Home / Companies / Kong / Blog / Post Details
Content Deep Dive

Behind the Scenes: Mesh Manager Architecture

Blog post from Kong

Post Details
Company
Date Published
Author
Danny Freese
Word Count
1,474
Company Posts That Month
8
Language
English
Hacker News Points
-
Post removed?
No
Summary

In September 2023, Kong officially integrated Mesh Manager into its SaaS platform, Kong Konnect, providing a streamlined and centralized hub for managing Kong Mesh control planes. Originally stemming from the CNCF project Kuma, Kong Mesh faced three primary challenges during its integration: offering an easy abstraction for Konnect engineering teams, ensuring seamless multi-tenancy, and addressing zone connectivity. To achieve this, Kong introduced two services: Kong Mesh deployed as a global control plane in universal mode with PostgreSQL, and the mesh virtual control plane manager (vcp-manager), which serves as an API entry point for managing virtual global control planes and provisioning zones. This architecture not only reduces overhead but also enhances multi-tenancy by leveraging Row Level Security to restrict access. The integration involved adapting the zone-to-global control plane connectivity model to work with Kong Konnect’s authentication system, using System Account Access Tokens instead of JSON Web Tokens. This approach effectively reduced costs, enhanced operational efficiency, and provided a secure, multi-tenant solution while remaining compatible with existing platform services like authentication and authorization. The successful integration reflects the collaborative efforts of Kong’s engineering team, and users are encouraged to try Mesh Manager for free via Kong Konnect, with feedback for future enhancements being warmly invited.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 1 2,064 217 83 +11%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.