Now supporting eBPF sidecarless mode

Monitor, trace, and secure
every container in your mesh

ServiceMesh is the observability and security layer your platform team has been duct-taping together. Uptime monitoring, distributed tracing, mTLS, and traffic shaping for every container — in one mesh, across every cloud.

$ kubectl apply -f https://servicemesh.io/install.yaml

app.servicemesh.io / mesh / production
ServiceMesh observability dashboard preview

/ Built for platform engineers

Built by engineers who got tired of stitching together six observability tools, four service-discovery hacks, and a homegrown rate limiter.

One mesh, one bill, one place to debug.

Observability

Distributed tracing without the spaghetti

Auto-instrumented spans across every service. Trace a request from edge to database in one click, no SDK rewrites required.

Zero-trust security

mTLS everywhere, by default

Identity-based authorization between every workload. Rotate certs automatically and enforce policy from a single pane.

Traffic shaping

Canary, blue-green, dark launch

Shift traffic by header, weight, or geography. Roll back in seconds when SLOs drift, without redeploying a single pod.

SLO alerting

Burn-rate alerts that page the right team

Define SLOs once, route to the on-call who actually owns the service. No more 3am pages for someone else's bug.

Multi-cluster

One mesh across every region

Federate clusters in EKS, GKE, AKS, or bare-metal. Failover regions without a Slack thread of fifteen engineers.

eBPF native

Sidecarless mode for 4x lower latency

Run with kernel-level eBPF data plane when you need raw speed, or sidecar mode when you need flexibility. Switch per-namespace.

/ Architecture

See the full picture.
One mesh, every cluster.

ServiceMesh injects a lightweight proxy next to every workload — or runs sidecarless with eBPF — and gives you a real-time picture of traffic, identity, and health.

p99 latency
12.4ms−18%
Request success rate
99.98%+0.04%
Active workloads
1,284+62
mTLS coverage
100%stable

Live mesh view

healthywarning

One agent per workload

A lightweight Envoy sidecar (or eBPF agent) runs alongside every container, capturing every request, enforcing every policy, and reporting real-time telemetry — all without touching your application code.

/ Use cases

One mesh for every team

01Platform teams

Give every team a self-service mesh

Abstract away traffic routing, retries, timeouts, and observability behind a single CRD. Your application teams get production-grade defaults without learning Envoy.

  • Templated service onboarding
  • GitOps-native policy
  • Self-service traffic splits
02SRE & on-call

Cut MTTR from hours to minutes

When a service degrades, you see the blast radius in one view: which upstreams, which versions, which regions. Stop guessing, start fixing.

  • Live dependency maps
  • Auto-correlated alerts
  • One-click traffic shift
03Security teams

Audit every byte that moves between workloads

Cryptographic identity per service, signed audit logs, and policy-as-code. Pass SOC 2 and FedRAMP audits without weeks of evidence-gathering.

  • SPIFFE-based identity
  • Per-request policy
  • Tamper-proof audit trail

/ Plays nice with everything

Drops into the stack you already run.

ServiceMesh speaks OpenTelemetry, Prometheus, SPIFFE, and Envoy xDS out of the box. Bring your own dashboards, your own SIEM, your own incident pipeline — we'll feed them clean signal instead of noise.

Browse all 80+ integrations
Kubernetes
Prometheus
Grafana
Datadog
OpenTelemetry
Jaeger
Envoy
Linkerd
Vault
Terraform
ArgoCD
PagerDuty
Priya Raman, Staff SRE at Lattice Financial
We replaced three observability tools and a homegrown sidecar with ServiceMesh. Our p99 dropped 40% and our on-call pages dropped even more.
PR
Priya Raman
Staff SRE, Lattice Financial
40%
lower p99
3→1
tools replaced
8min
avg MTTR

/ Pricing

Pay for traffic, not seats.

No per-user pricing, no per-cluster gotchas. Bring the whole team — your bill scales with the requests we mesh, nothing else.

Starter

$0forever

For solo developers and small teams kicking the tires.

  • Up to 5 services
  • Community support
  • 1 cluster
  • Basic metrics & traces
  • mTLS included
Get Started
Most popular

Pro

$99/month

For growing teams that need reliability and control.

  • Up to 50 services
  • Email & Slack support
  • 5 clusters
  • Advanced metrics & traces
  • Custom policies
  • 99.9% SLA
Start Free Trial

Enterprise

Custom

For organizations that need dedicated infrastructure and compliance.

  • Unlimited services
  • Dedicated support
  • Unlimited clusters
  • Custom integrations
  • Audit logs & SOC 2
  • 99.99% SLA
  • On-prem option
Contact Sales

One mesh to rule them all.

Uptime monitoring, distributed tracing, mTLS, and traffic management for every service you run — built by engineers who've been on call too many Fridays.

Start free — no card needed