WHY GARTNER’S “CONTEXT MESH” CHANGES EVERYTHING AI CONNECTIVITY: THE ROAD AHEAD DON’T MISS API + AI SUMMIT 2026 SEPT 30 – OCT 1
  • [Why Kong](/company/why-kong)Why Kong
    • Explore the unified API Platform
        • BUILD APIs
        • [
          Kong Insomnia](/products/kong-insomnia)
          Kong Insomnia
        • [
          API Design](/products/kong-insomnia/api-design)
          API Design
        • [
          API Mocking](/products/kong-insomnia/api-mocking)
          API Mocking
        • [
          API Testing and Debugging](/products/kong-insomnia/api-testing-and-debugging)
          API Testing and Debugging
        • [
          MCP Client](/products/kong-insomnia/mcp-client)
          MCP Client
        • RUN APIs
        • [
          API Gateway](/products/kong-gateway)
          API Gateway
        • [
          Context Mesh](/products/kong-konnect/features/context-mesh)
          Context Mesh
        • [
          AI Gateway](/products/kong-ai-gateway)
          AI Gateway
        • [
          Event Gateway](/products/event-gateway)
          Event Gateway
        • [
          Kubernetes Operator](/products/kong-gateway-operator)
          Kubernetes Operator
        • [
          Service Mesh](/products/kong-mesh)
          Service Mesh
        • [
          Ingress Controller](/products/kong-ingress-controller)
          Ingress Controller
        • [
          Runtime Management](/products/kong-konnect/features/runtime-management)
          Runtime Management
        • DISCOVER APIs
        • [
          Developer Portal](/products/kong-konnect/features/developer-portal)
          Developer Portal
        • [
          Service Catalog](/products/kong-konnect/features/api-service-catalog)
          Service Catalog
        • [
          MCP Registry](/products/mcp-registry)
          MCP Registry
        • GOVERN APIs
        • [
          Metering and Billing](/products/kong-konnect/features/usage-based-metering-and-billing)
          Metering and Billing
        • [
          APIOps and Automation](/products/apiops-automation)
          APIOps and Automation
        • [
          API Observability](/products/kong-konnect/features/api-observability)
          API Observability
        • [Why Kong?](/company/why-kong)Why Kong?
      • CLOUD
      • [Cloud API Gateways](/products/kong-konnect/features/dedicated-cloud-gateways)Cloud API Gateways
      • [Need a self-hosted or hybrid option?](/products/kong-enterprise)Need a self-hosted or hybrid option?
      • COMPARE
      • [Considering AI Gateway alternatives? ](/performance-comparison/ai-gateway-alternatives)Considering AI Gateway alternatives?
      • [Kong vs. Postman](/performance-comparison/kong-vs-postman)Kong vs. Postman
      • [Kong vs. MuleSoft](/performance-comparison/kong-vs-mulesoft)Kong vs. MuleSoft
      • [Kong vs. Apigee](/performance-comparison/kong-vs-apigee)Kong vs. Apigee
      • [Kong vs. IBM](/performance-comparison/ibm-api-connect-vs-kong)Kong vs. IBM
      • GET STARTED
      • [Sign Up for Kong Konnect](/products/kong-konnect/register)Sign Up for Kong Konnect
      • [Documentation](https://developer.konghq.com/)Documentation
      • FOR PLATFORM TEAMS
      • [Developer Platform](/solutions/building-developer-platform)Developer Platform
      • [Kubernetes and Microservices](/solutions/build-on-kubernetes)Kubernetes and Microservices
      • [Observability](/solutions/observability)Observability
      • [Service Mesh Connectivity ](/solutions/service-mesh-connectivity)Service Mesh Connectivity
      • [Kafka Event Streaming](/solutions/kafka-stream-api-management)Kafka Event Streaming
      • FOR EXECUTIVES
      • [AI Connectivity](/ai-connectivity)AI Connectivity
      • [Open Banking](/solutions/open-banking)Open Banking
      • [Legacy Migration](/solutions/legacy-api-management-migration)Legacy Migration
      • [Platform Cost Reduction](/solutions/api-platform-consolidation)Platform Cost Reduction
      • [Kafka Cost Optimization](/solutions/reduce-kafka-cost)Kafka Cost Optimization
      • [API Monetization](/solutions/api-monetization)API Monetization
      • [AI Monetization](/solutions/ai-monetization)AI Monetization
      • [AI FinOps](/solutions/ai-cost-governance-finops)AI FinOps
      • FOR AI TEAMS
      • [AI Governance](/solutions/ai-governance)AI Governance
      • [AI Security](/solutions/ai-security)AI Security
      • [AI Cost Control](/solutions/ai-cost-optimization-management)AI Cost Control
      • [Agentic Infrastructure](/solutions/agentic-ai-workflows)Agentic Infrastructure
      • [MCP Production](/solutions/mcp-production-and-consumption)MCP Production
      • [MCP Traffic Gateway](/solutions/mcp-governance)MCP Traffic Gateway
      • FOR DEVELOPERS
      • [Mobile App API Development](/solutions/mobile-application-api-development)Mobile App API Development
