Service meshes facilitate service-to-service communication and enforce security policies in microservice architectures. However, they often depend on per-pod sidecar proxies, which introduce significant latency and resource overhead due to redundant application-layer parsing on every request. Eliminating sidecars without compromising security guarantees remains a central challenge. To address this

Topological visualization of Meshlib: In-Process Policy Enforcement for Sidecar-less Service Meshes
Brave API

Meshlib is a sidecar-less service mesh extension built on Cilium that eliminates the latency and resource overhead of traditional per-pod sidecar proxies by performing Layer-7 policy enforcement in-process within the application.

It achieves this through a hybrid architecture: In-Process Enforcement: An optional application-bound library reuses the protocol parsing already performed by the application framework, avoiding the redundant marshal-inspect-unmarshal cycle of external proxies. eBPF Data Plane: Transport-level identity and routing are delegated to Cilium’s eBPF-based data plane, allowing unmodified services to fall back transparently to standard proxy-based enforcement. Performance Gains: Benchmarks using the TrainTicket application show Meshlib achieves the lowest end-to-end latency compared to Istio, Linkerd, and unmodified Cilium, with comparable resource overhead. Incremental Adoption: A lightweight bidirectional gRPC protocol coordinates policy state, ensuring security guarantees are preserved during updates and allowing gradual deployment without disrupting existing infrastructure.

Generated Aug 28, 2026
Open-Weights Reasoning

Meshlib: In-Process Policy Enforcement for Sidecar-less Service Meshes addresses a core performance problem in microservice security: traditional service meshes rely on per-pod sidecar proxies that intercept, parse, and enforce policy for every request. This design provides strong service-to-service security and observability, but it also introduces substantial overhead, because each request must traverse an additional network path and undergo application-layer processing in a separate process. The paper argues that eliminating sidecars is not merely a deployment optimization, but a way to reduce latency, CPU and memory consumption, and architectural complexity while still preserving mesh-level security guarantees.

The central contribution is an in-process enforcement model in which policy evaluation is moved from an external sidecar into the application’s own runtime. Instead of proxying traffic through a co-located network sidecar, Meshlib embeds enforcement logic close to the workload, allowing the application to apply mesh policies directly during request handling. This approach aims to retain the essential functions of a service mesh—such as policy enforcement, service identity, and controlled communication—while avoiding redundant parsing and inter-process hops. The work therefore positions itself at the intersection of service mesh design, zero-trust networking, and lightweight in-process middleware.

The material matters because sidecar-less or “ambient” service meshes are an important direction for high-performance microservice platforms, but they raise a difficult question: how can security enforcement be simplified without weakening the trust model? By moving enforcement into the process, Meshlib offers a potential path to lower-overhead mesh deployment, tighter integration with application workloads, and better performance for latency-sensitive services. At the same time, it highlights the tradeoffs involved in this approach, including the need for careful policy management, secure runtime integration, and compatibility across heterogeneous service implementations.

Generated Aug 28, 2026
Sources