About this project

Kuma is a modern, Envoy-based service mesh designed to run on any cloud, in single-zone or multi-zone configurations, across both Kubernetes and virtual machines. It provides L4-L7 service connectivity, discovery, security, observability and routing for services on any platform, including databases, without requiring deep Envoy expertise. The project was originally created and donated by Kong and is now a CNCF Sandbox project. It aims to be powerful yet simple, with built-in service mesh policies and an intuitive learning curve. Kuma supports multi-tenancy and multiple isolated meshes on a single control plane, and it can span Kubernetes namespaces, clusters and clouds with automatic policy synchronization and cross-zone communication. Key capabilities described in the README include: - Universal control plane that runs on Kubernetes, VMs and bare metal, with a lightweight Envoy-powered data plane and automatic sidecar injection on Kubernetes. - Multi-mesh and multi-zone support, including global and remote control planes for hybrid VM and Kubernetes deployments. - Automatic mTLS with identity and encryption, optional third-party CA support, and automatic certificate rotation. - Traffic management policies such as MeshHTTPRoute and MeshTCPRoute for blue/green, canary, versioning and rollback, MeshTrafficPermission for zero-trust firewalling, MeshFaultInjection, MeshRetry, and internal/external service aggregation. - Observability policies including MeshAccessLog, MeshTrace and MeshMetric with native Prometheus and Grafana support. - Gateway support for API gateways and ingress such as Kong Gateway, transparent proxying, and a configurable network overlay across clusters and namespaces. - A browser-based GUI, a kumactl CLI, CRD-based configuration on Kubernetes, and a RESTful HTTP API for other environments that integrates with CI/CD workflows. Kuma ships in multiple distributions and releases a minor version on a 10-week cycle, with roadmap tracked via GitHub milestones. The README notes it is under active development and production-ready, and points to enterprise offerings for mission-critical support. Community channels include Slack, monthly community calls, Twitter and a blog.