Infrastructure · Software component

Service Mesh Proxy

Software componentInfrastructureInfrastructurearc:ServiceMeshProxy

A sidecar proxy deployed beside each agent container that intercepts all inbound and outbound traffic to apply routing, resilience, mutual TLS and tracing without application changes.

Responsibility. Applies traffic, security and telemetry policies transparently to inter-service calls.

Also known as: Sidecar proxy, Service mesh

guards; routes toemits telemetry todeployed onhostshostshostsAgent Controller: guards; routes toAgent ControllerTrace Collector: emits telemetry toTrace CollectorContainer Orchestrator: deployed onContainer OrchestratorRetry Handler: hostsRetry HandlerCircuit Breaker: hostsCircuit BreakerCanary Rollout Controller: hostsCanary Rollout Controller
Direct neighbourhood (hover for relationship types)

Relationships

deployed on structural

hosts structural

emits telemetry to dynamic

routes to dynamic

guards control

Design guidance

Quantitative guidance

As stated by the sources; verify before use.

Classification

Patterns
SidecarMutual TLSTraffic splittingDistributed tracing
Technologies
IstioLinkerdConsul
Quality attributes
Security (ISO/IEC 25010 | NIST AI RMF: secure and resilient)Maintainability (ISO/IEC 25010)Reliability (ISO/IEC 25010 | NIST AI RMF: valid and reliable)
Risks mitigated
Unencrypted inter-agent trafficCascade failuresOpaque multi-service request paths

Sources

  1. Ch4.3: T. Nguyen, "Container Orchestration and Edge Deployment," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 4.3. ISBN: 9798244538229.