Talk to us
by KongTechBag Intel Page

Kong Mesh

Every service calls a dozen others. Each call should prove who is calling — Kong Mesh puts an Envoy proxy beside every service — in Kubernetes, on VMs or on bare metal — to encrypt, authorise and route every call between them, across one zone or many.

mTLS on every service callKubernetes, VMs, many zonesQuote, per data plane proxy

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
licensed per data plane proxy
Quote only
Built on
CNCF Sandbox open-source core
Kuma + Envoy
Runs on
single zone or multi-zone
K8s · VMs
India
Konnect India geo stores mesh config
IN geo or self-host

Quick answer

Kong Mesh is Kong’s enterprise service mesh: it gives every service an identity, encrypts service-to-service calls with mutual TLS and applies traffic and access policies through Envoy proxies. It is built on Kuma, the free open-source CNCF project, and adds OPA, FIPS 140-2, RBAC and external CA backends. It runs on Kubernetes, VMs or bare metal, in one zone or many, with the global control plane self-hosted or run by Kong in Konnect. Licensing counts data plane proxies; the price is by quote. Read more ↓ Show less ↑
Part 01 · Orient

The Kong platform family

This page covers Kong Mesh — the enterprise service mesh. The rest:

Quick facts

30-second orientation
Product
Enterprise service mesh, Envoy-based
Built on
Kuma — CNCF Sandbox project since 2020
Runs on
Kubernetes, VMs and bare metal
Topology
Single zone or multi-zone, multi-mesh
Control plane
Self-hosted, or global CP in Konnect
Licence metric
Data plane proxies across all zones
Price
Quote only — not on the Konnect Plus card
No licence file
Bundled licence: 10 proxies, 30 days
India
Self-host, or Konnect’s India (IN) geo
In India via
TechBag — sizing, INR/GST and support
Part 02 · Learn

Understand service meshes before you buy one

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is a service mesh?

A layer of proxies beside your services that encrypts, authorises and routes every call between them — without changing application code.

Hand-wired TLS and per-app retries vs one service mesh — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionPer-app TLS, retries and firewall rulesKong Mesh
Encryption between servicesTLS set up per app, when someone remembersMutual TLS on every call, issued by the mesh
Who may call whomIP allow-lists and firewall ticketsMeshTrafficPermission by service identity
Retries and timeoutsCoded differently in every serviceRetry, timeout and circuit-breaker policies
VMs next to KubernetesA separate network story for eachOne mesh across Kubernetes and Universal mode
Several clusters or sitesPer-cluster config, copied by handA global control plane syncing every zone
What it is NOT—Not an API gateway or portal — that is Konnect

The cheapest test is two services that already call each other: mesh them, switch on mTLS and a traffic permission, and see what breaks.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Beside every service

Data plane

Envoy data plane proxies

An Envoy proxy runs beside each workload — a sidecar on Kubernetes, a process on a VM — carrying its traffic, identity and policy. The licence counts these.

02
One per cluster or site

Zone CP

Zone control planes

Each zone control plane registers its own proxies, zone ingress and egress, and reports status upward. A zone can be a cluster, a data centre or a cloud region.

03
The source of truth

Global CP

Global control plane

The global control plane holds meshes and policies and pushes them to every zone. Run it yourself, or let Konnect host it while zone control planes stay with you.

04
How traffic behaves

Policies

Policy resources

MeshTrafficPermission, MeshHTTPRoute, MeshRetry, MeshCircuitBreaker and similar resources set access, routing and resilience without touching application code.

A proxy beside every service, a control plane per zone, one global plane for policy — on your servers or in Konnect.

Part 03 · Evaluate

Nine capabilities. Connect, secure, operate.

Kong Mesh secures and routes every call between your services, wherever those services run.

Connect
Hybrid

Kubernetes and VMs in one mesh

Kubernetes mode and Universal mode for VMs and bare metal join the same mesh, so a legacy service and a pod call each other the same way.

