WHY GARTNER’S “CONTEXT MESH” CHANGES EVERYTHING AI CONNECTIVITY: THE ROAD AHEAD DON’T MISS API + AI SUMMIT 2026 SEPT 30 – OCT 1
  • [Why Kong](/company/why-kong)Why Kong
    • Explore the unified API Platform
        • BUILD APIs
        • [
          Kong Insomnia](/products/kong-insomnia)
          Kong Insomnia
        • [
          API Design](/products/kong-insomnia/api-design)
          API Design
        • [
          API Mocking](/products/kong-insomnia/api-mocking)
          API Mocking
        • [
          API Testing and Debugging](/products/kong-insomnia/api-testing-and-debugging)
          API Testing and Debugging
        • [
          MCP Client](/products/kong-insomnia/mcp-client)
          MCP Client
        • RUN APIs
        • [
          API Gateway](/products/kong-gateway)
          API Gateway
        • [
          Context Mesh](/products/kong-konnect/features/context-mesh)
          Context Mesh
        • [
          AI Gateway](/products/kong-ai-gateway)
          AI Gateway
        • [
          Event Gateway](/products/event-gateway)
          Event Gateway
        • [
          Kubernetes Operator](/products/kong-gateway-operator)
          Kubernetes Operator
        • [
          Service Mesh](/products/kong-mesh)
          Service Mesh
        • [
          Ingress Controller](/products/kong-ingress-controller)
          Ingress Controller
        • [
          Runtime Management](/products/kong-konnect/features/runtime-management)
          Runtime Management
        • DISCOVER APIs
        • [
          Developer Portal](/products/kong-konnect/features/developer-portal)
          Developer Portal
        • [
          Service Catalog](/products/kong-konnect/features/api-service-catalog)
          Service Catalog
        • [
          MCP Registry](/products/mcp-registry)
          MCP Registry
        • GOVERN APIs
        • [
          Metering and Billing](/products/kong-konnect/features/usage-based-metering-and-billing)
          Metering and Billing
        • [
          APIOps and Automation](/products/apiops-automation)
          APIOps and Automation
        • [
          API Observability](/products/kong-konnect/features/api-observability)
          API Observability
        • [Why Kong?](/company/why-kong)Why Kong?
      • CLOUD
      • [Cloud API Gateways](/products/kong-konnect/features/dedicated-cloud-gateways)Cloud API Gateways
      • [Need a self-hosted or hybrid option?](/products/kong-enterprise)Need a self-hosted or hybrid option?
      • COMPARE
      • [Considering AI Gateway alternatives? ](/performance-comparison/ai-gateway-alternatives)Considering AI Gateway alternatives?
      • [Kong vs. Postman](/performance-comparison/kong-vs-postman)Kong vs. Postman
      • [Kong vs. MuleSoft](/performance-comparison/kong-vs-mulesoft)Kong vs. MuleSoft
      • [Kong vs. Apigee](/performance-comparison/kong-vs-apigee)Kong vs. Apigee
      • [Kong vs. IBM](/performance-comparison/ibm-api-connect-vs-kong)Kong vs. IBM
      • GET STARTED
      • [Sign Up for Kong Konnect](/products/kong-konnect/register)Sign Up for Kong Konnect
      • [Documentation](https://developer.konghq.com/)Documentation
      • FOR PLATFORM TEAMS
      • [Developer Platform](/solutions/building-developer-platform)Developer Platform
      • [Kubernetes and Microservices](/solutions/build-on-kubernetes)Kubernetes and Microservices
      • [Observability](/solutions/observability)Observability
      • [Service Mesh Connectivity ](/solutions/service-mesh-connectivity)Service Mesh Connectivity
      • [Kafka Event Streaming](/solutions/kafka-stream-api-management)Kafka Event Streaming
      • FOR EXECUTIVES
      • [AI Connectivity](/ai-connectivity)AI Connectivity
      • [Open Banking](/solutions/open-banking)Open Banking
      • [Legacy Migration](/solutions/legacy-api-management-migration)Legacy Migration
      • [Platform Cost Reduction](/solutions/api-platform-consolidation)Platform Cost Reduction
      • [Kafka Cost Optimization](/solutions/reduce-kafka-cost)Kafka Cost Optimization
      • [API Monetization](/solutions/api-monetization)API Monetization
      • [AI Monetization](/solutions/ai-monetization)AI Monetization
      • [AI FinOps](/solutions/ai-cost-governance-finops)AI FinOps
      • FOR AI TEAMS
      • [AI Governance](/solutions/ai-governance)AI Governance
      • [AI Security](/solutions/ai-security)AI Security
      • [AI Cost Control](/solutions/ai-cost-optimization-management)AI Cost Control
      • [Agentic Infrastructure](/solutions/agentic-ai-workflows)Agentic Infrastructure
      • [MCP Production](/solutions/mcp-production-and-consumption)MCP Production
      • [MCP Traffic Gateway](/solutions/mcp-governance)MCP Traffic Gateway
      • FOR DEVELOPERS
