
- Sidecars and the Sidecar CRD: default behavior and scoped configurations
- VirtualServices: routing rules, traffic splitting, retries, timeouts, and fault injection
- DestinationRules: subsets, load balancing, connection pools, circuit breaking, and outlier detection
- Gateways: exposing services via Ingress and managing outbound Egress traffic

| Topic | Purpose | Exam relevance |
|---|---|---|
| VirtualService | Configure request routing, retries, fault injection, mirroring, traffic splitting | High (30–35% of ICA) |
| DestinationRule | Define subsets, LB settings, connection pools, circuit breaking | High |
| Gateway (Ingress/Egress) | Expose services externally; manage outbound traffic | High |
| ServiceEntry | Bring external services into the mesh | Medium |
| Fault injection, retries, timeouts | Test and increase resilience | High |
| Ambient mode (ztunnel/waypoint) | Alternate model for L4/L7 traffic handling | Low (overview only) |
This lesson targets the Istio resources and behaviors you need for the ICA certification: VirtualServices, DestinationRules, Gateways, ServiceEntry, fault injection, retries/timeouts, and circuit breaking. Ambient mode and advanced HTTPRoute/EnvoyFilter details are out‑of‑scope for the exam and will be covered only at a high level.