CONTAINERS / A CONCEPT NOTE

Sidecar Pattern

attaching helper containers to your pod without modifying app code

~75 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

A sidecar is an additional container running in the same pod as your main application container. They share the same network namespace and volume mounts. Common use cases: logging agents (Fluentd), service mesh proxies (Envoy), secret reloaders, and metrics exporters. The app stays blissfully unaware of the sidecar.

02 / FOLLOW THE MECHANISM

How a sidecar operates

  1. Pod startup

    Kubernetes starts both the main app container and the sidecar container simultaneously.

  2. Shared network

    both containers share the same IP and localhost — the sidecar can intercept or observe traffic.

  3. Shared volume

    the sidecar mounts the same emptyDir volume as the app to read/write logs or config files.

  4. Sidecar job

    the sidecar tails log files and ships them to stdout or an external aggregator (CloudWatch, Loki).

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

view logs of just the sidecar container

kubectl logs deployment/my-app -c sidecar-proxy

EXAMPLE 02 · REFERENCE

exec into the sidecar

kubectl exec deployment/my-app -c sidecar-proxy -- ls /var/log

Explore command anatomy in the CLI lab