      • [GenAI App Development](/solutions/power-openai-applications)GenAI App Development
      • [API Gateway for Istio](/solutions/istio-gateway)API Gateway for Istio
      • [Decentralized Load Balancing](/solutions/decentralized-load-balancing)Decentralized Load Balancing
      • BY INDUSTRY
      • [Financial Services](/solutions/financial-services-industry)Financial Services
      • [Healthcare](/solutions/healthcare)Healthcare
      • [Higher Education](/solutions/api-platform-for-education-services)Higher Education
      • [Insurance](/solutions/insurance)Insurance
      • [Manufacturing](/solutions/manufacturing)Manufacturing
      • [Retail](/solutions/retail)Retail
      • [Software & Technology](/solutions/software-and-technology)Software & Technology
      • [Transportation](/solutions/transportation-and-logistics)Transportation
      • [See all Solutions](/solutions)See all Solutions
  • [Pricing](/pricing)Pricing
      • DOCUMENTATION
      • [Kong Konnect](https://developer.konghq.com/konnect/)Kong Konnect
      • [Kong Gateway](https://developer.konghq.com/gateway/)Kong Gateway
      • [Kong Mesh](https://developer.konghq.com/mesh/)Kong Mesh
      • [Kong AI Gateway](https://developer.konghq.com/ai-gateway/)Kong AI Gateway
      • [Kong Event Gateway](https://developer.konghq.com/event-gateway/)Kong Event Gateway
      • [Kong Insomnia](https://developer.konghq.com/insomnia/)Kong Insomnia
      • [Plugin Hub](https://developer.konghq.com/plugins/)Plugin Hub
      • EXPLORE
      • [Blog](/blog)Blog
      • [Learning Center](/blog/learning-center)Learning Center
      • [eBooks](/resources/e-book)eBooks
      • [Reports](/resources/reports)Reports
      • [Demos](/resources/demos)Demos
      • [Customer Stories](/customer-stories)Customer Stories
      • [Videos](/resources/videos)Videos
      • EVENTS
      • [API + AI Summit](/events/conferences/api-ai-summit)API + AI Summit
      • [Agentic Era World Tour](/agentic-era-world-tour)Agentic Era World Tour
      • [Webinars](/events/webinars)Webinars
      • [User Calls](/events/user-calls)User Calls
      • [Workshops](/events/workshops)Workshops
      • [Meetups](/events/meetups)Meetups
      • [See All Events](/events)See All Events
      • FOR DEVELOPERS
      • [Get Started](https://developer.konghq.com/)Get Started
      • [Community](/community)Community
      • [Certification](/academy/certification)Certification
      • [Training](https://education.konghq.com)Training
      • COMPANY
      • [About Us](/company/about-us)About Us
      • [We're Hiring!](/company/careers)We're Hiring!
      • [Press Room](/company/press-room)Press Room
      • [Contact Us](/company/contact-us)Contact Us
      • [Kong Partner Program](/partners)Kong Partner Program
      • [Enterprise Support Portal](https://support.konghq.com/s/)Enterprise Support Portal
      • [Documentation](https://developer.konghq.com/?_gl=1*tphanb*_gcl_au*MTcxNTQ5NjQ0MC4xNzY5Nzg4MDY0LjIwMTI3NzEwOTEuMTc3MzMxODI2MS4xNzczMzE4MjYw*_ga*NDIwMDU4MTU3LjE3Njk3ODgwNjQ.*_ga_4JK9146J1H*czE3NzQwMjg1MjkkbzE4OSRnMCR0MTc3NDAyODUyOSRqNjAkbDAkaDA)Documentation
  • [](/search)
  • [Login](https://cloud.konghq.com/login)Login
  • [Book Demo](/contact-sales)Book Demo
  • [Get Started](/products/kong-konnect/register)Get Started
[Blog](/blog)Blog
  • [AI Gateway](/blog/tag/ai-gateway)AI Gateway
  • [AI Security](/blog/tag/ai-security)AI Security
  • [AIOps](/blog/tag/aiops)AIOps
  • [API Security](/blog/tag/api-security)API Security
  • [API Gateway](/blog/tag/api-gateway)API Gateway
|
    • [API Management](/blog/tag/api-management)API Management
    • [API Development](/blog/tag/api-development)API Development
    • [API Design](/blog/tag/api-design)API Design
    • [Automation](/blog/tag/automation)Automation
    • [Service Mesh](/blog/tag/service-mesh)Service Mesh
    • [Insomnia](/blog/tag/insomnia)Insomnia
    • [Event Gateway](/blog/tag/event-gateway)Event Gateway
    • [View All Blogs](/blog/page/1)View All Blogs
We're Entering the Age of AI Connectivity [Read more](/blog/news/the-age-of-ai-connectivity)Read moreProducts & Agents:
    • [Kong AI Gateway](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong API Gateway](/products/kong-gateway)Kong API Gateway
    • [Kong Event Gateway](/products/event-gateway)Kong Event Gateway
    • [Kong Metering & Billing](/products/usage-based-metering-and-billing)Kong Metering & Billing
    • [Kong Insomnia](/products/kong-insomnia)Kong Insomnia
    • [Kong Konnect](/products/kong-konnect)Kong Konnect
  • [Documentation](https://developer.konghq.com)Documentation
  • [Book Demo](/contact-sales)Book Demo
  1. Home
  2. Blog
  3. Engineering
  4. Deploying Kong Mesh with Konnect on AWS ECS
[Engineering](/blog/engineering)Engineering
February 7, 2025
5 min read

