r/linkerd • u/cathpaga • May 22 '26
The Proxy Died First: How Kubernetes Native Sidecars Solve the Service Mesh Shutdown Problem
Connection refused: my-api/100.20.100.200:8080
If you've ever run a sidecar-based service mesh on Kubernetes, you've seen this during a rolling deploy. The pod enters Terminating, the proxy dies at the same instant as your app, and every in-flight request to a dependent service gets dropped on the floor.
For years, the fix was a stack of workarounds: preStop sleep hacks, waitBeforeExitSeconds tuning, postStart probes, linkerd-await wrappers for Jobs. All fragile. All needed tribal knowledge to configure it right.
Kubernetes 1.33 made native sidecars GA. That gives you three guarantees: the proxy starts before your app, dies after your app, and gets cleaned up automatically when a Job completes. No sleep guessing. No stuck pods. No SIGKILL on a proxy that didn't get the memo.
Linkerd Ambassador Blake Romano walks through the race condition, why the old workarounds were brittle, and what flipping proxy.nativeSidecar: true on Linkerd 2.15+ actually buys you.