      • [Mobile App API Development](/solutions/mobile-application-api-development)Mobile App API Development
      • [GenAI App Development](/solutions/power-openai-applications)GenAI App Development
      • [API Gateway for Istio](/solutions/istio-gateway)API Gateway for Istio
      • [Decentralized Load Balancing](/solutions/decentralized-load-balancing)Decentralized Load Balancing
      • BY INDUSTRY
      • [Financial Services](/solutions/financial-services-industry)Financial Services
      • [Healthcare](/solutions/healthcare)Healthcare
      • [Higher Education](/solutions/api-platform-for-education-services)Higher Education
      • [Insurance](/solutions/insurance)Insurance
      • [Manufacturing](/solutions/manufacturing)Manufacturing
      • [Retail](/solutions/retail)Retail
      • [Software & Technology](/solutions/software-and-technology)Software & Technology
      • [Transportation](/solutions/transportation-and-logistics)Transportation
      • [See all Solutions](/solutions)See all Solutions
  • [Pricing](/pricing)Pricing
      • DOCUMENTATION
      • [Kong Konnect](https://developer.konghq.com/konnect/)Kong Konnect
      • [Kong Gateway](https://developer.konghq.com/gateway/)Kong Gateway
      • [Kong Mesh](https://developer.konghq.com/mesh/)Kong Mesh
      • [Kong AI Gateway](https://developer.konghq.com/ai-gateway/)Kong AI Gateway
      • [Kong Event Gateway](https://developer.konghq.com/event-gateway/)Kong Event Gateway
      • [Kong Insomnia](https://developer.konghq.com/insomnia/)Kong Insomnia
      • [Plugin Hub](https://developer.konghq.com/plugins/)Plugin Hub
      • EXPLORE
      • [Blog](/blog)Blog
      • [Learning Center](/blog/learning-center)Learning Center
      • [eBooks](/resources/e-book)eBooks
      • [Reports](/resources/reports)Reports
      • [Demos](/resources/demos)Demos
      • [Customer Stories](/customer-stories)Customer Stories
      • [Videos](/resources/videos)Videos
      • EVENTS
      • [API + AI Summit](/events/conferences/api-ai-summit)API + AI Summit
      • [Agentic Era World Tour](/agentic-era-world-tour)Agentic Era World Tour
      • [Webinars](/events/webinars)Webinars
      • [User Calls](/events/user-calls)User Calls
      • [Workshops](/events/workshops)Workshops
      • [Meetups](/events/meetups)Meetups
      • [See All Events](/events)See All Events
      • FOR DEVELOPERS
      • [Get Started](https://developer.konghq.com/)Get Started
      • [Community](/community)Community
      • [Certification](/academy/certification)Certification
      • [Training](https://education.konghq.com)Training
      • COMPANY
      • [About Us](/company/about-us)About Us
      • [We're Hiring!](/company/careers)We're Hiring!
      • [Press Room](/company/press-room)Press Room
      • [Contact Us](/company/contact-us)Contact Us
      • [Kong Partner Program](/partners)Kong Partner Program
      • [Enterprise Support Portal](https://support.konghq.com/s/)Enterprise Support Portal
      • [Documentation](https://developer.konghq.com/?_gl=1*tphanb*_gcl_au*MTcxNTQ5NjQ0MC4xNzY5Nzg4MDY0LjIwMTI3NzEwOTEuMTc3MzMxODI2MS4xNzczMzE4MjYw*_ga*NDIwMDU4MTU3LjE3Njk3ODgwNjQ.*_ga_4JK9146J1H*czE3NzQwMjg1MjkkbzE4OSRnMCR0MTc3NDAyODUyOSRqNjAkbDAkaDA)Documentation
  • [](/search)
  • [Login](https://cloud.konghq.com/login)Login
  • [Book Demo](/contact-sales)Book Demo
  • [Get Started](/products/kong-konnect/register)Get Started
[Blog](/blog)Blog
  • [AI Gateway](/blog/tag/ai-gateway)AI Gateway
  • [AI Security](/blog/tag/ai-security)AI Security
  • [AIOps](/blog/tag/aiops)AIOps
  • [API Security](/blog/tag/api-security)API Security
  • [API Gateway](/blog/tag/api-gateway)API Gateway
|
    • [API Management](/blog/tag/api-management)API Management
    • [API Development](/blog/tag/api-development)API Development
    • [API Design](/blog/tag/api-design)API Design
    • [Automation](/blog/tag/automation)Automation
    • [Service Mesh](/blog/tag/service-mesh)Service Mesh
    • [Insomnia](/blog/tag/insomnia)Insomnia
    • [View All Blogs](/blog/page/1)View All Blogs
We're Entering the Age of AI Connectivity [Read more](/blog/news/the-age-of-ai-connectivity)Read moreProducts & Agents:
    • [Kong AI Gateway](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong API Gateway](/products/kong-gateway)Kong API Gateway
    • [Kong Event Gateway](/products/event-gateway)Kong Event Gateway
    • [Kong Metering & Billing](/products/usage-based-metering-and-billing)Kong Metering & Billing
    • [Kong Insomnia](/products/kong-insomnia)Kong Insomnia
    • [Kong Konnect](/products/kong-konnect)Kong Konnect
  • [Documentation](https://developer.konghq.com)Documentation
  • [Book Demo](/contact-sales)Book Demo
  1. Home
  2. Blog
  3. Engineering
  4. Deploying Kong Mesh in Multiple Security Domains
[Engineering](/blog/engineering)Engineering
March 3, 2022
6 min read