# Deploying Kong Mesh with Konnect on AWS ECS

Vince Russo
Senior Solutions Engineer, Kong
John Harris
Principal PM Kong Mesh & Kuma

## Deploying Kong Mesh on ECS

The focus of this blog is to provide step-by-step instructions for deploying and configuring Kong Mesh with Kong Konnect on an AWS ECS instance so that anyone will be able to get pre-production installation of Kong Mesh standing up on their own.

### What is Kong Konnect?

Kong Konnect is an API lifecycle management platform designed from the ground up for the cloud native era and delivered as a service. This platform lets you build modern applications better, faster, and more securely. The management plane is hosted in the cloud by Kong, while you can choose to either host the data plane yourself in your preferred network environments or let Kong manage it for you in the cloud. 

Want to check out Kong Konnect? Click [here](https://cloud.konghq.com/register)here to register for free.

### What is Kong Mesh?

[Kong Mesh](https://konghq.com/products/kong-mesh)Kong Mesh is an enterprise-grade service mesh that runs on both Kubernetes and VMs on any cloud. Built on top of CNCF’s [Kuma](https://kuma.io/)Kuma and Envoy and focused on simplicity, Kong Mesh enables the microservices transformation with: out-of-the-box service connectivity and discovery; zero-trust security; traffic reliability; and global observability across all traffic, including cross-cluster deployments. Konnect extends this functionality by adding a global control plane to manage your various mesh zones and robust RBAC capabilities with SSO integrations.

## Service mesh on AWS ECS

The best practice implementation of a service mesh typically involves running inside a Kubernetes cluster, however, for some organizations, that approach simply isn't tenable. In this post, we'll explore deploying Kong Mesh’s solution in Universal mode (meaning non-K8s) utilizing AWS’s Elastic Container Service (ECS).

ECS offers architects a flexible platform for deploying and managing containerized workloads while not having to be mired in Kubernetes configuration. However, this does introduce complexities of its own as there is no inter-container management by default. We will be exploring how to deploy and configure Kong Mesh, providing the necessary service discovery scaffolding that will enable all the functionality expected of an enterprise-grade service mesh.

