Kong Open Sources Kuma: The Universal Service Mesh
September 11, 2019

Kong announced the release of a new open source project called Kuma.

Based on the popular open source Envoy proxy, Kuma is a universal control plane that addresses limitations of first-generation service mesh technologies by enabling seamless management of any service on the network. Kuma runs on any platform – including Kubernetes, containers, virtual machines, bare metal and other legacy environments – and includes a fast data plane and an advanced control plane that makes it significantly easier to use. By covering the services across the entire organization, Kuma will enable greater return on current investment and drive greater value from a service mesh.

“It’s been amazing to see how quickly Envoy has been adopted by the tech community, and I’m super excited by Kong’s new ‘Kuma’ project,” said Matt Klein, creator of the Envoy proxy. “Kuma brings Kong’s proven enterprise developer focus to an Envoy-based service mesh, which will make it faster and easier for companies to create and manage cloud native applications.”

As companies increasingly adopt distributed architectures, being certain of network reliability, security and visibility is essential. Initial service mesh solutions lacked the ease-of-use and flexibility needed to ease adoption across every team. Kuma automates the process of securing the underlying network, ensuring reliability and making everything observable without having to change any code. It does that for any platform – not only for greenfield or Kubernetes-oriented applications, enabling a more pragmatic cloud native journey within the organization.

“We now have more microservices talking to each other, and connectivity between them is the most unreliable piece: prone to failures, insecure and hard to observe,” said Marco Palladino, CTO and co-founder of Kong. “It was important for us to make Kuma very easy to get started with on both Kubernetes and VM environments, so developers can start using service mesh immediately even if their organization hasn’t fully moved to Kubernetes yet, providing a smooth path to containerized applications and to Kubernetes itself. We are thrilled to be open sourcing Kuma and extending the adoption of Envoy, and we will continue to contribute back to the Envoy project like we have done in the past. Just as Kong transformed and modernized API gateways with our open source Kong Gateway, we are now doing that for service mesh with Kuma.”

Kuma is democratizing service mesh for organizations of all types without sacrificing advanced customization. First-generation meshes lacked a mature control plane, requiring substantial manual work and often custom builds. When they did provide a control plane, it was either hard to use, hard to deploy or built on immature proprietary networking libraries. Kuma, however, is designed for ease of use and enabling rapid adoption of mesh by leveraging the de-facto industry sidecar proxy Envoy.

Built on Envoy, Kuma can easily support all environments in the organization, so new applications can be built in Kubernetes, while existing applications can still be leveraged in their traditional environments, providing comprehensive coverage across an organization and the highest business value.

Kuma couples a fast data plane with an advanced control plane that allows users to easily set permissions, expose metrics and set routing rules with just a few commands by either using native CRDs or a RESTful API. The control plane is the core enabler for the service mesh that holds the master truth for all the service configurations and infinitely scales to manage tens of thousands of services across an organization. Key features include:

- Software-Defined Security – Kuma enables mTLS for all L4 traffic. Permissions can also be easily set to ensure appropriate access control.

- Powerful Productivity Capabilities – Kuma enables users to quickly implement tracing and logging, allowing them to better analyze metrics for rapid debugging.

- Sophisticated Routing & Control – Kuma provides fine-grained traffic control capabilities such as circuit breakers and health checks to enhance L4 routing.

Share this

Industry News

April 17, 2024

CIQ launched fully supported, upstream stable kernels for Rocky Linux via the CIQ Enterprise Linux Platform, providing enhanced performance, hardware compatibility and security.

April 17, 2024

Redgate launched an enterprise version of its database monitoring tool, providing a range of new features to address the challenges of scale and complexity faced by larger organizations.

April 17, 2024

Snyk announced the expansion of its current partnership with Google Cloud to advance secure code generated by Google Cloud’s generative-AI-powered collaborator service, Gemini Code Assist.

April 16, 2024

Kong announced the commercial availability of Kong Konnect Dedicated Cloud Gateways on Amazon Web Services (AWS).

April 16, 2024

Pegasystems announced the general availability of Pega Infinity ’24.1™.

April 16, 2024

Sylabs announces the launch of a new certification focusing on the Singularity container platform.

April 15, 2024

OpenText™ announced Cloud Editions (CE) 24.2, including OpenText DevOps Cloud and OpenText™ DevOps Aviator.

April 15, 2024

Postman announced its acquisition of Orbit, the community growth platform for developer companies.

April 11, 2024

Check Point® Software Technologies Ltd. announced new email security features that enhance its Check Point Harmony Email & Collaboration portfolio: Patented unified quarantine, DMARC monitoring, archiving, and Smart Banners.

April 11, 2024

Automation Anywhere announced an expanded partnership with Google Cloud to leverage the combined power of generative AI and its own specialized, generative AI automation models to give companies a powerful solution to optimize and transform their business.

April 11, 2024

Jetic announced the release of Jetlets, a low-code and no-code block template, that allows users to easily build any technically advanced integration use case, typically not covered by alternative integration platforms.

April 10, 2024

Progress announced new powerful capabilities and enhancements in the latest release of Progress® Sitefinity®.

April 10, 2024

Buildkite signed a multi-year strategic collaboration agreement (SCA) with Amazon Web Services (AWS), the world's most comprehensive and broadly adopted cloud, to accelerate delivery of cloud-native applications across multiple industries, including digital native, financial services, retail or any enterprise undergoing digital transformation.

April 10, 2024

AppViewX announced new functionality in the AppViewX CERT+ certificate lifecycle management automation product that helps organizations prepare for Google’s proposed 90-day TLS certificate validity policy.

April 09, 2024

Rocket Software is addressing the growing demand for integrated security, compliance, and automation in software development with its latest release of Rocket® DevOps, formerly known as Aldon®.