Connect
Multi-zone

Many clusters, one policy set

A global control plane syncs meshes and policies to every zone; zone ingress and egress carry calls between clusters, sites and clouds.

Connect
Routing

L4 and L7 routing, retries

HTTP and TCP routes, retries, timeouts, health checks and circuit breakers are set as policies, not coded into each service.

Secure
mTLS

Mutual TLS with your own CA

Enterprise adds HashiCorp Vault, AWS Private CA and cert-manager as mTLS backends, plus CA rotation — say, moving from the built-in CA to Vault.

Secure
Policy

OPA inside the proxy

An Open Policy Agent ships in the data plane sidecar, so access decisions for a service can use Rego policies you already maintain.

Secure
Compliance

FIPS 140-2 mode

Kong Mesh uses Envoy’s FIPS-compliant BoringSSL mode — relevant where a customer or regulator asks for validated crypto. Not on macOS.

Operate
Access

RBAC and an audit trail

AccessRole and AccessRoleBinding limit who may change which policy; the AccessAudit resource records user and system actions.

Operate
Observability

Prometheus and OpenTelemetry

Service-to-service metrics and traces flow to Prometheus or an OpenTelemetry collector you already run, with no agent of Kong’s own.

Operate
Konnect

A Kong-hosted global plane

Konnect can host the global control plane and show services, zones and proxies in one view; zone control planes still run with you.

See it, don’t just read it

Watch Kong Mesh in action

Multi-zone traffic and load balancing, a tour of Kong Mesh in Konnect, and an older OpenShift quickstart — Kong has published little mesh video since 2024.

Kong (official)·Jan 2025 · 34 min

Services, Multizone & Load Balancing: Combining it all Together in Kong Mesh

Multi-zone traffic and load balancing, end to end.

Kong (official)·Sep 2024 · 4 min

Intro to The Kong Konnect Mesh Manager, Guided Tour of Federated Service Management

Recorded 2024; Konnect’s mesh screens may look different now.

Kong (official)·2023 · 15 min

Kong Mesh Quickstart for OpenShift 4.12

Older and OpenShift-specific — check steps against current docs.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Kong Mesh

Your services don’t all live in Kubernetes. Kong Mesh doesn’t assume they do.

Here’s what genuinely sets it apart — and exactly where it stops.

01

One mesh for pods and the VMs beside them

Most Indian estates are not all Kubernetes: a core banking adapter on a VM, a payments service in a cluster, a batch job on bare metal. Kong Mesh runs its Envoy proxy in all three, so the same identity, mTLS and traffic rules cover calls between them — not just calls inside one cluster.

02

Open-source core, enterprise controls on top

Kuma, the CNCF Sandbox project underneath, is free and Apache-2.0. Kong Mesh adds what an audit asks for: FIPS 140-2 mode, OPA in the proxy, RBAC, zone authentication, Vault or AWS Private CA for certificates, UBI images, and signed images with build provenance on recent releases.

03

Run the control plane yourself, or let Kong

The global control plane can sit on your servers in India, or in Konnect, whose India (IN) geo stores control-plane data such as service meshes and zones in-geo, per Kong’s docs; only authentication, billing and usage cross geos. Zone control planes and proxies stay in your environment either way.

04

Where it stops

There is no public price: Kong quotes per data plane proxy, and Mesh is not on the Konnect Plus card. It is a sidecar mesh, so every counted pod or VM carries an Envoy proxy. It governs traffic between your services; the API front door, portals and API keys are Kong Konnect’s job.

The idea
mTLS on every service call
The reach
Kubernetes, VMs, many zones
The price
Quote, per data plane proxy
Proof, not promises

The numbers behind the platform

10
data plane proxies allowed by the bundled licence with no file
— Kong docs
30 days
before that bundled licence expires
— Kong docs
6
Konnect geos, India among them, for a hosted control plane
— Kong docs
2 years
of support for each yearly LTS release
— Kong docs
4
minor releases a year, from January 2026
— Kong docs
3
external CA backends for mTLS: Vault, AWS Private CA, cert-manager
— Kong docs

What your Kong Mesh rollout looks like

Week 1Model

Count proxies across every zone

Add up pods and VMs that will join the mesh in every cluster and site — that total is what Kong’s quote counts.