### Configure your environment

Prerequisites:

  • - [aws-cli](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html)aws-cli
  • - AWS authentication tool ([saml2aws](https://github.com/Versent/saml2aws?tab=readme-ov-file)saml2aws)
  • - [Kumactl](https://docs.konghq.com/mesh/latest/production/install-kumactl/)Kumactl
  • - [Kong Konnect account](https://konghq.com/products/kong-konnect)Kong Konnect account ([registration](https://konghq.com/products/kong-konnect/register)registration is free and includes a 30-day trial)

Set your AWS default profile to “kong” which will configure the session's working profile.

export AWS_DEFAULT_PROFILE=kong

At this point we are ready to begin deploying our demo environment. We’ll use CloudFormation to install a VPC, configure the TLS secrets, deploy a Kong Mesh control plane, ingress, and our demo applications.

First, we need to pull the files for our deployment. They can be found at this [repository](https://github.com/Kong/kong-mesh-ecs-blog)repository. Clone or download the kong-mesh-ecs-blog and navigate to the “/deploy” folder in your favorite IDE. We will be working exclusively in this folder. Referencing the vpc, controlplane and ingress yaml files as the core of our AWS CloudFormation deployment.

### Deploy the VPC

We are ready to deploy the first component of the Kong Mesh on Kong Konnect platform, the VPC. In your terminal, navigate to the “**kong-mesh-ecs-blog**” directory. All commands in this blog will be executed from this root directory. With the AWS CLI execute the following command to deploy the VPC.

aws --region cloudformation deploy \
    --capabilities CAPABILITY_IAM \
    --stack-name ecs-demo-vpc \
    --template-file deploy/1-vpc.yaml

This process takes about 3–5 minutes to complete. Log in to your AWS Cloud Console and check the CloudFormation section to confirm the creation of the VPC.

### Create TLS Certificates

Now we need to reference the control planes address to build the TLS certs needed for Kong Mesh. Echo the CP_ADDR variable to verify its creation.

CP_ADDR=$(aws cloudformation describe-stacks --stack-name ecs-demo-vpc \
  | jq -r '.Stacks[0].Outputs[] | select(.OutputKey == "ExternalCPAddress") | .OutputValue')

echo $CP_ADDR

Use the kuma-ctl to generate the cert and the AWS Secrets Manager to inject them into secrets to be used in the rest of the cloud formation deployments. 

kumactl generate tls-certificate --type=server --hostname ${CP_ADDR} --hostname controlplane.kongmesh

TLS_KEY=$(
  aws secretsmanager create-secret \
  --name ecs-demo/CPTLSKey \
  --description "Secret containing TLS private key for serving control plane traffic" \
  --secret-string file://key.pem \
  | jq -r .ARN)


TLS_CERT=$(
  aws secretsmanager create-secret \
  --name ecs-demo/CPTLSCert \
  --description "Secret containing TLS certificate for serving control plane traffic" \
  --secret-string file://cert.pem \
  | jq -r .ARN)

### Deploy Konnect Kong Mesh Control Plane and Ingress 

Now that we have our VPC and certs, we can deploy the Kong Mesh control plane and ingress. We should always be aware of the version we are deploying, and insure they match each other. Open controlplane.yaml in your favorite IDE and find line 11, verify it has the latest version (2.9.0 as of the writing of this blog).

Image:
   Type: String
   Default: "docker.io/kong/kuma-cp:2.9.0"
   Description: Name of the control plane docker image
 ZoneName:
   Type: String
   Default: "ecs-zone"
   Description: Name of the zone control plane setup in Konnect

Notice the ZoneName (line 13) “**ecs-zone**”. Note this as it will be used in later steps.

Since we are leveraging Konnect as our backing license controller, we need to include some Konnect IDs into our deployment script. Follow the screenshots below to create your Konnect Mesh Manger Control Plane and generate a Konnect Personal Access Token (spat). Name your Global Control Plane whatever suits you, the zone name in the following prompt should use the zone name we saved from the previous step, **“ecs-zone**”.

Make sure to select **Universal** environment as ECS does not support Kubernetes-based deployments. Inside the “Connect Zone” you’ll find the **spat** and **control plane id,** make sure to copy these to a secure location, we will use them in the following section.

