distributedsystem/microservice platformengineering

What is the meaning

Core Idea

North-south traffic crosses the cluster boundary between users and services; east-west traffic stays inside between services, and the split drives different scaling and security decisions.

  • North-south: the ingress and egress path from outside the cluster.
  • East-west: service-to-service communication inside.
  • Why the distinction matters for architecture and operations.

North-South traffic

This is traffic crosses your system's outer boundary, between the outside world and your services. Think of it as the verticale axis: it flows down into youe cluster from users, partners or external systems and up back to them as responses.

Characteristics of north–south traffic:

  • Enters through an API gateway or load balancer, which handles TLS termination, authentication, rate limiting, and routing
  • Comes from untrusted sources — browsers, mobile apps, third-party webhooks
  • Typically uses standard HTTP/REST or gRPC over the public internet
  • Governed heavily: every request must be authenticated and authorized before being forwarded inward

A real example: a user’s browser sending GET /orders/123 → that hits your gateway → gateway verifies the JWT → routes to the Order service.

East-West traffic

This is traffic that stays entirely _inside_ your cluster — between services talking to each other. Think of it as the horizontal axis: it flows laterally across your mesh.

Characteristics of east–west traffic:

  • Never leaves the cluster; travels over internal private networks (or a service mesh like Istio / Linkerd)
  • Comes from trusted sources — services you own — but still needs authorization (zero-trust: never assume a caller is legitimate just because it’s internal)
  • Often uses faster protocols like gRPC, message queues, or event buses in addition to HTTP
  • Much higher in volume than north–south — one external request can fan out into dozens of internal calls
  • Secured via Mutual TLS (mTLS) in modern architectures, where each service proves its identity to the other

A real example: the Order service calling the User service to fetch the buyer’s email, then calling the Payment service to charge them — all of that is east–west.

Why the distinction matters

The two traffic types have different security surfaces, performance profiles, and governance needs, so treating them the same is a mistake.

North–SouthEast–West
OriginExternal / untrustedInternal / semi-trusted
Entry pointAPI gatewayService mesh / sidecar
VolumeLowerMuch higher
Security concernPerimeter defenceLateral movement (zero trust)
ProtocolsHTTPS, RESTgRPC, events, mTLS
ObservabilityRequest-level tracingInter-service latency, circuit breaking

In Cell-Based Architecture (CBA), north–south maps to traffic entering or leaving a cell through its gateway, while east–west maps to inter-cell or intra-cell service calls — which is exactly what makes the cell gateway so central: it is the checkpoint where external becomes internal.