Announcing Built On Envoy: Making Envoy Extensions Accessible to Everyone

Learn more

Announcing Full Istio Ambient Mode Support for Tetrate Istio Subscription Plus

In January, we announced the general availability of Tetrate Istio Subscription Plus (TIS+) as a hosted Kubernetes network troubleshooting solution fo

Announcing%20Full%20Istio%20Ambient%20Mode%20Support%20for%20Tetrate%20Istio%20Subscription%20Plus

In January, we announced the general availability of Tetrate Istio Subscription Plus (TIS+) as a hosted Kubernetes network troubleshooting solution for Application Developers and Application Operations.

As a next step, Tetrate is excited to announce the same support for service mesh clusters that run Istio in ambient mode. With Istio 1.24 declaring GA support for Ambient mode, TIS+ will support all Observability that the Open-Source Istio in Ambient mode supports.

Taken together, TIS and TIS+ provide a comprehensive solution to support every stage of your Istio journey. From Istio break/fix support to troubleshooting the full TIS offering empowers organizations to confidently deploy, manage, and optimize Istio in any environment.

TIS+ is available standalone or as an add-on to your TIS package.

To see TIS+ in action, visit our website, get a demo, or read onwards!

Tetrate offers an enterprise-ready, 100% upstream distribution of Istio, Tetrate Istio Subscription (TIS). TIS is the easiest way to get started with Istio for production use cases. TIS+, a hosted Day 2 operations solution for Istio, adds a global service registry, unified Istio metrics dashboard, and self-service troubleshooting.

Learn more

Istio Ambient Mode

Istio ambient mode is now stable as of Istio 1.24. 

Istio’s ambient mode promises a reduced resource overhead in some use cases compared to the traditional sidecar deployment mode, which may result in lower costs and improved performance for some users by eliminating the need for a dedicated proxy container within each pod, while still providing service mesh capabilities like traffic management and security. 

Ambient mode treats Node level traffic (at Layer 4 – designated as zTunnel)  and Proxy level traffic (at Layer 7 – designated as Waypoints) as separate components, with the Waypoints associated only to a subset of services that specifically need Layer 7 capabilities support and thereby consuming fewer resources.

Most customers will be running a mesh with both the traditional, sidecar enabled Istio and ambient mode.

As of February 2025, TIS+ will support service discovery and observability of clusters running in Istio ambient mode. In this mode, TIS+ will:

  • Offer service discovery and service dependency visualization, and provide a full service topology, health, and inter-service communication view of the deployment
  • Collect aggregated metrics from the data path services
  • Support distributed call tracing in a way that is supported by the ambient mesh’s observability feature-set.

What’s Next

In this monthly blog series, we will continuously announce TIS+ features, capabilities, and news.

Stay tuned for the next blog that will cover:

  1. TIS+ support for virtual machines
  2. TIS+ support for sidecar-less services (eBPF mode)

Get Started

Here are some resources to help you get started:

Product background Product background for tablets
Building AI agents

Agent Router Enterprise provides managed LLM & MCP Gateways plus AI Guardrails in your dedicated instance. Graduate agents from prototype to production with consistent model access, governed tool use, and runtime supervision — built on Envoy AI Gateway by its creators.

  • LLM Gateway – Unified model catalog with automatic fallback across providers
  • MCP Gateway – Curated tool access with per-profile authentication and filtering
  • AI Guardrails – Enforce policies, prevent data loss, and supervise agent behavior
  • Learn more
    Replacing NGINX Ingress

    Tetrate Enterprise Gateway for Envoy (TEG) is the enterprise-ready replacement for NGINX Ingress Controller. Built on Envoy Gateway and the Kubernetes Gateway API, TEG delivers advanced traffic management, security, and observability without vendor lock-in.

  • 100% upstream Envoy Gateway – CVE-protected builds
  • Kubernetes Gateway API native – Modern, portable, and extensible ingress
  • Enterprise-grade support – 24/7 production support from Envoy experts
  • Learn more
    Decorative CTA background pattern background background
    Tetrate logo in the CTA section Tetrate logo in the CTA section for mobile

    Ready to enhance your
    network

    with more
    intelligence?