Week 2Scope

Pick where the control plane lives

Self-host the global control plane in India or use Konnect’s IN geo, and ask Kong for a trial licence file.

Week 3Pilot

Mesh one service pair

Put two services that call each other into the mesh, turn on mTLS and a traffic permission, and check nothing breaks.

Month 2Extend

Bring in the VMs and a second zone

Join VM workloads in Universal mode and a second cluster or site, then test failover between the two zones.

Month 3Commit

Default-deny and hand over

Switch to deny-by-default permissions, move retries and timeouts into policies, and set RBAC for each team.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
60+ reviews*
84% would recommend
VM and Kubernetes mix4.5
Multi-zone setup4.3
Policy model4.2
Learning curve3.6
Price transparency3.4
5★
48%
4★
34%
3★
12%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Our settlement engine lives on VMs and will for years. Kong Mesh let those VMs and our new pods share one mTLS trust domain.”
Platform Architect
BFSI
Telecom
“Two data centres became two zones under one global control plane. Failover rules are written once instead of per site.”
SRE Lead
Telecom
Insurance
“The auditor asked for FIPS mode and a CA we control. Pointing the mesh at our Vault CA answered both questions.”
Security Architect
Insurance
E-commerce
“Counting proxies was the hard part of the quote — every pod and VM counts, and our replica numbers swing with load.”
Engineering Manager
E-commerce
SaaS
“We trialled on the bundled licence and hit its proxy cap in a week. Ask Kong for a proper trial file on day one.”
DevOps Engineer
SaaS
Logistics
“Retries and circuit breakers moved out of four codebases into mesh policies. Our Java and Go teams stopped arguing.”
Head of Engineering
Logistics
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the service mesh market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Service Mesh Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Kong MeshThis page

Kuma-based; Kubernetes, VMs and multi-zone.

Grid 02 · The architecture

Runtime Reach × Enterprise Hardening

The grid nobody publishes — how far beyond Kubernetes it reaches vs how much enterprise hardening comes with it.

Hardened, Kubernetes-boundHardened and universalCluster-native basicsWide reach, fewer extras
Kong MeshThis page

K8s, VMs, bare metal; FIPS, OPA, RBAC.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Kong Mesh vs the service mesh field

Against open-source Istio, Solo Enterprise for Istio, HashiCorp Consul Enterprise, Buoyant Enterprise for Linkerd and Cilium — on runtimes, price, security, support and India.

DimensionKong MeshIstio (open source)Solo Enterprise for IstioHashiCorp Consul EnterpriseBuoyant Enterprise for LinkerdCilium service mesh
What it isEnterprise Kuma meshCNCF graduated meshHardened Istio buildDiscovery plus meshSupported LinkerdeBPF networking + mesh
DeploymentK8s, VMs, bare metalSelf-run, K8s-centredYour clustersSelf-managed onlyK8s, plus Linux VMsKubernetes only
Coverage and topologyMulti-zone, multi-meshMulti-cluster, ambientIstio multi-clusterMesh needs PremiumMulti-cluster failoverCluster Mesh
Pricing modelPer data plane proxyFree, Apache-2.0Tiered, by estimateStandard vs PremiumPremium vs StrategicFree, or Cisco quote
Published entry priceNone — quote only$0Not publishedNot publishedFree under 50 staff$0 open source
Included vs add-onExtras in the licenceUpstream features onlySupport, FIPS, UIMesh is the upper tierFIPS on StrategicHubble in the core
Scale and limitsProxies may overrunNo licence capIstio scale, supportedMulti-datacenterZone-aware balancingNo sidecar per pod
Security depthmTLS, OPA, FIPS, SPIFFEmTLS and authzFIPS, long CVE windowmTLS, FIPS 140-3mTLS, FIPS optionalMutual auth in beta
IntegrationsVault, OTel, Kong GWWidest ecosystemIstio ecosystemHashiCorp stackKubernetes nativeHubble, Istio interop
Governance and SSORBAC and audit logKubernetes RBACIstio APIs + Solo UIPartitions, OIDCPolicy, not tenancyKubernetes RBAC
India storage regionSelf-host or IN geoWherever you run itYour own clustersSelf-managed in IndiaYour own clustersYour own clusters
SupportIn the Kong quoteCommunity onlyThree tiers, n-4IBM licensed support24x7 on StrategicVia Cisco
Lock-in and exitKuma is the fallbackOpen standard APIsUpstream Istio APIsBUSL and IBM termsEdge releases onlyTied to your CNI
Best fitPods and VMs togetherSkilled platform teamsIstio, with supportHashiCorp estatesLean Kubernetes meshCilium-run clusters
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Kong Mesh if…

