All Products
Search
Document Center

Alibaba Cloud Service Mesh:Features

Last Updated:Mar 11, 2026

Service Mesh (ASM) is a fully managed, Istio-compatible service mesh available in two commercial editions: Enterprise Edition and Ultimate Edition. Each edition supports two data plane modes: sidecar mode and ambient mode.

Compare feature availability across editions and modes to determine which combination fits your workload.

Choose an edition

DimensionEnterprise EditionUltimate Edition
Target workloadProduction workloads up to 1,000 podsLarge-scale production workloads up to 10,000 pods
Control planeHosted Istiod (multiple replicas)Hosted Istiod (multiple replicas)
Cluster types (sidecar mode)ACK managed, dedicated, Serverless, Edge, ACS, and external Kubernetes clustersSame as Enterprise Edition
Cluster types (ambient mode)ACK managed clusters onlyACK managed clusters only
Multi-cluster (sidecar mode)Cross-VPC and cross-regionCross-VPC and cross-region
Multi-cluster (ambient mode)Single cluster onlySingle cluster only

Both editions support sidecar mode and ambient mode. Ambient mode has a narrower feature set. See the tables below for specifics.

The open source community version of Istio is included in the tables below as a baseline. It is suitable for development and testing only.

Features by category

Mesh management

Create, upgrade, and manage mesh instances and clusters through the ASM console or the KubeConfig file of a data plane cluster.

FeatureOSSEnterpriseUltimate
Console-based lifecycle management (deploy, upgrade)--Sidecar / AmbientSidecar / Ambient
ACK clusters (managed, dedicated, ECI on ACK)--Sidecar: all types / Ambient: managed onlySidecar: all types / Ambient: managed only
ACS clusters--Sidecar onlySidecar only
ACK Serverless clusters--Sidecar onlySidecar only
External Kubernetes clusters--Sidecar onlySidecar only
ACK Edge clusters--Sidecar onlySidecar only
Production-grade multi-cluster (cross-VPC, cross-region)--Sidecar onlySidecar only
Supported node operating systemsAlibaba Cloud Linux 2 onlyAlibaba Cloud Linux 2 and 3Alibaba Cloud Linux 2 and 3
Automatic mesh configuration diagnosisPartialSidecar / AmbientSidecar / Ambient
Istio resource version history--Sidecar / AmbientSidecar / Ambient
Access Istio resources via data plane KubeConfig--Sidecar / AmbientSidecar / Ambient

Data plane component management

Configure sidecar proxies and manage injectors at the global, namespace, or workload level.

FeatureOSSEnterpriseUltimate
Multi-level sidecar proxy configuration (global, namespace, workload)PartialSidecar onlySidecar only
Console-based sidecar injector management--Sidecar onlySidecar only
CNI mode compatibility in ACK clusters--Sidecar / AmbientSidecar / Ambient

Gateway management

Create and manage ASM ingress gateways with routing, security, and high availability.

FeatureOSSEnterpriseUltimate
Gateway lifecycle management (create, upgrade, delete, configure)--Sidecar / AmbientSidecar / Ambient
Console-based routing management--Sidecar / AmbientSidecar / Ambient
Advanced gateway features (graceful shutdown, HPA autoscaling, traffic-lossless upgrades, TLS optimization)--Sidecar / AmbientSidecar / Ambient
External authorization (ext_authz) with visual configuration--Sidecar / AmbientSidecar / Ambient
One-click OIDC-based single sign-on (SSO)--Sidecar / AmbientSidecar / Ambient
Throttling and circuit breaking--Sidecar onlySidecar only
Certificate management--Sidecar / AmbientSidecar / Ambient
Built-in observability--Sidecar / AmbientSidecar / Ambient
High availability (HA)--Sidecar / AmbientSidecar / Ambient

Traffic management

Control how traffic flows between services with routing rules, rate limiting, circuit breaking, and traffic labeling.

