

Learn more about IT Security Summit
This bootcamp provides a deep dive into the security and traffic routing capabilities of Istio Ambient—the next-generation service mesh architecture that eliminates sidecar proxies entirely. You will begin by exploring the shift from classic Istio to the Ambient mesh, learning how to secure service-to-service communication without the traditional architectural overhead.
Through hands-on implementation, you will secure the entire traffic lifecycle: from TLS termination at the Ingress Gateway to full mTLS mesh encryption and controlled Egress monitoring. You will move beyond basic connectivity to master request-based authorization, JWT-based routing, and zero-trust security policies, backed by rigorous error analysis and debugging techniques for complex distributed environments.
On the second day, you will integrate multiple microservices into a unified service mesh. You will apply concrete Istio rules to solve real-world challenges in tracing, resilience, and observability. By working with best practices for traffic shifting and A/B testing, you will learn how to stabilize distributed applications and prevent common failure modes in production.
By the end of the bootcamp, you will be equipped with the scripts, code samples, and expert cheat sheets needed to deploy and operate Istio Ambient. You will be ready to lead service mesh initiatives that balance high-security requirements with operational simplicity across Kubernetes clusters and virtual machines.
Fundamentals
Ingress Gateway & TLS
Peer & Request Authentication
Authorization & Egress
Building the Mesh
Resilience & Metrics
Advanced Operations




Michael Hofmann is a freelance architect, consultant and developer. He has been gaining project experience for more than 2 decades on the German and international scenes, mainly in the areas of software architecture, Enterprise Java and DevOps. In addition to his project assignments, he is active as a speaker at various conferences or as an author of professional articles and books.