Resource requirements and impact

Review the cluster resource consumption and quota behavior for each Istio service mesh deployment mode.

Resource overhead

Resource requirements for Istio mesh integration depend on the selected deployment mode and cluster footprint:

Sidecar mode
Every workload pod receives an injected Envoy sidecar proxy container, causing resource overhead to scale linearly with the total pod count (approximately 0.20 vCPU and 60 MB per pod).
Ambient mode
Traffic is captured at Layer 4 by a node-level ztunnel agent (approximately 0.06 vCPU and 12 MB per node), and a single waypoint proxy pod is deployed per Virtual Warehouse namespace for Layer 7 policy enforcement, resulting in a lower, mostly fixed overhead per namespace.
Quota management:
Cloudera Data Warehouse quota management automatically accounts for these additional proxy resources in both deployment modes.

Latency overhead

Mesh enrollment inserts proxy hops into every pod-to-pod connection. The interception occurs in the kernel (iptables rules in the pod network namespace in sidecar mode; iptables or eBPF at the node level in ambient mode) and cannot be bypassed by the application. The application connects to the peer address directly and operates transparently without awareness of the redirect.

Mode Hops added per connection Proxy Added latency per hop
Sidecar 2 (source pod proxy, destination pod proxy) Envoy: L7 HTTP parsing, routing, retries approximately 1.0–2.5 ms
Ambient 2 (source node ztunnel, destination node ztunnel) ztunnel: L4 TCP stream forwarding and mTLS only approximately 0.2–0.5 ms

The mTLS encryption cost itself is minimal compared to the hop cost. The TLS handshake runs once per connection because Cloudera Data Warehouse engines utilize long-lived connections, and symmetric encryption is hardware-accelerated. Disabling mTLS on a port removes the encryption cost, but it does not remove the proxy hop.

For standard query workloads, this overhead is negligible because query execution times are orders of magnitude larger. The primary exception is Impala's KRPC channel between coordinator and executors, which exchanges a high volume of small messages, causing per-hop latency to accumulate. For this reason, mTLS is disabled on the KRPC port in ambient mode by default. Set istio-impala-krpc-mesh-enabled: true in edws.yaml to include it in the mesh mTLS.