Keep the UI window open while we wait for the zone to be connected. Run the following command, be sure to replace <KONNECT_SPAT> and <KONNECT_CP_ID> with the values from the previous step. 

aws cloudformation deploy \
 --capabilities CAPABILITY_IAM \
 --stack-name ecs-demo-kong-mesh-cp \
 --parameter-overrides VPCStackName=ecs-demo-vpc \
   ServerKeySecret=${TLS_KEY} \
   ServerCertSecret=${TLS_CERT} \
   KonnectSPAT=<KONNECT_SPAT> \
   KonnectCPID=<KONNECT_CP_ID> \
 --template-file deploy/2-controlplane.yaml

After about 5 minutes the control plane should be **CREATE_COMPLETE **and we are ready to deploy the ingress. Before we do that, let's capture the internal IP address of the control plane for our demo apps that we will deploy later on.

We need to get the cluster arn to get the task list of our control plane. First list the clusters and then list the tasks of that cluster.

aws ecs list-clusters
{
    "clusterArns": [
        "arn:aws:ecs:us-west-1:162225303348:cluster/ecs-demo-vpc-ECSCluster-swfrzSqeH7zd"
    ]
}

aws ecs list-tasks --cluster <CLUSTER_ANR>
{
    "taskArns": [
        "arn:aws:ecs:us-west-1:162225303348:task/ecs-demo-vpc-ECSCluster-swfrzSqeH7zd/83070866933a41b8bd62b8201df00337"
    ]
}

Now that we have the cluster and task arn, we can extract the internal IP address of our control plane.

aws ecs describe-tasks --cluster <CLUSTER_ARN> --tasks <TASK_ARN> --query 'tasks[].attachments[].details[?name==`privateDnsName`].value'

[
    [
        "ip-10-0-0-234.us-west-1.compute.internal"
    ]
]

Make sure to store this address for when we deploy the demo apps.

Now we can deploy the ingress and finalize our Konnect Kong Mesh deployment:

aws cloudformation deploy \
 --capabilities CAPABILITY_IAM \
 --stack-name ecs-demo-ingress \
 --parameter-overrides VPCStackName=ecs-demo-vpc CPStackName=ecs-demo-kong-mesh-cp \
 --template-file deploy/3-ingress.yaml

At this point we should have the ecs-demo-vpc, the ecs-demo-kong-mesh-cp and the ecs-demo-ingress created successfully, and our deployment of Kong Mesh backed by Konnect is complete. However, we don’t have any applications to use our mesh. 

### Deploy the Counter App

The last two commands we need to run deploy the Counter app and its redis cache. First deploy the redis and then the demo-app. Remember that control plane address we saved a few steps ago? That gets used here:

aws cloudformation deploy \
 --capabilities CAPABILITY_IAM \
 --stack-name ecs-demo-redis \
 --parameter-overrides VPCStackName=ecs-demo-vpc CPStackName=ecs-demo-kong-mesh-cp ZoneCpAddress=INTERNAL_CP_ADDRESS \
 --template-file deploy/4-redis.yaml

aws cloudformation deploy \
 --capabilities CAPABILITY_IAM \
 --stack-name ecs-demo-demo-app \
 --parameter-overrides VPCStackName=ecs-demo-vpc CPStackName=ecs-demo-kong-mesh-cp ZoneCpAddress=INTERNAL_CP_ADDRESS \
 --template-file deploy/5-demo-app.yaml

Once those two deploy successfully, you can navigate to the external control plan address we stored in the very beginning, the CP_ADDR, and you will see our Kuma Counter Demo. You can click increment and the number will rise until you reset. 

## Wrap up

You have now successfully deployed Kong Mesh into your ECS environment with a running sample demo application. The next steps will be to explore your ecs-zone in Konnect and add [policies](https://kuma.io/docs/2.9.x/policies/introduction/)policies to re-enforce your microservices:

We’ll save that for another blog. Thanks for your time, happy helming meshing!

