distributedsystem/microservice platformengineering
Core Idea
North-south traffic crosses the cluster boundary between users and services; east-west traffic stays inside between services, and the split drives different scaling and security decisions.
- North-south: the ingress and egress path from outside the cluster.
- East-west: service-to-service communication inside.
- Why the distinction matters for architecture and operations.

North-South traffic
This is traffic crosses your system's outer boundary, between the outside world and your services. Think of it as the verticale axis: it flows down into youe cluster from users, partners or external systems and up back to them as responses.
Characteristics of north–south traffic:
- Enters through an API gateway or load balancer, which handles TLS termination, authentication, rate limiting, and routing
- Comes from untrusted sources — browsers, mobile apps, third-party webhooks
- Typically uses standard HTTP/REST or gRPC over the public internet
- Governed heavily: every request must be authenticated and authorized before being forwarded inward
A real example: a user’s browser sending GET /orders/123 → that hits your gateway → gateway verifies the JWT → routes to the Order service.
East-West traffic
This is traffic that stays entirely _inside_ your cluster — between services talking to each other. Think of it as the horizontal axis: it flows laterally across your mesh.
Characteristics of east–west traffic:
- Never leaves the cluster; travels over internal private networks (or a service mesh like Istio / Linkerd)
- Comes from trusted sources — services you own — but still needs authorization (zero-trust: never assume a caller is legitimate just because it’s internal)
- Often uses faster protocols like gRPC, message queues, or event buses in addition to HTTP
- Much higher in volume than north–south — one external request can fan out into dozens of internal calls
- Secured via Mutual TLS (mTLS) in modern architectures, where each service proves its identity to the other
A real example: the Order service calling the User service to fetch the buyer’s email, then calling the Payment service to charge them — all of that is east–west.
Why the distinction matters
The two traffic types have different security surfaces, performance profiles, and governance needs, so treating them the same is a mistake.
| North–South | East–West | |
|---|---|---|
| Origin | External / untrusted | Internal / semi-trusted |
| Entry point | API gateway | Service mesh / sidecar |
| Volume | Lower | Much higher |
| Security concern | Perimeter defence | Lateral movement (zero trust) |
| Protocols | HTTPS, REST | gRPC, events, mTLS |
| Observability | Request-level tracing | Inter-service latency, circuit breaking |
In Cell-Based Architecture (CBA), north–south maps to traffic entering or leaving a cell through its gateway, while east–west maps to inter-cell or intra-cell service calls — which is exactly what makes the cell gateway so central: it is the checkpoint where external becomes internal.