypoints process L7 functions like traffic routing, retries, and load balancing. Cilium uses eBPF to handle networking in the kernel without proxies, while Linkerd uses a lightweight Rust micro-proxy. You should know that moving away from sidecars changes your entire operational model.
| Feature | Istio Ambient | Cilium eBPF | Linkerd |
|---|---|---|---|
| Data Plane | ztunnel & Waypoint | eBPF & Envoy (optional) | Rust micro-proxy |
| mTLS | SPIFFE | SPIFFE / WireGuard | Identity-based |
| L7 Management | Waypoint Envoy | Envoy (optional) | Basic |
Istio Ambient simplifies adoption by allowing users to add or remove applications by labeling a namespace. This removes the need to restart application pods during upgrades. However, Ambient introduces a multi-tier data plane. An L7 request follows a path from the source ztunnel to a waypoint proxy and then to the destination ztunnel. This adds more hops for troubleshooting compared to the Linkerd model. Linkerd maintains a single proxy type per pod, which keeps the upgrade process simpler. Traditional sidecars add 50 to 100 MB of memory per pod and 1 to 3 ms of latency per hop.
Management complexity and upgrade paths
The upgrade of Istio Ambient requires coordinating three different components: istiod, the node-level ztunnels, and the namespace-level waypoints. This creates a compatibility matrix that Linkerd avoids with its two-tier control plane and data plane model. Linkerd 2.20 remains the current upstream line, but the open source project stopped shipping its own stable release artifacts in February 2024. Companies with 50 or more employees must use a paid subscription from Buoyant to access stable releases. Linkerd developers provide a CLI-first workflow that returns golden metrics like success rate, requests per second, and latency percentiles.
Istio Ambient provides deep L7 traffic management like canary deployments and fault injection, but these features depend on the deployment and scaling of waypoint proxies. If a team enables L7 features, the request path gains extra hops that can complicate incident response. A failure in a shared ztunnel affects every workload on that node, whereas a Linkerd micro-proxy failure only impacts a single pod. Istio 1.24 also improved Envoy logs to show more error details when connection failures occur in ambient mode. The convergence of eBPF and sidecarless architectures means that the decision between Istio, Linkerd, and Cilium rests on how your team manages the complex trade-off between deep feature sets and the need for operational simplicity.
Cilium provides a unified stack where the CNI, network policy, and service mesh live together in the kernel. This makes it a strong choice for teams already using Cilium for pod networking. Cilium provides L7 enforcement through the Kubernetes Gateway API and Cilium Network Policies. You can specify HTTP rules, such as allowed methods or specific paths, within a CiliumNetworkPolicy resource. Cilium also uses Maglev-consistent hashing and EDT-based rate limiting for traffic management.
Security risks in the kernel and the control plane
Cilium Service Mesh introduces a security risk because its mutual authentication mechanism uses an eventual consistency model. This design creates a window where unauthenticated packets might be accepted before the authentication verification is solidified. In dynamic Kubernetes environments, this lag can expose the system to malicious traffic. Also, Cilium does not inherently encrypt traffic between services and requires explicit configuration of WireGuard or IPSec for data confidentiality. Identity-based authorization in Cilium relies on pod labels, namespaces, or IP addresses to regulate access.
Performance results for 2025 show that Linkerd leads in high-load scenarios. At 2000 requests per second, Linkerd finished 11.2ms ahead of Istio Ambient. Cilium is often the fastest for L3/L4 traffic because eBPF operates in kernel space. An academic benchmark from October 2025 found Istio Ambient delivered more queries per core than Cilium in a specific 50,000-pod test. Istio Ambient improves upon the classic sidecar model, but it remains heavier than the eBPF approach for pure L3/L4 workloads.
If you require the most advanced L7 traffic shaping, Istio is the clear winner. For those who want the lowest latency for L3/L4 traffic, Cilium is the best option. Users migrating to Istio ambient reported a 45% reduction in container counts. Does the reduction in resource consumption outweigh the increased complexity of managing multi-tier data planes?