# Deploying Kong Mesh in Multiple Security Domains

Scott Lowe

It's not uncommon for organizations to have to deploy solutions across (or among) multiple security domains. Here, we use the term "security domain" to refer to a segregated network environment, like a restricted internal network or a DMZ. This post will explore some design considerations when deploying [Kong Mesh](https://konghq.com/kong-mesh)Kong Mesh (and [Kuma](https://kuma.io)Kuma, the CNCF-hosted open source project upon which Kong Mesh is built) in environments with multiple security domains. After reading this post, you'll have a better idea of some of the different ways Kong Mesh can be architected to meet your specific security requirements.

Although this blog post only refers to Kong Mesh, everything mentioned here also applies to Kuma unless noted otherwise.

## **Potential Approaches**

When deploying Kong Mesh in an environment with multiple security domains, customers have at least three general approaches to consider:

  1. - Using a zone as your security domain boundary
  2. - Using a mesh as your security domain boundary
  3. - Using the control plane as your security domain boundary

Which one of these approaches is right for you? The answer is, *"It depends."* Each of these approaches has its advantages and disadvantages. It is up to customers to evaluate the advantages and disadvantages of each approach to determine which approach is the right one for their organization.

Before proceeding, you may find it useful to review [this blog post](https://konghq.com/blog/zones-meshes)this blog post on the role of zones and meshes in Kong Mesh.

First, let's take a deeper look at using a zone as your security domain boundary.

[**The Importance of Zero-Trust Security When Making the Microservices Move**](https://konghq.com/ebooks/the-importance-of-zero-trust-security-when-making-the-microservices-move)**The Importance of Zero-Trust Security When Making the Microservices Move**

## **Using a Zone as Your Security Domain Boundary**

In this architecture, each zone resides entirely within a single security domain; no zone ever exists in multiple security domains. This means you would end up with separate zones for your DMZ and your internal network, for example. Because each zone exists only within a single security domain, this also means that each zone control plane (recall that when using multiple zones, each zone has its own control plane) also resides entirely within a single security domain. However, the global control plane would "span" multiple security domains.

