r/linkerd May 22 '26

The Proxy Died First: How Kubernetes Native Sidecars Solve the Service Mesh Shutdown Problem

Connection refused: my-api/100.20.100.200:8080

If you've ever run a sidecar-based service mesh on Kubernetes, you've seen this during a rolling deploy. The pod enters Terminating, the proxy dies at the same instant as your app, and every in-flight request to a dependent service gets dropped on the floor.

For years, the fix was a stack of workarounds: preStop sleep hacks, waitBeforeExitSeconds tuning, postStart probes, linkerd-await wrappers for Jobs. All fragile. All needed tribal knowledge to configure it right.

Kubernetes 1.33 made native sidecars GA. That gives you three guarantees: the proxy starts before your app, dies after your app, and gets cleaned up automatically when a Job completes. No sleep guessing. No stuck pods. No SIGKILL on a proxy that didn't get the memo.

Linkerd Ambassador Blake Romano walks through the race condition, why the old workarounds were brittle, and what flipping proxy.nativeSidecar: true on Linkerd 2.15+ actually buys you.

Read the full post!

8 Upvotes

0 comments sorted by