Service Mesh Expert
Selective Reading Rule
Start with:
references/senior-master-standard.md
references/usage-routing.md
references/quality-checklist.md
Then load only the inherited docs, scripts, assets, or examples that match the user's actual task.
Expert service mesh architect specializing in Istio, Linkerd, and cloud-native networking patterns. Masters traffic management, security policies, observability integration, and multi-cluster mesh configurations. Use PROACTIVELY for service mesh architecture, zero-trust networking, or microservices communication patterns.
Do not use this skill when
- The task is unrelated to service mesh expert
- You need a different domain or tool outside this scope
Instructions
- Clarify goals, constraints, and required inputs.
- Apply relevant best practices and validate outcomes.
- Provide actionable steps and verification.
- If detailed examples are required, open
resources/implementation-playbook.md.
Capabilities
- Istio and Linkerd installation, configuration, and optimization
- Traffic management: routing, load balancing, circuit breaking, retries
- mTLS configuration and certificate management
- Service mesh observability with distributed tracing
- Multi-cluster and multi-cloud mesh federation
- Progressive delivery with canary and blue-green deployments
- Security policies and authorization rules
Use this skill when
- Implementing service-to-service communication in Kubernetes
- Setting up zero-trust networking with mTLS
- Configuring traffic splitting for canary deployments
- Debugging service mesh connectivity issues
- Implementing rate limiting and circuit breakers
- Setting up cross-cluster service discovery
Workflow
- Assess current infrastructure and requirements
- Design mesh topology and traffic policies
- Implement security policies (mTLS, AuthorizationPolicy)
- Configure observability (metrics, traces, logs)
- Set up traffic management rules
- Test failover and resilience patterns
- Document operational runbooks
Best Practices
- Start with permissive mode, gradually enforce strict mTLS
- Use namespaces for policy isolation
- Implement circuit breakers before they're needed
- Monitor mesh overhead (latency, resource usage)
- Keep sidecar resources appropriately sized
- Use destination rules for consistent load balancing
Limitations
- Use this skill only when the task clearly matches the scope described above.
- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.
1---2name: service-mesh-expert3description: ALWAYS use this when the request matches Service Mesh Expert: Expert service mesh architect specializing in Istio, Linkerd, and cloud-native networking patterns.4---56# Service Mesh Expert78## Selective Reading Rule910Start with:1112- `references/senior-master-standard.md`13- `references/usage-routing.md`14- `references/quality-checklist.md`1516Then load only the inherited docs, scripts, assets, or examples that match the user's actual task.1718Expert service mesh architect specializing in Istio, Linkerd, and cloud-native networking patterns. Masters traffic management, security policies, observability integration, and multi-cluster mesh configurations. Use PROACTIVELY for service mesh architecture, zero-trust networking, or microservices communication patterns.1920## Do not use this skill when2122- The task is unrelated to service mesh expert23- You need a different domain or tool outside this scope2425## Instructions2627- Clarify goals, constraints, and required inputs.28- Apply relevant best practices and validate outcomes.29- Provide actionable steps and verification.30- If detailed examples are required, open `resources/implementation-playbook.md`.3132## Capabilities3334- Istio and Linkerd installation, configuration, and optimization35- Traffic management: routing, load balancing, circuit breaking, retries36- mTLS configuration and certificate management37- Service mesh observability with distributed tracing38- Multi-cluster and multi-cloud mesh federation39- Progressive delivery with canary and blue-green deployments40- Security policies and authorization rules4142## Use this skill when4344- Implementing service-to-service communication in Kubernetes45- Setting up zero-trust networking with mTLS46- Configuring traffic splitting for canary deployments47- Debugging service mesh connectivity issues48- Implementing rate limiting and circuit breakers49- Setting up cross-cluster service discovery5051## Workflow52531. Assess current infrastructure and requirements542. Design mesh topology and traffic policies553. Implement security policies (mTLS, AuthorizationPolicy)564. Configure observability (metrics, traces, logs)575. Set up traffic management rules586. Test failover and resilience patterns597. Document operational runbooks6061## Best Practices6263- Start with permissive mode, gradually enforce strict mTLS64- Use namespaces for policy isolation65- Implement circuit breakers before they're needed66- Monitor mesh overhead (latency, resource usage)67- Keep sidecar resources appropriately sized68- Use destination rules for consistent load balancing6970## Limitations71- Use this skill only when the task clearly matches the scope described above.72- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.73- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.