This architectural approach is illustrated in this diagram:

Using only a zone as a security boundary

This architecture has some advantages. One of the most notable advantages is that this architecture could be considered more flexible than the other approaches described here. Mesh policies can be applied "end to end" to any traffic flow between any two services in any zone, all from a single global control plane. Similarly, a single global control plane aggregates metrics and observability data. This simplifies the integration of Kong Mesh into customers' existing observability infrastructure.

However, this approach also has some drawbacks of which users should be aware. Keep in mind that zones do not restrict connectivity (again, refer back to [this blog post](https://konghq.com/blog/zones-meshes)this blog post on zones and meshes for more details). Therefore, cross-zone—and therefore cross-security domain—traffic would be allowed by default. Users have to explicitly take steps to prevent cross-zone traffic, typically using a TrafficPermission policy. This means it's easier to "accidentally" allow traffic between security domains that might not otherwise be permitted to communicate directly.

It would also be necessary to "punch" a hole in any intervening network segmentation mechanisms (like network firewalls, network access control lists, or security groups) to allow traffic between the zone control plane in each security domain and the global control plane (TCP port 5685, by default), as well as to allow traffic to flow between the Zone Ingresses for each zone (TCP port 10000, by default).

Given the drawbacks, you might think you can't or shouldn't use zones when dealing with multiple security domains. However, any Kong Mesh deployment that involves multiple security domains will likely involve multiple zones. Recall that a Kong Mesh zone is used to describe a network segment in which data plane proxies can freely communicate with each other. Therefore, it would be typical to use a zone to represent each security domain because you want Kong Mesh to know that data plane proxies in one security domain (zone) can't freely communicate with data plane proxies in a different security domain (zone).

However, using *only* zones and nothing else may be overlooking a key part of Kong Mesh functionality that is very useful in dealing with multiple security domains: the mesh.

[**API Gateway vs. Service Mesh…Join me to learn how they work together.**](https://konghq.com/webinars/api-gateway-vs-service-mesh)**API Gateway vs. Service Mesh…Join me to learn how they work together.**

## **Using a Mesh as Your Security Domain Boundary**

Kong Mesh supports multiple, logical meshes as policy and traffic boundaries, as described in [the blog post](https://konghq.com/blog/zones-meshes)the blog post explaining zones and meshes in Kong Mesh. Since a mesh provides a logical boundary, it can make sense as part of a Kong Mesh architecture that involves multiple security domains.

What advantages does using multiple meshes bring to such an environment? For one, each mesh is a separate policy domain, meaning that policies must be managed on a per-mesh basis. This reduces the possibility that a policy intended for an internal mesh might accidentally be applied to a DMZ mesh or vice versa. Once applied, a policy assigned to one mesh cannot affect traffic on a different mesh.

A multi-mesh deployment shares the benefit of aggregating metrics and observability data from a single source with a single global control plane.

Finally, cross-mesh traffic is subject to additional inspection and controls. Since traffic must exit the source mesh and then re-enter the destination mesh, network segmentation mechanisms like firewalls, network access control lists, NAT devices, or security groups can act upon these cross-mesh traffic flows.

Typically, to address an environment with multiple security domains, meshes would be combined with zones in an architecture that might look something like this:

Using a mesh as a security boundary

This approach allows you to combine the logical separation provided by a mesh with the connectivity-modeling functionality of a zone. This puts the "superpowers" of these features of Kong Mesh to their best use.

However, even this approach is not without any drawbacks. Connectivity to and from the global control plane and connectivity between the Zone Ingresses must still be allowed through whatever network segmentation devices are in place, like network firewalls. Operationally, policies need to be managed for each mesh separately, potentially introducing additional operational overhead. As mentioned earlier, though, there is the related benefit that policies can be managed independently for each mesh.

As illustrated in the diagram above, though, there is still one shared element among the different security domains: the global control plane. The final approach eliminates even that shared component.

[**The age of the load balancer has come to an end. Here's how Kong Mesh helps you break free with ZeroLB.**](https://konghq.com/webinars/zerolb)**The age of the load balancer has come to an end. Here's how Kong Mesh helps you break free with ZeroLB.**

## **Using the Global Control Plane as Your Security Domain Boundary**

The third and final approach we'll discuss in this blog post is using the global control plane as the security domain boundary. This is a true "shared nothing" architecture; each security domain maintains its own global control plane, its own set of logical meshes and its own set of connectivity-modeling zones. Each Kong Mesh instance is completely autonomous and independent of other Kong Mesh instances.

