Every service calls a dozen others. Each call should prove who is calling — Kong Mesh puts an Envoy proxy beside every service — in Kubernetes, on VMs or on bare metal — to encrypt, authorise and route every call between them, across one zone or many.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Kong Mesh — the enterprise service mesh. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A layer of proxies beside your services that encrypts, authorises and routes every call between them — without changing application code.
What consolidation actually replaces, dimension by dimension.
| Dimension | Per-app TLS, retries and firewall rules | Kong Mesh |
|---|---|---|
| Encryption between services | TLS set up per app, when someone remembers | Mutual TLS on every call, issued by the mesh |
| Who may call whom | IP allow-lists and firewall tickets | MeshTrafficPermission by service identity |
| Retries and timeouts | Coded differently in every service | Retry, timeout and circuit-breaker policies |
| VMs next to Kubernetes | A separate network story for each | One mesh across Kubernetes and Universal mode |
| Several clusters or sites | Per-cluster config, copied by hand | A global control plane syncing every zone |
| What it is NOT | — | Not an API gateway or portal — that is Konnect |
The cheapest test is two services that already call each other: mesh them, switch on mTLS and a traffic permission, and see what breaks.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
An Envoy proxy runs beside each workload — a sidecar on Kubernetes, a process on a VM — carrying its traffic, identity and policy. The licence counts these.
Each zone control plane registers its own proxies, zone ingress and egress, and reports status upward. A zone can be a cluster, a data centre or a cloud region.
The global control plane holds meshes and policies and pushes them to every zone. Run it yourself, or let Konnect host it while zone control planes stay with you.
MeshTrafficPermission, MeshHTTPRoute, MeshRetry, MeshCircuitBreaker and similar resources set access, routing and resilience without touching application code.
A proxy beside every service, a control plane per zone, one global plane for policy — on your servers or in Konnect.
Kong Mesh secures and routes every call between your services, wherever those services run.
Kubernetes mode and Universal mode for VMs and bare metal join the same mesh, so a legacy service and a pod call each other the same way.
A global control plane syncs meshes and policies to every zone; zone ingress and egress carry calls between clusters, sites and clouds.
HTTP and TCP routes, retries, timeouts, health checks and circuit breakers are set as policies, not coded into each service.
Enterprise adds HashiCorp Vault, AWS Private CA and cert-manager as mTLS backends, plus CA rotation — say, moving from the built-in CA to Vault.
An Open Policy Agent ships in the data plane sidecar, so access decisions for a service can use Rego policies you already maintain.
Kong Mesh uses Envoy’s FIPS-compliant BoringSSL mode — relevant where a customer or regulator asks for validated crypto. Not on macOS.
AccessRole and AccessRoleBinding limit who may change which policy; the AccessAudit resource records user and system actions.
Service-to-service metrics and traces flow to Prometheus or an OpenTelemetry collector you already run, with no agent of Kong’s own.
Konnect can host the global control plane and show services, zones and proxies in one view; zone control planes still run with you.
Multi-zone traffic and load balancing, a tour of Kong Mesh in Konnect, and an older OpenShift quickstart — Kong has published little mesh video since 2024.
Multi-zone traffic and load balancing, end to end.
Recorded 2024; Konnect’s mesh screens may look different now.
Older and OpenShift-specific — check steps against current docs.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most Indian estates are not all Kubernetes: a core banking adapter on a VM, a payments service in a cluster, a batch job on bare metal. Kong Mesh runs its Envoy proxy in all three, so the same identity, mTLS and traffic rules cover calls between them — not just calls inside one cluster.
Kuma, the CNCF Sandbox project underneath, is free and Apache-2.0. Kong Mesh adds what an audit asks for: FIPS 140-2 mode, OPA in the proxy, RBAC, zone authentication, Vault or AWS Private CA for certificates, UBI images, and signed images with build provenance on recent releases.
The global control plane can sit on your servers in India, or in Konnect, whose India (IN) geo stores control-plane data such as service meshes and zones in-geo, per Kong’s docs; only authentication, billing and usage cross geos. Zone control planes and proxies stay in your environment either way.
There is no public price: Kong quotes per data plane proxy, and Mesh is not on the Konnect Plus card. It is a sidecar mesh, so every counted pod or VM carries an Envoy proxy. It governs traffic between your services; the API front door, portals and API keys are Kong Konnect’s job.
Add up pods and VMs that will join the mesh in every cluster and site — that total is what Kong’s quote counts.
Self-host the global control plane in India or use Konnect’s IN geo, and ask Kong for a trial licence file.
Put two services that call each other into the mesh, turn on mTLS and a traffic permission, and check nothing breaks.
Join VM workloads in Universal mode and a second cluster or site, then test failover between the two zones.
Switch to deny-by-default permissions, move retries and timeouts into policies, and set RBAC for each team.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our settlement engine lives on VMs and will for years. Kong Mesh let those VMs and our new pods share one mTLS trust domain.”
“Two data centres became two zones under one global control plane. Failover rules are written once instead of per site.”