  • ✓Your services run on VMs and bare metal as well as Kubernetes, across more than one site
  • ✓Audits ask for FIPS mode, OPA policies and certificates from a CA you already run
  • ✓You want the option of a Kong-hosted global control plane, with India (IN) as its geo

Compare alternatives if…

  • ✓Everything is Kubernetes and your team can run free open-source Istio or Linkerd itself
  • ✓Your clusters already run Cilium and you would rather avoid sidecars
  • ✓You are a HashiCorp shop that needs Consul’s service discovery as well

Do not expect…

  • ✓A published price — Kong quotes per data plane proxy
  • ✓The bundled licence to cover a real pilot — it stops at 10 proxies and 30 days
  • ✓An API gateway, developer portal or API keys — those are Kong Konnect

Kong Mesh is one of 35 developer tools products TechBag carries. The Developer Tools guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does hand-wired service security cost you?

Drag the sliders (services in the mesh; engineer-hour cost). Estimates model engineering time spent wiring service-to-service TLS, retries, timeouts and access rules by hand — at an assumed 1.5 hours per service a year, with 70% of it avoided once a mesh applies them as policy. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual hand-wiring cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only: Kong publishes no price for Kong Mesh, and it is not on the Konnect Plus card. The licence counts data plane proxies — pods plus VMs across every zone — and has an expiry date; without a licence file, a bundled licence allows 10 proxies for 30 days. Kuma, the open-source core, is free. TechBag counts your proxies first, then quotes in INR with GST.

Self-hosted control plane

Best when everything must run on your servers

  • Quote, per data plane proxy
  • Global and zone control planes in your estate
  • Kubernetes, VMs or bare metal

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Global control plane in Konnect

Best when you would rather not run the global plane

  • Quote, per data plane proxy
  • Kong hosts the global control plane
  • India (IN) geo; zones stay with you

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Proxy count

How many pods and VMs will join the mesh across all zones — at peak replica counts, not the average?

2
Runtimes

Which services run on VMs or bare metal? If none do, compare the Kubernetes-only meshes before you buy.

3
Control plane

Will the global control plane run on your servers or in Konnect — and which geo will you choose?

4
Data residency

Is Konnect’s India (IN) geo enough for your regulator, given Kong does not name its city or cloud region?

5
Certificates

Which CA should issue mesh certificates — the built-in one, HashiCorp Vault, AWS Private CA or cert-manager?

6
Compliance

Do you need FIPS 140-2 mode, OPA policies or signed images with build provenance? Confirm your version.

7
Trial licence

Have you asked Kong for a trial file? The bundled licence stops at 10 proxies and expires after 30 days.

8
Upgrades

Which LTS will you standardise on? Kong ships four minors a year and supports each LTS for two years.

FAQ

Questions buyers ask

Kong’s enterprise service mesh. An Envoy proxy beside each service handles mutual TLS, identity, routing, retries and access rules, set by a control plane rather than in application code. It is built on the open-source Kuma project and runs on Kubernetes, VMs and bare metal, in one zone or many.

Ready to evaluate Kong Mesh?

Count the pods and VMs that will join the mesh first, or let a TechBag advisor scope a pilot on one pair of services with a proper trial licence.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.