### Supporting documentation

  • - Kong Konnect Documentation: [https://docs.konghq.com/konnect/](https://docs.konghq.com/konnect/)https://docs.konghq.com/konnect/
  • - [](https://docs.konghq.com/konnect/)Kong Mesh Documentation: [https://docs.konghq.com/mesh/latest/](https://docs.konghq.com/mesh/latest/)https://docs.konghq.com/mesh/latest/
  • - Kong Mesh on ECS: [https://docs.konghq.com/mesh/latest/installation/ecs/](https://docs.konghq.com/mesh/latest/installation/ecs/)https://docs.konghq.com/mesh/latest/installation/ecs/
  • - Kuma Policies: [https://kuma.io/docs/2.9.x/policies/introduction/](https://kuma.io/docs/2.9.x/policies/introduction/)https://kuma.io/docs/2.9.x/policies/introduction/
  • - Kong Mesh ECS Blog GitHub: [https://github.com/Kong/kong-mesh-ecs-blog/tree/main](https://github.com/Kong/kong-mesh-ecs-blog/tree/main)https://github.com/Kong/kong-mesh-ecs-blog/tree/main

## Mesh your services together effortlessly with Kong

[Learn More](/products/kong-mesh/)Learn More[Get a Demo](/contact-sales)Get a Demo
- [Kong Konnect](/blog/tag/kong-konnect)Kong Konnect- [Kong Mesh](/blog/tag/kong-mesh)Kong Mesh- [Service Mesh](/blog/tag/service-mesh)Service Mesh- [AWS](/blog/tag/aws)AWS

## More on this topic

_Videos_

## Demystifying the Latest in Kong Mesh

_Webinars_

## Accelerate Your Financial Services API Strategy in AWS with Kong Konnect

## See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

[Get a Demo](/contact-sales)Get a Demo
**Topics**
- [Kong Konnect](/blog/tag/kong-konnect)Kong Konnect- [Kong Mesh](/blog/tag/kong-mesh)Kong Mesh- [Service Mesh](/blog/tag/service-mesh)Service Mesh- [AWS](/blog/tag/aws)AWS
Vince Russo
Senior Solutions Engineer, Kong
John Harris
Principal PM Kong Mesh & Kuma

Recommended posts

# Announcing Mesh Manager Support in Konnect Terraform Provider

[Product Releases](/blog)Product ReleasesJuly 17, 2025

What Is Terraform? Terraform is an infrastructure-as-code (IaC) tool developed by HashiCorp. It allows users to define and provision data center infrastructure using a declarative configuration language known as HashiCorp Configuration Language (HCL

Krzysztof Słonka
[](https://konghq.com/blog/product-releases/mesh-manager-support-in-konnect-terraform-provider)

# Kong Mesh 2.11: Reduced Privileges, Improved Support for AWS ECS

[Product Releases](/blog)Product ReleasesJune 20, 2025

We’re at it again, bringing more incremental improvements to Kong Mesh!  Built on top of Kuma, Kong Mesh brings much-needed simplicity and production-grade tooling. Kong Mesh is built for smooth operations with platform teams in mind, providing secu

Justin Davies
[](https://konghq.com/blog/product-releases/kong-mesh-2-11)

# Kong Simplifies Multicloud Cloud Gateways with Managed Redis Cache

[Product Releases](/blog)Product ReleasesMarch 12, 2026

Managed Redis cache is a turnkey "Shared State" add-on for Kong Dedicated Cloud Gateways. It is designed to combine the performance of an in-memory data store with the simplicity of a SaaS product. When you spin up a Dedicated Cloud Gateway in Kong

Amit Shah
[](https://konghq.com/blog/product-releases/multicloud-cloud-gateways-managed-redis-cache)

# Kong Konnect Advanced Analytics: Running Faster Than StatsD

[Engineering](/blog)EngineeringMarch 5, 2025

Using Konnect Advanced Analytics for a faster real-time measurement of what your users are experiencing Earlier this year the Kong Konnect Analytics team was looking to leverage the stability and flexibility of our own Kong Gateway to handle the e

Hiroshi Fukada
[](https://konghq.com/blog/engineering/konnect-advanced-analytics-faster-than-statsd)

# Mesh to the Rescue of API Gateways for Cross-Cloud Connectivity

[Engineering](/blog)EngineeringFebruary 10, 2025

Many organizations struggle with managing API gateways across multiple cloud environments. In this blog post, we'll explore how Kong Mesh can solve these challenges and enable seamless cross-cloud connectivity. The challenge of multi-cloud API gatew

