• Home
  • Workshops
  • Services
  • Contact
Mont-Cenis-Straße 399, Herne 44627, Germany
+49 (0) 221 9865099 0
hello@devninjas.io

Workshops

  • Docker Fundamentals
  • Kubernetes Introduction
  • CKAD Exam Prep
  • CKA Exam Prep
  • All Workshops

Services

  • Shogun · Platform Consulting
  • Mamori · Managed Retainer
  • Kensho · Platform Audit

Company

  • Contact
  • Sitemap
2026 • Coded with by DevNinjas
  • Imprint
  • Privacy
  • GTC

Introduction to Istio and Service Mesh

After three days you operate a production-ready Istio service mesh on Kubernetes. From installation through traffic management, mTLS and ambient mesh to Prometheus monitoring and Kiali visualization: everything live online and hands-on on your own cluster.

Share via email
  • Workshop levelSome practical experience recommended
  • Satisfied participants2340+
  • Days3
  • LanguageGerman & English
  • Workshop codeDW16

Workshop Details

What makes this workshop stand out

🎯

What you will learn and take away

After three days of Istio training you configure a service mesh independently. What you take away:

  • Control traffic precisely: Use VirtualService, DestinationRule and the Gateway API for canary deployments, A/B tests and weighted routing
  • Implement zero trust in your cluster: Enable mTLS, write AuthorizationPolicy rules and control access at the service level
  • Find problems in the mesh: Track down latencies, errors and bottlenecks in service communication with Prometheus, Grafana, Jaeger and Kiali

All exercises run in our cloud environment. Dedicated cluster per participant, no local setup.

Want to go further? Our Kubernetes Observability Training deepens monitoring well beyond Istio.

💼

Why the investment pays off

When your microservices communicate unencrypted and every release risks all traffic, the problem is not discipline but infrastructure. This Istio training changes that:

  • Security without code changes: mTLS and authorization policies encrypt and control all service communication at the infrastructure level
  • Releases without risk: Canary deployments and traffic mirroring enable gradual rollouts your team controls independently
  • Transparency instead of guesswork: Prometheus metrics and distributed tracing make latencies and errors visible before customers notice them

Small groups of maximum 8 participants, so we can address questions from your specific project context.

📋

Prerequisites

Required:

  • Experience with Kubernetes: Pods, Services, Deployments and Namespaces should be familiar
  • Basics of Kubernetes networking: know ClusterIP, NodePort and Ingress
  • Comfortable with kubectl and the Linux command line

Not required:

  • Prior experience with Istio or service mesh (built from scratch)
  • Programming skills (all configurations are YAML-based)

Our Kubernetes Fundamentals Training provides the ideal preparation if you still need the Kubernetes basics.

Workshop Agenda

Your Agenda at a Glance

Hands-on and structured. Every participant works in their own cloud environment. The agenda shows you what to expect each day.

Day 1: Understand service mesh, install Istio and route your first traffic

5 topics
09:00–10:00💬 Introduction Round

When does a service mesh pay off and when are plain Kubernetes Services enough? This module settles the fundamental question before you dive into Istio. You compare three widely used approaches (Istio, Linkerd, Cilium) against concrete criteria: resource consumption, feature scope, operational overhead and team requirements. By the end, you can assess whether and which service mesh fits your own project.

Istio consists of two layers: the control plane with Istiod and the data plane with Envoy proxies. You learn how Istiod distributes configuration to proxies, what role the xDS APIs play and why Envoy became the most widely used service mesh proxy. After this block, you read Istio architecture diagrams without guesswork.

istioIstioenvoyEnvoy
12:00–13:00🥪 Lunch Break

First hands-on session: you install Istio on your own cluster using istioctl and alternatively via Helm chart. Then you deploy a microservice application and enable automatic sidecar injection through a namespace label. You verify the mesh configuration with istioctl analyze and inspect the injected Envoy container inside a running pod.

istioIstio

With VirtualService and DestinationRule you control which traffic flows where. You configure weighted routing (90/10 split between two versions), header-based rules and subset routing. You watch the traffic shifts live in Kiali as they happen. This module lays the groundwork for canary deployments and A/B testing on the next day.

How does external traffic enter your mesh? You configure an Istio Gateway for HTTPS ingress and compare it with the new Kubernetes Gateway API, stable since Istio 1.22. The Gateway API separates infrastructure from application configuration more cleanly than the legacy model. By the end, you route external traffic through TLS-terminated gateways to your services.