“The auditor asked for FIPS mode and a CA we control. Pointing the mesh at our Vault CA answered both questions.”
“Counting proxies was the hard part of the quote — every pod and VM counts, and our replica numbers swing with load.”
“We trialled on the bundled licence and hit its proxy cap in a week. Ask Kong for a proper trial file on day one.”
“Retries and circuit breakers moved out of four codebases into mesh policies. Our Java and Go teams stopped arguing.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the service mesh market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Kuma-based; Kubernetes, VMs and multi-zone.
The grid nobody publishes — how far beyond Kubernetes it reaches vs how much enterprise hardening comes with it.
K8s, VMs, bare metal; FIPS, OPA, RBAC.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against open-source Istio, Solo Enterprise for Istio, HashiCorp Consul Enterprise, Buoyant Enterprise for Linkerd and Cilium — on runtimes, price, security, support and India.
| Dimension | Kong Mesh | Istio (open source) | Solo Enterprise for Istio | HashiCorp Consul Enterprise | Buoyant Enterprise for Linkerd | Cilium service mesh |
|---|---|---|---|---|---|---|
| What it is | Enterprise Kuma mesh | CNCF graduated mesh | Hardened Istio build | Discovery plus mesh | Supported Linkerd | eBPF networking + mesh |
| Deployment | K8s, VMs, bare metal | Self-run, K8s-centred | Your clusters | Self-managed only | K8s, plus Linux VMs | Kubernetes only |
| Coverage and topology | Multi-zone, multi-mesh | Multi-cluster, ambient | Istio multi-cluster | Mesh needs Premium | Multi-cluster failover | Cluster Mesh |
| Pricing model | Per data plane proxy | Free, Apache-2.0 | Tiered, by estimate | Standard vs Premium | Premium vs Strategic | Free, or Cisco quote |
| Published entry price | None — quote only | $0 | Not published | Not published | Free under 50 staff | $0 open source |
| Included vs add-on | Extras in the licence | Upstream features only | Support, FIPS, UI | Mesh is the upper tier | FIPS on Strategic | Hubble in the core |
| Scale and limits | Proxies may overrun | No licence cap | Istio scale, supported | Multi-datacenter | Zone-aware balancing | No sidecar per pod |
| Security depth | mTLS, OPA, FIPS, SPIFFE | mTLS and authz | FIPS, long CVE window | mTLS, FIPS 140-3 | mTLS, FIPS optional | Mutual auth in beta |
| Integrations | Vault, OTel, Kong GW | Widest ecosystem | Istio ecosystem | HashiCorp stack | Kubernetes native | Hubble, Istio interop |
| Governance and SSO | RBAC and audit log | Kubernetes RBAC | Istio APIs + Solo UI | Partitions, OIDC | Policy, not tenancy | Kubernetes RBAC |
| India storage region | Self-host or IN geo | Wherever you run it | Your own clusters | Self-managed in India | Your own clusters | Your own clusters |
| Support | In the Kong quote | Community only | Three tiers, n-4 | IBM licensed support | 24x7 on Strategic | Via Cisco |
| Lock-in and exit | Kuma is the fallback | Open standard APIs | Upstream Istio APIs | BUSL and IBM terms | Edge releases only | Tied to your CNI |
| Best fit | Pods and VMs together | Skilled platform teams | Istio, with support | HashiCorp estates | Lean Kubernetes mesh | Cilium-run clusters |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Kong Mesh is one of 35 developer tools products TechBag carries. The Developer Tools guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (services in the mesh; engineer-hour cost). Estimates model engineering time spent wiring service-to-service TLS, retries, timeouts and access rules by hand — at an assumed 1.5 hours per service a year, with 70% of it avoided once a mesh applies them as policy. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only: Kong publishes no price for Kong Mesh, and it is not on the Konnect Plus card. The licence counts data plane proxies — pods plus VMs across every zone — and has an expiry date; without a licence file, a bundled licence allows 10 proxies for 30 days. Kuma, the open-source core, is free. TechBag counts your proxies first, then quotes in INR with GST.
Best when everything must run on your servers
Best for a broader rollout
Best when you would rather not run the global plane
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many pods and VMs will join the mesh across all zones — at peak replica counts, not the average?
Which services run on VMs or bare metal? If none do, compare the Kubernetes-only meshes before you buy.
Will the global control plane run on your servers or in Konnect — and which geo will you choose?
Is Konnect’s India (IN) geo enough for your regulator, given Kong does not name its city or cloud region?
Which CA should issue mesh certificates — the built-in one, HashiCorp Vault, AWS Private CA or cert-manager?
Do you need FIPS 140-2 mode, OPA policies or signed images with build provenance? Confirm your version.
Have you asked Kong for a trial file? The bundled licence stops at 10 proxies and expires after 30 days.
Which LTS will you standardise on? Kong ships four minors a year and supports each LTS for two years.
Count the pods and VMs that will join the mesh first, or let a TechBag advisor scope a pilot on one pair of services with a proper trial licence.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.