Flomesh Service Mesh (FSM) manages traffic and service governance for microservices running on Kubernetes. It uses the Flomesh Pipy proxy, injecting it as a sidecar into applications that are onboarded. Traffic tools include shifting, ingress and egress, and Kubernetes Gateway API capabilities. FSM handles HTTP, TCP, gRPC, and MQTT traffic. For service security, it supports mutual TLS and fine-grained access policies, with certificates managed through Tresor, cert-manager, or HashiCorp Vault. Prometheus and Grafana integrations are listed as stable, while Jaeger tracing is beta. Integration guides also cover Dapr and service discovery registries such as Consul, Eureka, and Nacos. FSM is open source and free, with self-hosted deployment. Its documentation lists x86 and ARM architectures and multi-cluster connectivity through the MCS API, though multicluster is marked alpha. Installation requires Kubernetes 1.19 or later; version 1.1 is listed for Kubernetes 1.19 through 1.24. The compatibility guide notes limits in Gateway API support, including no ReferenceGrant support.
Who it is for
FSM suits teams running Kubernetes microservices that need traffic controls, service-to-service security, or integrations with monitoring and discovery tools. It is relevant to self-hosted environments using Kubernetes or OpenShift.
What is good
- Free and open source
- Supports HTTP, TCP, gRPC, and MQTT
- Mutual TLS and fine-grained access policies
- Stable Prometheus and Grafana integrations
- Supports x86 and ARM architectures
What to know first
- Requires Kubernetes 1.19 or later
- Multicluster is marked alpha
- ReferenceGrant is not supported
- Init container runs as root and adds NET_ADMIN
Verdict
FSM combines traffic management, service security, and integrations for Kubernetes microservices in a free, self-hosted package. Check the Kubernetes version and Gateway API limitations, and account for the init container's root privileges and NET_ADMIN capability.
Flomesh Service Mesh plans and pricing
All plansCompared on service mesh platforms
- Deployment model
- self_hosted
- Proxy architecture
- sidecar
- mTLS support
- Yes
- Traffic policies
- Yes
- Multi-cluster support
- Yes
- Supported platforms
- Kubernetes, OpenShift