16:00–16:30💭 Questions & Answers

Day 2: Secure services, build resilience and explore ambient mesh

5 topics
09:00–10:00💭 Questions & Answers

Without mTLS, all cluster traffic runs unencrypted. You enable PeerAuthentication in strict mode, verify encryption with istioctl proxy-config and observe how Istio rotates certificates automatically. Afterward you understand the difference between permissive and strict mode and know how to roll out mTLS gradually without disrupting running services.

istioIstio

Encryption alone is not enough: who may call which service? You write AuthorizationPolicy rules at namespace and workload level, allowing or denying traffic by source, path and HTTP method. Then you configure RequestAuthentication with JWT validation for external access. The result: a mesh where every call must be explicitly permitted.

12:00–13:00🥪 Lunch Break

What happens when a service stops responding? You configure a circuit breaker in a DestinationRule to prevent cascading failures and define retry policies with backoff strategies. Using fault injection, you deliberately simulate latencies and HTTP errors to test application behavior under stress. Chaos engineering with Istio's built-in tooling instead of external tools.

Roll out new versions safely without risking the entire system: you implement a canary deployment with weighted routing (first 5%, then 25%, then 100%) and monitor metrics at each stage. In parallel, you use traffic mirroring to shadow production traffic to a new version without affecting end users. Both strategies build directly on the VirtualService rules from day 1.

Since Istio 1.24, ambient mode is production-ready and offers an alternative to the classic sidecar approach. You migrate an application from sidecar to ambient mode, compare resource consumption and latency of both variants and learn the architecture with ztunnel (L4) and waypoint proxies (L7). By the end you know when ambient is the better choice and when sidecars still have the edge.

istioIstioenvoyEnvoy
16:00–16:30💭 Questions & Answers

Day 3: Build observability, master operations and go production-ready

5 topics
09:00–10:00💭 Questions & Answers

Istio automatically generates metrics for every connection in the mesh. You install Prometheus as metrics backend, import the bundled Grafana dashboards and analyze request rates, latencies and error rates per service. Instead of just showing pre-built dashboards, you write your own queries to understand the metrics Istio exposes through Envoy.

prometheusPrometheusgrafanaGrafana

Where does latency hide in a chain of five services? With Jaeger you trace individual requests across the entire mesh and identify bottlenecks at a glance. In Kiali you see the service topology as an interactive graph: which service calls which, where do errors accumulate, where does most traffic flow? Both tools together provide the complete picture for debugging and capacity planning.

12:00–13:00🥪 Lunch Break

Installing a mesh is the easy part. In production, what matters is: how do you perform a canary upgrade of Istio itself? How do you find out why an Envoy proxy rejects traffic? You work with istioctl analyze, proxy-config dump and proxy-status to diagnose typical misconfigurations. These include sidecar version mismatches, broken mTLS policies and forgotten namespace labels.

For teams with more than one cluster: you learn how Istio connects multi-cluster setups with shared or separate control planes. Additionally, we cover ServiceEntry for external services, egress control and performance tuning (proxy concurrency, access log sampling). This module summarizes the best practices that separate a demo installation from a production-ready mesh.

All topics from the three days in one exercise: you independently deploy a microservice application into the mesh, configure mTLS, set up a canary deployment, establish monitoring with Prometheus and Grafana and debug an intentionally broken configuration. No step-by-step guide: you work with the tools and concepts you learned over the three days.

istioIstioprometheusPrometheusgrafanaGrafana
16:00–16:30💭 Questions & Answers

Our Benefits

All from one hand!

With our high-quality trainings and workshops, you can bring yourself and your team up to date. All this with many benefits that you get from us.

👨‍💻High Practical Content
70% hands-on, 30% theory. You work continuously with real scenarios and take working code home with you. No PowerPoint battles, but directly applicable knowledge for your projects.
☁️Cloud Learning Environment
DevNinjas Dojo: Your own Kubernetes clusters and VMs for each participant in the browser. No installation, works despite VPN/proxy/firewalls. You work with dedicated resources, not in shared environments.
🥷Experienced Trainers
Full-time DevOps engineers and consultants from DevNinjas lead the workshops. Not external trainers, but specialized employees actively working on client projects and sharing real-world experience.
👥Small Groups
Maximum 8 participants per workshop. Everyone gets individual support from the trainer. Your specific questions and use cases get answered, not passed over in anonymous crowds.
🏗️Real-World Scenarios
No toy examples or hello-world demos. You work with production-grade setups: multi-container applications, CI/CD pipelines, monitoring stacks. Directly transferable to your production environments.
🎓Certification
You receive an official certificate of attendance as PDF and a verified LinkedIn badge. Document your professional development for your employer, HR, and recruiters professionally.

