Why a Service Mesh Beats Application Gateway for Pod-Level Canary Control
You are designing a release pipeline for a critical application that requires zero-downtime deployments. The application runs on Azure Kubernetes Service (AKS) with multiple replicas. You are using Azure Pipelines with a canary deployment strategy. What is the best approach to gradually shift traffic to the new version while monitoring for errors?
Quick Answer
A service mesh like Istio is the right tool for gradual, monitored traffic shifting on AKS — it splits traffic at the pod level with fine-grained percentage control. Application Gateway only routes at the ingress layer without that granularity, a plain rolling update replaces pods without splitting traffic at all, and a VIP swap shifts everything at once, which is blue-green, not canary.
⚠ Common exam trap
AZ-400 often tests the distinction between canary and blue/green or rolling deployments, tricking candidates into selecting ingress-level or Kubernetes-native strategies that lack the granular traffic-percentage control and observability a service mesh provides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a service mesh like Istio to route a percentage of traffic to the new version.
A service mesh like Istio provides fine-grained traffic splitting at the network layer, allowing a precise percentage of traffic (e.g., 5%, then 10%, then 50%) to be routed to the canary version while the rest goes to the stable version. Istio's telemetry (via Envoy sidecars) enables real-time error-rate and latency monitoring, so you can automatically or manually roll back if anomalies appear. This is the most controlled, observable approach for canary deployments on AKS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use a service mesh like Istio to route a percentage of traffic to the new version.
Why this is correct
Istio's traffic-splitting rules operate at the ingress and sidecar layer, letting you weight traffic by percentage independently of pod replica counts. That satisfies the gradual, monitored shift the canary strategy demands, since rollback is a routing change rather than a redeployment.
- ✗
Use Azure Application Gateway as an ingress controller with weighted backend pools.
Why it's wrong here
Application Gateway weighted backend pools route at layer 7 to VM or IP backends, not to individual Kubernetes pods, so it cannot split traffic between canary and stable pod revisions. It suits ingress with weighted routing across services. Canary at pod granularity requires a service mesh or ingress controller that understands Kubernetes endpoints.
- ✗
Use the AKS rolling update strategy with max surge.
Why it's wrong here
A rolling update replaces pods in place with no traffic-splitting control, so it cannot gradually shift a percentage of traffic while monitoring errors; it simply maintains availability during replacement. Rolling updates with max surge are correct for standard zero-downtime releases, not canary analysis.
- ✗
Deploy to a staging environment, then swap VIPs with production.
Why it's wrong here
Swapping VIPs is an all-or-nothing cutover, sending 100% of traffic to staging instantly with no gradual percentage shift or error monitoring. Blue-green deployments use this pattern for instant rollback. Canary requires incremental traffic weighting between versions, which VIP swapping cannot provide.
Go deeper
Related to this question
Learn chapter
Designing a Release Pipeline
Key term
Release pipeline
A Release pipeline is an automated sequence of steps that takes software from code commit to production deployment, ensuring quality and consistency.
Key term
Anthos
Anthos is a Google Cloud platform that lets you run applications consistently across different computing environments, like on-premises data centers and multiple public clouds.
About these practice questions
Courseiva writes every AZ-400 question from scratch — 696 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on AZ-400
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses GitHub Actions for CI/CD. You need to implement a deployment strategy where a new version of the application is gradually shifted from the stable environment to a canary environment, and if health checks pass, the traffic is fully shifted to the canary. Which GitHub Actions deployment strategy should you use?
hard- A.Recreate deployment
- ✓ B.Canary deployment
- C.Blue-green deployment
- D.Rolling deployment
Why B: A canary deployment gradually shifts traffic from the stable environment to a new canary environment, using health checks to validate the new version before fully routing all traffic to it. This matches the requirement of a gradual shift with health-check gating. GitHub Actions supports this via deployment strategies like `canary` in environments or custom workflows with traffic-splitting tools.
Variation 2. A company uses Azure Pipelines to deploy microservices to Azure Kubernetes Service (AKS). They want to implement a canary deployment strategy. What should they use?
medium- ✓ A.Use Kubernetes native deployment strategies with multiple replica sets and traffic splitting
- B.Use Azure Front Door to route traffic between clusters
- C.Use deployment slots in Azure App Service
- D.Use Azure Container Instances as a staging environment
Why A: Kubernetes natively supports canary deployments by running multiple replica sets of the same application and using a service mesh or ingress controller (e.g., Istio, NGINX Ingress) to split traffic between the stable and canary versions. Azure Pipelines can orchestrate this by updating the canary deployment and adjusting traffic weights gradually, enabling controlled rollouts and rollbacks without external routing services.
Variation 3. Which THREE components are essential for implementing a canary deployment strategy using Azure Kubernetes Service (AKS) and Azure Pipelines? (Choose three.)
medium- A.Azure Traffic Manager for global load balancing.
- ✓ B.A service mesh like Istio or Linkerd for traffic splitting.
- ✓ C.A health check endpoint to validate the canary deployment.
- D.Multiple Kubernetes namespaces to separate canary and stable deployments.
- E.Azure Front Door for routing traffic to the canary.
Why B: Option B is correct because a service mesh such as Istio or Linkerd provides the fine-grained traffic-splitting capability (e.g., Istio VirtualService weights or Linkerd TrafficSplit) needed to route a controlled percentage of requests to the canary while the rest go to the stable version. Option C is correct because a health check endpoint (readiness/liveness probe or a dedicated /health route) is essential to validate that the canary is behaving correctly before progressively increasing its traffic share or promoting it. Options A and E are not essential: Azure Traffic Manager and Azure Front Door operate at DNS/global HTTP layers and cannot perform the pod-level, percentage-based traffic splitting that a canary strategy inside AKS requires. Option D is not essential because canary and stable workloads can coexist in the same namespace and be distinguished by labels/selectors; separate namespaces are an organizational choice, not a requirement for canary deployment.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.