This approach might look something like the following:

Using the global control plane as a security boundary

As you can see, you can (and should!) still use zones to model the underlying connectivity, and it's still possible to use multiple meshes where it makes sense. Traffic moving between Kong Mesh instances has to exit the source instance and traverse the network to re-enter the destination instance, allowing external security mechanisms to control cross-security domain traffic and enforce appropriate security controls.

Each instance has its own control plane, so all policies are independently managed and maintained. Barring human error, this completely prevents policies in an instance of Kong Mesh in one security domain from affecting another instance of Kong Mesh in a different security domain.

While having a true "shared nothing" architecture does mean that policy and configuration are maintained separately for each Kong Mesh instance, this separate maintenance could be considered to be requiring additional operational overhead. It's not possible, for example, to create a single policy that would affect traffic "end to end" across security domains. It's also necessary to separately configure metrics and observability integration for each Kong Mesh instance. However, this configuration is a one-time task that usually occurs when Kong Mesh is deployed (and can often be automated).

## **Conclusion**

So what's the right approach for you? That depends on a lot of different factors. Some organizations may want—or even need—the rigid isolation provided by separate, independent instances of Kong Mesh in each security domain. Other organizations may want something more flexible, and choose to use a single Kong Mesh instance that leverages multiple meshes and multiple zones. The key takeaway here is that Kong Mesh supports a variety of ways to support your organization's requirements and needs. How are you going to put Kong Mesh to work in your environment?

- [Service Mesh](/blog/tag/service-mesh)Service Mesh- [API Security](/blog/tag/api-security)API Security- [Deployment](/blog/tag/deployment)Deployment

## More on this topic

_Videos_

## Zero Trust Security with Service Mesh

_Videos_

## How to Achieve Zero-Trust Security With Service Mesh

## See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

[Get a Demo](/contact-sales)Get a Demo
**Topics**
- [Service Mesh](/blog/tag/service-mesh)Service Mesh- [API Security](/blog/tag/api-security)API Security- [Deployment](/blog/tag/deployment)Deployment
Scott Lowe

Recommended posts

# 10 Ways Microservices Create New Security Challenges

[Engineering](/blog)EngineeringOctober 1, 2025

Why are Microservices Security Risks? Traditional security was simple. One perimeter. Few entry points. Clear boundaries. Microservices shattered this model. Now organizations manage hundreds of independent services. The average number of API calls

Mike Bilodeau
[](https://konghq.com/blog/engineering/10-ways-microservices-create-new-security-challenges)

# A Guide to Service Mesh Adoption and Implementation

[Engineering](/blog)EngineeringAugust 10, 2024

In the rapidly evolving world of microservices and cloud-native applications , service mesh has emerged as a critical tool for managing complex, distributed systems. As organizations increasingly adopt microservices architectures, they face new c

Kong
[](https://konghq.com/blog/engineering/implementing-a-service-mesh)

# Achieving Zero Trust on VMs with Universal Mesh

[Engineering](/blog)EngineeringJune 10, 2024

Two of the main tenets of Zero Trust are encryption between services and managing the connections each service is allowed to use. Achieving this generally falls to running a service mesh in a Kubernetes cluster. Refactoring applications to run prope

George Fridrich
[](https://konghq.com/blog/engineering/zero-trust-on-vms-with-universal-mesh)

# Reducing Deployment Risk: Canary Releases and Blue/Green Deployments with Kong

Kong Logo
[Engineering](/blog)EngineeringJune 20, 2018

When we build software, it's critical that we test and roll-out the software in a controlled manner. To make sure this happens, we make use of available tools and best practices to make sure that the software works as intended. We conduct code revie

Thijs Schreijer
[](https://konghq.com/blog/engineering/reducing-deployment-risk-canary-releases-blue-green-deployments-kong)

# Practical Strategies to Monetize AI APIs in Production

[Engineering](/blog)EngineeringMarch 27, 2026

Traditional APIs are, in a word, predictable. You know what you're getting: Compute costs that don't surprise you Traffic patterns that behave themselves Clean, well-defined request and response cycles AI APIs, especially anything that runs on LLMs

Deepanshu Pandey
[](https://konghq.com/blog/engineering/monetize-ai-apis)

# Connecting Kong and Solace: Building Smarter Event-Driven APIs

[Engineering](/blog)EngineeringMarch 20, 2026

Running Kong in front of your Solace Broker adds real benefits: Authentication & Access Control – protect your broker from unauthorized publishers. Validation & Transformation – enforce schemas, sanitize data, and map REST calls into event topics.