Testimonials

How participants experience our trainings

4.9/ 5

1047+ participant reviews · unfiltered

across all DevNinjas trainings

Trainer
5.0
Content
4.8
Hands-on
4.8

DevNinjas overall: over 1,384 participants · 207 companies · 241 workshops

Including BMW, Bundeswehr, Deutsche Bahn and many more.

"My colleagues specifically looked for a sysadmin course for Docker with another provider and had an instructor who only set up an IDE for them and then only worked on a task sheet with development tasks. I had a course with lots of background information, an instructor who had a really extensive knowledge of the whole subject matter beyond the slides, and I feel optimally informed."

Default avatar picture of DevNinjas
Johannes Bernstein
@TRIMET Gelsenkirchen SE

"The advanced Kubernetes workshop at DevNinjas really helped me grow professionally. The content was practical and excellently prepared, so even complex topics like RBAC, network policies and Ingress were conveyed in an understandable and directly applicable way. The deep expertise of the trainer was especially impressive and noticeable in every session. I can recommend this workshop to anyone who wants to use Kubernetes in production!"

Default avatar picture of DevNinjas
Marius Büttner
@Siemens AG

"From my perspective, the workshop had the right speed and an appropriate level of challenge. The subject matter was explained clearly by the instructor and practically consolidated with well-distributed exercises. Adjusting the workshop focus to the participants wishes was not a problem. Valuable practical experiences were shared, and even more specific questions were gladly answered. The instructor's professional expertise and extensive practical experience on the subject gave this workshop a special quality."

Default avatar picture of DevNinjas
S. Kaiser
@forcont business technology GmbH

"The instructor is very competent and was able to answer all questions satisfactorily even outside the presentation. It was a very pleasant workshop with a good learning pace. I learned a lot and look forward to applying and expanding my acquired knowledge in everyday work, as well as privately."

Default avatar picture of DevNinjas
Schmucker
@RODIAS GmbH

"The training exceeded my expectations by far. It was excellently structured, and the trainer's expertise was evident from the very first moment. The topics were presented vividly and with practical examples, and the exercises were pleasantly challenging, exactly right for a course like this. Through targeted questions, the trainer drew me so deeply into the subject that I absolutely wanted to keep working after the session ended. The teaching was outstanding too: topics were explained clearly and the trainer always addressed follow-up questions. I can recommend DevNinjas one hundred percent."

Default avatar picture of DevNinjas
Patrick J.

"In the workshop the most important Docker and Kubernetes topics were put together, prepared and explained superbly. The exercises fit precisely and were very well chosen in terms of difficulty. I am very satisfied with how much I learned in the five days and feel well prepared for upcoming tasks at work. Sure, you can teach yourself a lot on your own with AI tools, but without the workshop I would not have gained this overview or worked through so many exercises independently."

Default avatar picture of DevNinjas
Christine L.

"The seminar was superbly prepared, the group pleasantly small and the materials first-class. An excellent instructor who knows the subject inside out, takes time for the participants and answers questions in detail. The learning material alternated in a balanced way between theory and hands-on exercises that were timed excellently."

Default avatar picture of DevNinjas
Kevin H.
@Oest Holding GmbH

"All expectations met. Good technical expertise."

Default avatar picture of DevNinjas
Manuel Köhn
@Mercedes-Benz Tech Innovation

"Nico was very organized, technically excellent, and brought a great atmosphere from day one. He knows how to get people excited about the subject and conveys the knowledge very well. Questions were answered right away unless they would have given away later topics, and he then picked those up again at the right moment. All in all a very successful course and definitely a recommendation. Thank you, Nico, for the instructive and cool time."

Default avatar picture of DevNinjas
Pascal S.

"I really enjoyed the Docker & Kubernetes workshop at DevNinjas. Nico explained the complex topics around containers and orchestration in a very understandable and practical way. The mix of theory and hands-on exercises was perfect for being able to apply everything directly. I was able to take a lot away for my everyday work and now feel significantly more confident working with Docker and Kubernetes."

Default avatar picture of DevNinjas
Dominik Kneissl
@Siemens Healthineers

"Overall, I thought the training was very good. The instructor was technically very competent and gave plenty of input on every topic. On a personal level it was very pleasant too, which made it fun. The learning environment was absolutely exemplary in its setup and usability. I will definitely recommend the training and DevNinjas."