Baptiste Collard
[](https://konghq.com/blog/engineering/service-mesh-api-gateways-cross-cloud-connectivity)

# Achieving Zero Trust on VMs with Universal Mesh

[Engineering](/blog)EngineeringJune 10, 2024

Two of the main tenets of Zero Trust are encryption between services and managing the connections each service is allowed to use. Achieving this generally falls to running a service mesh in a Kubernetes cluster. Refactoring applications to run prope

George Fridrich
[](https://konghq.com/blog/engineering/zero-trust-on-vms-with-universal-mesh)

# Enterprise-Grade Service Mesh: A Reference Architecture with OpenShift, Istio, and Kong

[Engineering](/blog)EngineeringMay 13, 2024

The service mesh architecture pattern has become a de facto standard for microservices-based projects. In fact, from the mesh standpoint, not just microservices but all components of an application should be under its control, including databases,

Claudio Acquaviva
[](https://konghq.com/blog/engineering/service-mesh-reference-architecture-openshift-istio-kong)

## Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

[Get a Demo](/contact-sales)Get a Demo
Ask AI for a summary of Kong
  • [](https://chatgpt.com/s/t_69b981cfa37081919ce25ce107c431c1)
  • [](https://share.google/aimode/hyefOiNwl8pg8W99d)
  • [](https://www.perplexity.ai/search/what-solutions-does-kong-offer-VsYWPddxQjajgvLA4B9hjQ)
Stay connected

## step-0

    • Company
    • [About Kong](/company/about-us)About Kong
    • [Customers](/customer-stories)Customers
    • [Careers](/company/careers)Careers
    • [Press](/company/press-room)Press
    • [Events](/events)Events
    • [Contact](/company/contact-us)Contact
    • [Pricing](/pricing)Pricing
    • Legal
    • [Terms](/legal/terms-of-use)Terms
    • [Privacy](/legal/privacy-policy)Privacy
    • [Trust and Compliance](https://trust.konghq.com)Trust and Compliance
    • Platform
    • [Kong AI Gateway](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong Konnect](/products/kong-konnect)Kong Konnect
    • [Kong Gateway](/products/kong-gateway)Kong Gateway
    • [Kong Event Gateway](/products/event-gateway)Kong Event Gateway
    • [Kong Insomnia](/products/kong-insomnia)Kong Insomnia
    • [Documentation](https://developer.konghq.com)Documentation
    • [Book Demo](/contact-sales)Book Demo
    • Compare
    • [AI Gateway Alternatives](/performance-comparison/ai-gateway-alternatives)AI Gateway Alternatives
    • [Kong vs Apigee](/performance-comparison/kong-vs-apigee)Kong vs Apigee
    • [Kong vs IBM](/performance-comparison/ibm-api-connect-vs-kong)Kong vs IBM
    • [Kong vs Postman](/performance-comparison/kong-vs-postman)Kong vs Postman
    • [Kong vs Mulesoft](/performance-comparison/kong-vs-mulesoft)Kong vs Mulesoft
    • Explore More
    • [Open Banking API Solutions](/solutions/open-banking)Open Banking API Solutions
    • [API Governance Solutions](/solutions/api-governance)API Governance Solutions
    • [Istio API Gateway Integration](/solutions/istio-gateway)Istio API Gateway Integration
    • [Kubernetes API Management](/solutions/build-on-kubernetes)Kubernetes API Management
    • [API Gateway: Build vs Buy](/campaign/secure-api-scalability)API Gateway: Build vs Buy
    • [Kong vs Apigee](/performance-comparison/kong-vs-apigee)Kong vs Apigee
    • Open Source
    • [Kong Gateway](https://developer.konghq.com/gateway/install/)Kong Gateway
    • [Kuma](https://kuma.io/)Kuma
    • [Insomnia](https://insomnia.rest/)Insomnia
    • [Kong Community](/community)Kong Community

Kong enables the connectivity layer for the agentic era – securely connecting, governing, and monetizing APIs and AI tokens across any model or cloud.

  • Japanese
  • Frenchcoming soon
  • Spanishcoming soon
  • Germancoming soon
© Kong Inc. 2026
Interaction mode