Envoy is an open-source edge and service proxy designed for cloud-native applications. It provides advanced L3-L7 traffic management, observability, and extensibility via filters, supporting dynamic discovery, TLS, and HTTP/2/gRPC. Envoy is commonly used as a sidecar, gateway, or load balancer to centralize routing, resilience, and telemetry in microservice…
Use this profile to understand the building block briefly, place it in the model, and open related building blocks.
Technical building block: can be automated, integrated, or operated.
Concrete cog in the system that works inside larger relationships.
Envoy is an open-source edge and service proxy for cloud-native applications. It manages L3–L7 traffic, makes communication observable, and can be extended with filters for routing, security, and resilience.
Envoy originated at Lyft, where it was built to support a move away from a monolithic architecture and to make network traffic more transparent to applications. Lyft contributed the project to the Cloud Native Computing Foundation in 2017. It then developed into an open proxy used as a building block for service-mesh, gateway, and edge setups.
Think of Envoy as a programmable traffic gate. A request reaches a listener, is assigned to an upstream by a routing rule, and passes through a filter chain that can inspect, enrich, limit, or measure it. Dynamic service discovery supplies targets at runtime; the same instance can operate as a sidecar, gateway, or load balancer.
An infrastructure layer governs communication between microservices.
A sequence of filters can inspect, enrich, limit, or measure requests.
Targets and upstreams can be resolved at runtime and fed into forwarding decisions.
Metrics, logs, and traces reveal behavior, latency, and failures.
Envoy can run close to the workload, at the edge, or in front of a service group.
Envoy is useful when traffic should be routed, secured, and observed centrally without heavily reshaping the applications. It is especially strong in service-mesh and gateway architectures, TLS termination, and uniform telemetry. The trade-off is additional operational and configuration overhead, plus dependence on clean routing and well-maintained upstream data.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.