Default avatar picture of DevNinjas
Marius B.
@Dataport

"The trainer's materials were very well prepared, and the approach was clearly structured, moving from the easy to the more demanding blocks of content. Advanced Kubernetes fundamentals and the path to a solution were shown using practical examples, and questions were always resolved with an answer and a fitting real-world example. My expectations were met, and I can only recommend this seminar."

Default avatar picture of DevNinjas
Stefan J.
@BMI

"The "Docker & Kubernetes Bundle" training provided me with solid, practical knowledge for everyday work and enabled me to handle Docker and Kubernetes professionally. The excellently structured material offers real added value, even beyond the workshop. The combination of technical depth and interactive delivery by the trainer rounded off the whole experience. An experience that continues to help me even after the training."

Default avatar picture of DevNinjas
Swen Strangfeld
@Bundesdruckerei GmbH

"It was fun and I learned a lot that I can actually apply directly in my company. The trainer's approach was very hands-on, and he repeatedly brought in real-world examples."

Default avatar picture of DevNinjas
Felix R.
@Dirk Rossmann GmbH

"The workshop gave me a very good insight into Kubernetes and made working with containers much clearer. Nico delivered the content in a practical and well-structured way, so I could quickly find my way around. The hands-on exercises in particular helped me apply what I learned directly. For anyone looking for a solid introduction to Kubernetes, this workshop is definitely recommended."

Default avatar picture of DevNinjas
Daniel Hagen
@DKB Service GmbH

"The CKAD content is extensive, and the hands-on exercises are helpful and necessary to really learn it. This course struck a good balance between enough practice and sufficient depth. The understanding conveyed over the three days is definitely enough to work through the remaining CKAD topics on your own, because the concepts are taught clearly. The learning environment worked smoothly and reliably."

Default avatar picture of DevNinjas
Peter Menze

Continue Learning

Related Workshops for You

Foundation
Introduction to Kubernetes Workshop
Beginner

Introduction to Kubernetes

Learn to use Kubernetes confidently in three days. From Pods and Deployments to Storage and deployment strategies. You work hands-on in your own cloud environment with kubectl, K9s, and Helm.
3 Days€1,665.00
Extension
Kubernetes Monitoring with Prometheus, Grafana & Loki Workshop
Advanced

Kubernetes Monitoring with Prometheus, Grafana & Loki

After four days, you will operate a production-ready Kubernetes monitoring stack with Prometheus, Grafana, and Loki. From installation through PromQL and alerting to SLOs and performance tuning: everything hands-on with your own cluster.
4 Days€2,220.00
Tooling
Introduction to Kubernetes Helm Workshop
Intermediate

Introduction to Kubernetes Helm

Develop production-ready Helm charts in 3 days: From installation through OCI registry publishing to GitOps integration. You create custom charts, test with helm-unittest, and deploy multi-environment setups. All exercises run on dedicated Kubernetes clusters in the DevNinjas Dojo.
3 Days€1,665.00
Vincent Sturm - DevNinjas

Your Contact

Vincent Sturm

Key Account Manager

Looking for the right Kubernetes or DevOps training for your team? Vincent personally advises you on open workshops, certification prep and customized in-house training. He can also connect you with our consulting services. Get in touch with him directly.

vincent@devninjas.io
+49 221 9865099-4
WhatsApp Chat

Frequently asked questions

As a yardstick: you should know how a ClusterIP service distributes traffic inside the cluster and how Ingress handles external access, with NodePort for context. If you can confidently tell these three building blocks apart, you will quickly grasp where Istio fits in and what a service mesh adds on top.

Beyond that, you should be comfortable with kubectl and familiar with Pods, Services, Deployments and Namespaces. Programming skills are not required since all configurations are YAML-based.

If you still need the Kubernetes fundamentals, our Kubernetes Fundamentals Training provides the ideal preparation.

Three widely used service meshes take different approaches:

Istio uses Envoy as its proxy and offers the broadest feature set: fine-grained traffic management, mTLS, observability and since version 1.24 a production-ready ambient mode without sidecars. The trade-off is a steeper learning curve and higher resource requirements.

Linkerd relies on a lightweight Rust proxy with minimal overhead. Ideal for teams that want to get started quickly and don't need complex routing rules.

Cilium works with eBPF at the kernel level and achieves very low overhead, but requires eBPF compatibility and networking expertise.

We cover all three approaches on the first day so you can make an informed decision for your project.

Not every Kubernetes project needs a service mesh. If you run fewer than ten services and have no requirements for mTLS, traffic splitting or distributed tracing, native Kubernetes Services and Network Policies are often sufficient.

