No items found.

Gloo Mesh 2.10: More Secure, Scalable Cloud Connectivity

Gloo Mesh 2.10 adds flat network support, traffic shifting, and policy enforcement for secure, scalable multi-cluster service mesh.

Earlier this year, Gloo Mesh 2.8 and 2.9 delivered major advancements to multi-cluster service mesh. They introduced automated peering to remove manual configuration, enhanced waypoint insights to simplify troubleshooting, and a new Global Services view for unified observability. These releases streamlined operations, strengthened visibility, and made it easier for teams to scale and manage connectivity across large, distributed environments.

With Gloo Mesh 2.10, we expanded multi-cluster capabilities even further. This release introduced flat network support in Ambient, enabling pod-to-pod traffic policies and direct cross-cluster communication without the need for a gateway. Built on the existing peering model, this approach delivers both speed and scalability at massive scale. We also added weighted locality support in Ambient, allowing teams to shift traffic gradually from one cluster to another for safer rollouts. In addition, Gloo Mesh Virtual Destinations now support OPA-based policy enforcement and JWT server-side policies, giving organizations more control and flexibility in securing service-to-service traffic.

What’s New in Gloo Mesh 2.10

Gloo Mesh 2.10 builds directly on previous releases, introducing new features that address long-standing customer challenges around security, scale, and flexibility, especially in Ambient Mesh (sidecarless) environments:

  • Flat network support in Ambient Mesh multi-cluster, enforcing pod-to-pod traffic policies that traverse directly - without requiring a gateway - by leveraging a high-performance peering model proven to support up to 100 million pods.
  • Ambient Mesh now includes weighted locality support, enabling gradual traffic shifting between clusters. This feature offers enhanced control multi cluster traffic, for instance, by allowing traffic to be drained from a cluster for maintenance.
  • Gloo Mesh virtual destination that now supports OPA (Open Policy Agent) and JWT (JSON Web Token) policies directly attached to the server side. This enhancement allows security policies to be applied at the workload level, significantly improving overall security.

These improvements bring even greater control, performance, and manageability for enterprise teams rolling out mesh at scale.

Flat Network Support in Ambient Mesh (Multi-cluster)

Gloo Mesh 2.10 introduces native flat network support for Ambient Mesh. This new feature eliminates the need for gateways in multi-cluster traffic for organizations utilizing a flat network between their clusters, where direct pod reachability is established.

What it does:

  • Enables direct pod-to-pod traffic across clusters without gateways
  • Uses a high-performance peering model proven to scale up to 100 million pods
  • Enforces L4 and L7 traffic policies even across distributed environments

This model significantly reduces operational overhead, improves performance, and provides stronger policy enforcement at scale.

Weighted Locality-based Traffic Shifting

Gradually shifting traffic between clusters such as in blue/green deployments or regional failover has long been a challenge for multi-cluster mesh setups. This release introduces weighted locality support for Ambient Mesh.

What it does:

  • Routes traffic based on cluster proximity and weight
  • Supports progressive traffic migration (e.g. 10% to cluster B, 90% to cluster A)
  • Simplifies multi-region failover and controlled rollouts

The result is smoother migrations, safer upgrades, and more predictable performance across regions.

Virtual Destinations with Policy Enforcement (OPA + JWT)

Controlling who can access what - and enforcing policy server-side - has historically required complex manual configuration. We’ve now enhanced virtual destinations with support for:

  • Open Policy Agent (OPA) policies
  • JWT token validation attached to the server-side destination

This allows platform teams to define fine-grained access control directly on the service, without requiring app changes or client-side logic.

The benefits of this include:

  • Centralized policy management
  • Cleaner separation of responsibilities between application teams and platform teams
  • Simplified compliance and audit readiness

Try Gloo Mesh 2.10

For additional detailed features, examples, and upgrade info, visit the Gloo Mesh release notes. You can also learn more with our free, hands-on Gloo Mesh labs

Curious about Ambient Mesh? Check out free tools like the cost savings estimator and sidecar migration assistant at ambientmesh.io.

What’s Next

We’re very excited looking ahead to the next Gloo Mesh 2.11 release! This next release will mark a significant milestone, tackling one of the biggest challenges of companies at scale, multi-tenancy, and how to create global services available company-wide. Stay tuned for more.

Cloud connectivity done right