
In January 2025, we announced the general availability of Tetrate Istio Subscription Plus (TIS+) as a hosted Kubernetes network troubleshooting solution for Application Developers and Application Operations. In February 2025, we enhanced the TIS+ experience with the addition of workloads running on Istio clusters in ambient mode.
This month, we are excited to announce support for workloads that are not managed by Istio, but are running on Vanilla Kubernetes clusters. With TIS+, a single pane of glass and a common API platform for Observability and Monitoring is now available for all your microservices based containerized applications!
Troubleshooting and observability in hybrid Kubernetes environments (where some clusters run in eBPF mode and others are managed by Istio as part of a Service Mesh) can become fragmented if not managed under a unified management plane. With a normalized metrics and distributed tracing enabled platform, debugging and troubleshooting complexities are greatly reduced and thereby shortening the duration for issue isolation and issue resolution.
Taken together, TIS and TIS+ provide a comprehensive solution to support every stage of your Istio journey. From Istio break/fix support to troubleshooting the full TIS offering empowers organizations to confidently deploy, manage, and optimize Istio in any environment.
TIS+ is available standalone or as an add-on to your TIS package.
To see TIS+ in action, visit our website, get a demo, or read onwards!
Vanilla Kubernetes with eBPF
eBPF Kubernetes cluster management refers to leveraging eBPF (Extended Berkeley Packet Filter) to handle networking, security, observability, and performance monitoring within a Kubernetes environment. Unlike traditional Kubernetes cluster management, which relies on iptables, sidecars, and userspace proxies, eBPF operates directly in the Linux kernel, providing efficient, low-latency, and highly scalable management capabilities.
In a deployment with any cluster type (Istio with sidecars, Istio in ambient mode, and now with no Istio at all) or with a hybrid deployment with any combination of these variants, a common workload-agnostic Observability solution like TIS+ becomes key.
Starting March 2025, TIS+ will support – with a seamless and consistent user experience – full service discovery and observability of clusters running without Istio (or on Vanilla Kubernetes). In this mode, TIS+ will:
- Offer service discovery and service dependency visualization, and provide a full service topology, health, and inter-service communication view of the deployment
- Collect aggregated metrics from the data path services
- Support distributed call tracing for Services that are instrumented to export Trace spans in Zipkin or OpenTelemetry formats.

Figure 1: A single view with Ambient and Non-Istio enabled workloads

Figure 2: A Single Service Inventory from ambient and eBPF enabled clusters

Figure 3: Detailed metrics for a Service in an eBPF enabled cluster
What’s Next
In this monthly blog series, we will continuously announce TIS+ features, capabilities, and news.
Stay tuned for the upcoming blogs that will cover:
- TIS+ support for virtual machines
- Istio Config validation correctness checks
- New User Interface capabilities
- Cross-Cluster traffic configurations and visualization
Get Started
Here are some resources to help you get started:
- Free training. If you’re new to Istio, check out our free Istio training at Tetrate Academy, including Istio Fundamentals and our Istio 0-60 and Istio Wasm workshops ›
- Hardened Istio distribution. If you’re looking to take Istio for a test drive, install Tetrate Istio Distro, our open source, 100% upstream Istio builds with extended CVE patching and version support.
- CVE scanner. If you’re already running Istio, try our free CVE scanner ›
- Config verification Learn more about our Istio config verification tooling, Tetrate Configuration Analyzer: Istio Configuration Security: How to Avoid Misconfigurations ›
- Let’s talk. Schedule a call with an Istio expert to find out how TIS and TIS+ can help speed delivery, reduce risk, and streamline Istio operations ›
- TIS+ Documentation. Learn about TIS+ through our online documentation.
###
If you’re new to service mesh, Tetrate has a bunch of free online courses available at Tetrate Academy that will quickly get you up to speed with Istio and Envoy.
Are you using Kubernetes? Tetrate Enterprise Gateway for Envoy (TEG) is the easiest way to get started with Envoy Gateway for production use cases. Get the power of Envoy Proxy in an easy-to-consume package managed by the Kubernetes Gateway API. Learn more ›
Getting started with Istio? If you’re looking for the surest way to get to production with Istio, check out Tetrate Istio Subscription. Tetrate Istio Subscription has everything you need to run Istio and Envoy in highly regulated and mission-critical production environments. It includes Tetrate Istio Distro, a 100% upstream distribution of Istio and Envoy that is FIPS-verified and FedRAMP ready. For teams requiring open source Istio and Envoy without proprietary vendor dependencies, Tetrate offers the ONLY 100% upstream Istio enterprise support offering.
Need global visibility for Istio? TIS+ is a hosted Day 2 operations solution for Istio designed to simplify and enhance the workflows of platform and support teams. Key features include: a global service dashboard, multi-cluster visibility, service topology visualization, and workspace-based access control.
Get a Demo