A service mesh pays off when you need encrypted service-to-service communication, want to implement canary deployments without custom infrastructure, or need visibility into latencies and error rates between services.

We address this decision on the first workshop day using concrete criteria, so you leave with a well-founded answer for your own project.

After three days you can:

  • Install and configure Istio (using istioctl or Helm)
  • Control traffic routing with VirtualService, DestinationRule and Gateway API
  • Set up mTLS and authorization policies for zero-trust security
  • Implement canary deployments and traffic mirroring for safe releases
  • Build observability with Prometheus, Grafana, Jaeger and Kiali
  • Troubleshoot with istioctl analyze and proxy debugging

Reality check: After three days you can set up and operate a mesh independently. For complex multi-cluster setups or Wasm extensions, further practice in your own projects is needed.

Around 80% of workshop time is hands-on practice, not lectures or slides. Every participant works on a dedicated multi-node cluster in our cloud environment (no Minikube, no shared lab). You install Istio yourself, configure routing rules, test security policies and debug misconfigurations.

No local setup required: open your browser, log in, start working.

In the classic sidecar mode, every pod gets its own Envoy proxy as an additional container. This provides full L7 control per workload but consumes about 60 MB of memory per sidecar according to Istio's official benchmark (at 1,000 requests per second; varies with configuration).

Ambient mode (GA since Istio 1.24) works without sidecars. Instead, a ztunnel per node handles L4 encryption while optional waypoint proxies provide L7 features like traffic routing. This reduces resource consumption and simplifies upgrades.

In the workshop you migrate an application between both modes and compare performance and resources directly.

Yes, the Linux Foundation offers the Istio Certified Associate (ICA). The exam costs USD 250 and tests practical skills in a real Istio environment.

Exam domains (2-hour exam, as of July 2026):

  • Installation, Upgrade and Configuration: 20%
  • Traffic Management: 35%
  • Securing Workloads: 25%
  • Troubleshooting: 20%

Our workshop covers all domains but is not a dedicated certification course. If your primary goal is the ICA exam, we recommend combining it with the official LFS245 preparation from the Linux Foundation. Our workshop provides the practical foundation on which you can build your exam preparation.

Our trainings usually take place from 9:00 to 16:00, both on-site and for public remote trainings.

For corporate trainings, other time models are flexible and can be worked out together.

We recommend a maximum of 8 participants per training to ensure individual attention for each participant. For corporate trainings, arrangements for larger groups are possible.

Yes, upon completion you will receive an official certificate of attendance from DevNinjas as PDF. This confirms your successful participation and the topics covered. The certificate is perfect for conversations with your employer and your personnel file.

Additionally, you will receive a verified digital badge that you can directly embed in your LinkedIn profile (section "Licenses & Certifications"). The badge follows the Open Badges 2.0 standard and is verifiable via QR code at any time. This way you showcase your qualification and position yourself with recruiters.

Workshop Dates

Workshop dates

Choose a suitable date and book directly online. All dates are guaranteed to run.

Guaranteed to runFew spots left

17. – 19. August 2026

09:00 - 16:00 (CET/CEST, German time)

Online🇩🇪German

1.665,00 €

per person · plus 19% VAT

Guaranteed to runPopular date

07. – 09. September 2026

09:00 - 16:00 (CET/CEST, German time)

Online🇩🇪German

1.665,00 €

per person · plus 19% VAT

Guaranteed to run

07. – 09. September 2026

09:00 - 16:00 (CET/CEST, German time)

Online🇬🇧English

1.665,00 €

per person · plus 19% VAT

Guaranteed to run

21. – 23. September 2026

09:00 - 16:00 (CET/CEST, German time)

Online🇩🇪German

1.665,00 €

per person · plus 19% VAT

Your booking benefits

  • Guaranteed to run

    Every training date takes place: no cancellation due to low participant numbers.

  • Invoice after the workshop

    No prepayment: pay conveniently by invoice afterwards.

  • 3=2

    3-for-2 promotion*

    Register three participants, pay for two: the third seat is free.

  • Price per participant

    Transparent fixed price per participant, plus VAT.

No hidden costs

Cloud lab (DevNinjas Dojo) and all training materials are included in the price.

  • Certificate & Open Badge

    Certificate of attendance plus a digital Open Badge for your LinkedIn profile included.

  • * Cannot be combined with other discounts.

    Tailor a workshop for your team?

    Custom content, flexible dates, from 1 participant.

    Request
    Book date
    Book date
    Book date
    Book date