FeatureOSSEnterpriseUltimate
Istio VirtualService, DestinationRule, and Gateway compatibilityAllAllAll
Console-based traffic rule configuration--Sidecar / AmbientSidecar / Ambient
Local rate limitingPartial (sidecar)Sidecar onlySidecar only
Spring Cloud service management--Sidecar onlySidecar only
Lossless service startup and shutdown--Sidecar / AmbientSidecar / Ambient
Traffic lanes and traffic tags (TrafficLabel)--Sidecar onlySidecar only
Route-level circuit breaking--Sidecar onlySidecar only
Same-zone-prioritized routingAllAllAll
Service prefetchingAllAllAll
Service-centric traffic management--Sidecar onlySidecar only
Layer 7 load balancing for east-west gateways--Sidecar onlySidecar only

Observability

Monitor service health, visualize mesh topology, and integrate with Alibaba Cloud monitoring services.

FeatureOSSEnterpriseUltimate
Visual mesh topology and analysisPartialSidecar / AmbientSidecar / Ambient
Self-managed Prometheus integrationPartial (requires separate install)Sidecar / AmbientSidecar / Ambient
Application Real-Time Monitoring Service (ARMS) integration--Sidecar / AmbientSidecar / Ambient
Simple Log Service (SLS) integration--Sidecar / AmbientSidecar / Ambient
Custom monitoring metricsPartialSidecar / AmbientSidecar / Ambient
Enhanced dashboards and reports--Sidecar / AmbientSidecar / Ambient
Service-level objective (SLO) policies--Sidecar onlySidecar only
SLO-driven application elasticity--Sidecar onlySidecar only

Security

Enforce authentication, authorization, and audit policies with Resource Access Management (RAM), OIDC, Open Policy Agent (OPA), and dry-run testing.

FeatureOSSEnterpriseUltimate
RAM authorization--Sidecar / AmbientSidecar / Ambient
Console-based security policy configuration--Sidecar / AmbientSidecar / Ambient
OIDC-based SSO and JWT authentication--Sidecar / AmbientSidecar / Ambient
OPA fine-grained access control--Sidecar / AmbientSidecar / Ambient
Alibaba Cloud OpenAPI audit--Sidecar / AmbientSidecar / Ambient
Kubernetes API audit--Sidecar / AmbientSidecar / Ambient
Alibaba Cloud account authorization--Sidecar / AmbientSidecar / Ambient
Dry-run modeAllAllAll

Extensibility and ecosystem integration

Extend ASM with plugins, third-party registries, and integrations for CI/CD and infrastructure-as-code tools.

FeatureOSSEnterpriseUltimate
Plugin marketplace--Sidecar onlySidecar only
Multiple EnvoyFilter API versions--Sidecar onlySidecar only
Third-party registry integration--Sidecar onlySidecar only
KServe inference framework integration--Sidecar onlySidecar only
Argo CD, Argo Rollouts, and KubeVela best practices--Sidecar onlySidecar only
Terraform support--Sidecar / AmbientSidecar / Ambient

Performance optimization

Improve throughput with TLS acceleration, hardware-aware optimization, and resource tuning recommendations.

FeatureOSSEnterpriseUltimate
TLS acceleration with Multi-Buffer--Sidecar / AmbientSidecar / Ambient
Console-based selective service discovery--Sidecar / AmbientSidecar / Ambient
Automatic sidecar resource optimization based on access log analysis--Sidecar onlySidecar only
Hardware-software co-design with NFD (AVX instruction sets, QAT acceleration)--Sidecar / AmbientSidecar / Ambient
Best practices for service definitions and parameter tuning--Sidecar / AmbientSidecar / Ambient

Stability and scale

DimensionOSSEnterprise EditionUltimate Edition
Data plane scaleDevelopment and testing only1,000 pods10,000 pods
Hosted Istiod--Multiple replicasMultiple replicas

References

For step-by-step guides on commercial edition features, see the following topics:

Feature areaGuides
Mesh managementUse Multi-Buffer to accelerate TLS
Gateway managementAdd a certificate for a domain name
Enable compression for an ASM gateway
Enhance the high availability of an ASM gateway
Traffic managementConfigure local rate limiting for an ingress gateway
Use route-level circuit breaking
Prevent traffic loss with graceful shutdown
Use ASM gateway traffic routing
TrafficLabel overview
Manage Spring Cloud services
Implement an end-to-end canary release with TrafficLabel