Hugo Guerrero
[](https://konghq.com/blog/engineering/smarter-event-driven-apis-kong-solace)

# Kong Mesh 2.6: More Flexibility, Usability, and Security

[Product Releases](/blog)Product ReleasesFebruary 1, 2024

The first release of Kong Mesh for 2024 (version 2.6) brings many new features that ease day 0 for new starters of service mesh reinforcing our goal of making a simple yet powerful product! In this blog, we'll break down these new features and provi

Charly Molter
[](https://konghq.com/blog/product-releases/kong-mesh-2-6)

## Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

[Get a Demo](/contact-sales)Get a Demo
Ask AI for a summary of Kong
  • [](https://chatgpt.com/s/t_69b981cfa37081919ce25ce107c431c1)
  • [](https://share.google/aimode/hyefOiNwl8pg8W99d)
  • [](https://www.perplexity.ai/search/what-solutions-does-kong-offer-VsYWPddxQjajgvLA4B9hjQ)
Stay connected

## step-0

    • Company
    • [About Kong](/company/about-us)About Kong
    • [Customers](/customer-stories)Customers
    • [Careers](/company/careers)Careers
    • [Press](/company/press-room)Press
    • [Events](/events)Events
    • [Contact](/company/contact-us)Contact
    • [Pricing](/pricing)Pricing
    • Legal
    • [Terms](/legal/terms-of-use)Terms
    • [Privacy](/legal/privacy-policy)Privacy
    • [Trust and Compliance](https://trust.konghq.com)Trust and Compliance
    • Platform
    • [Kong AI Gateway](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong Konnect](/products/kong-konnect)Kong Konnect
    • [Kong Gateway](/products/kong-gateway)Kong Gateway
    • [Kong Event Gateway](/products/event-gateway)Kong Event Gateway
    • [Kong Insomnia](/products/kong-insomnia)Kong Insomnia
    • [Documentation](https://developer.konghq.com)Documentation
    • [Book Demo](/contact-sales)Book Demo
    • Compare
    • [AI Gateway Alternatives](/performance-comparison/ai-gateway-alternatives)AI Gateway Alternatives
    • [Kong vs Apigee](/performance-comparison/kong-vs-apigee)Kong vs Apigee
    • [Kong vs IBM](/performance-comparison/ibm-api-connect-vs-kong)Kong vs IBM
    • [Kong vs Postman](/performance-comparison/kong-vs-postman)Kong vs Postman
    • [Kong vs Mulesoft](/performance-comparison/kong-vs-mulesoft)Kong vs Mulesoft
    • Explore More
    • [Open Banking API Solutions](/solutions/open-banking)Open Banking API Solutions
    • [API Governance Solutions](/solutions/api-governance)API Governance Solutions
    • [Istio API Gateway Integration](/solutions/istio-gateway)Istio API Gateway Integration
    • [Kubernetes API Management](/solutions/build-on-kubernetes)Kubernetes API Management
    • [API Gateway: Build vs Buy](/campaign/secure-api-scalability)API Gateway: Build vs Buy
    • [Kong vs Apigee](/performance-comparison/kong-vs-apigee)Kong vs Apigee
    • Open Source
    • [Kong Gateway](https://developer.konghq.com/gateway/install/)Kong Gateway
    • [Kuma](https://kuma.io/)Kuma
    • [Insomnia](https://insomnia.rest/)Insomnia
    • [Kong Community](/community)Kong Community

Kong enables the connectivity layer for the agentic era – securely connecting, governing, and monetizing APIs and AI tokens across any model or cloud.

  • Japanese
  • Frenchcoming soon
  • Spanishcoming soon
  • Germancoming soon
© Kong Inc. 2026
Interaction mode