# kumahq/kuma

🐻 The multi-zone service mesh for containers, Kubernetes and VMs. Built with Envoy. CNCF Sandbox Project.

Repository: https://github.com/kumahq/kuma
Canonical: https://ross.abutalabs.com/products/kuma
Homepage: https://kuma.io/install
Language: Go
License: Apache-2.0
License Family: permissive
Topics: service-mesh, golang, envoy, envoyproxy, kong, servicemesh, sidecar-proxy, cloud-native, kubernetes, kuma, control-plane, networking, connectivity, apis, microservices, cncf, controlplane, mesh
Last push: 2026-08-26T17:14:38+00:00

## Health v2 (maintenance only)
Score: 94/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 99, release rhythm 85, longevity 100
- inputs: {"age_days": 2730, "days_push": 7, "days_rel": 23, "gap_med": 0.0, "n_releases_24m": 117}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3995, forks 368 (observed 2026-08-28T04:08:31.881733+00:00)

## What it is
Kuma is a CNCF Sandbox, Envoy-based service mesh that provides L4-L7 connectivity, discovery, security (mTLS), observability, and traffic control across Kubernetes and VM workloads. It supports single- and multi-zone deployments across clouds with automatic policy propagation and multi-mesh multi-tenancy.

## Use cases
- secure microservices with mutual TLS across clusters
- run a service mesh spanning both Kubernetes and VMs
- manage traffic routing, retries, and circuit breaking between services
- observe service traffic with metrics, logs, and distributed tracing
- connect services across multiple zones, clusters, and clouds
- apply zero-trust security policies to east-west traffic
- expose services through built-in or delegated gateways

## When to choose
- you need a multi-zone or multi-cluster service mesh across Kubernetes and VMs
- you want Envoy-powered mesh features without requiring Envoy expertise
- you need multi-tenancy with multiple isolated meshes
- you want a CNCF-neutral project with broad policy support (mTLS, rate limiting, observability)

## When to avoid
- you run a single small Kubernetes cluster where native Kubernetes networking suffices
- you are already standardized on another service mesh like Istio or Linkerd
- you cannot operate sidecar proxies or a control plane
- you need a lightweight mesh for very simple, low-traffic deployments

## Facets
- artifact type: application
- maturity: stable
- function: networking, security, monitoring, api-gateway, service-discovery, cryptography, rate-limiting
- domain: microservices, cloud-computing, networking, security, infrastructure-as-code
- platform: self-hosted, cloud, go
- tags: service-mesh, envoy, sidecar-proxy, mtls, zero-trust, multi-zone, control-plane, cncf, traffic-management, observability, containers, devops, kubernetes, docker, linux

## Member repositories
- kumahq/kuma (main) score 94

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:31.881733+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:24:11.691370+00:00, confidence not recorded.
  - readme: https://github.com/kumahq/kuma (fetched 2026-08-28T04:08:31.881733+00:00, sha e53ad00f98aa)
  - homepage: https://kuma.io/install (fetched 2026-08-29T09:17:41.858990+00:00, sha deb6f2b84318)
  - site_page: https://kuma.io/features (fetched 2026-08-29T09:17:41.868484+00:00, sha 15a07e1f9bf9)
  - site_page: https://kuma.io/docs (fetched 2026-08-29T09:17:41.870412+00:00, sha 1d1febeeb88d)
  - site_page: https://kuma.io/docs/latest/introduction/install (fetched 2026-08-29T09:17:41.872445+00:00, sha 751bec952748)
  - site_page: https://kuma.io/docs/changelog (fetched 2026-08-29T09:17:41.874586+00:00, sha 3c530b423073)
  - site_page: https://kuma.io/docs/2.14.x/production/upgrades-tuning/upgrade-notes (fetched 2026-08-29T09:17:41.880486+00:00, sha b548bfe01215)
  - site_page: https://kuma.io/docs/2.14.x/quickstart/kubernetes-demo (fetched 2026-08-29T09:17:41.886223+00:00, sha 86f477ba37a3)
  - site_page: https://kuma.io/docs/2.14.x/quickstart/universal-docker-demo (fetched 2026-08-29T09:17:41.888197+00:00, sha 98a482db6e37)
- Data as of 2026-08-30T08:39:29.467469+00:00.
