Case study

Building a microservices security platform for a disruptive startup

About the client

Mesh7, a startup originating from Silicon Valley, emerged with a vision led by experienced professionals from the IT industry and received substantial support from venture capital funds. Mesh7 specialized in delivering the Cloud Native API Security Mesh solution, a cutting-edge approach to safeguarding contemporary applications designed for the DevSecOps framework. Recently, VMware recognized its potential and acquired the company.

mesh7

Client’s testimonial

Thanks to its expertise in networking technologies and Kubernetes, CodiLime has become our reliable technical partner helping us deliver the first-in-class product for monitoring security in microservices. CodiLime’s experienced project managers and engineers played an important role in releasing the final product and thus keeping promises given to clients and investors.

Mesh7

Amit Jain - Co-founder & CTO

Mesh7

Challenge

As an application’s complexity grows exponentially (resulting from interconnected ephemeral, heterogeneous, and distributed workloads), so too do concerns about the security of such applications. Using cloud and third-party services, and exchanging sensitive information at Layer 7 over a network, had created dangerous blind spots:

Lack of real-time visibility of the interactions between various workloads, cloud, and third-party services

Lack of control over the flow of sensitive data, both internally and externally

Impossible to detect anomalous behavior and unsanctioned changes in applications

No real-time detection of lateral threats and vulnerabilities at run time.

Mesh7 decided to tackle these challenges by creating a complex platform to monitor communication between different workloads and apply automated security rules. The platform works on top of the customer’s infrastructure and ensures that no potential threat remains undetected.
CodiLime was chosen as an external technology partner to help Mesh7 build the product and keep the promises it has made to its clients and investors. Together we have succeeded in creating a product we believe will become the first-in-class solution for ensuring the security of microservices.

Solution

Thanks to the SaaS model installation, it takes mere minutes to onboard a customer. The product can be used in any type of workload, cloud or environment. The modern user interface clearly visualizes all the necessary information.

Short summary of the project:

Created DDOS protection mechanism

Created a plethora of plugins for the observability ecosystem (service mesh, Istio)

Created performance measurement toolki8

Delivered policies generation mechanisms (api discovery, api validation, service discovery) utilizing Envoy Proxy as insertion point

Developed data enrichment mechanisms and plugins for Envoy

Golang control plane utilizing K8s operator

Get your project estimate

For businesses that need support in their software or network engineering projects, please fill in the form and we’ll get back to you within one business day.

For businesses that need support in their software or network engineering projects, please fill in the form and we’ll get back to you within one business day.

We guarantee 100% privacy.

Trusted by leaders:

Cisco Systems
Palo Alto Services
Equinix
Jupiter Networks
Nutanix