How do I do that exactly? I need to install some iptables rules inside a pod to redirect pod traffic to envoy?
You're spot-on about using iptables rules. There is an example here with a yaml configuration and some iptables commands: https://github.com/envoyproxy/envoy/blob/main/configs/origin...
You might be able to re-use some of that. It should be pretty easy to get metrics for outbound/inbound http requests, but I don't remember the exact yaml incantation.
install istio, turn off mtls if you dont want that (https://istio.io/latest/docs/reference/config/security/peer_...) and you have what you’re looking for. doesn’t get simpler than that.
Also I'm worried about its pervasiveness. Is it possible to enable those side-cars only on selected pods?
It's not possible to disable mtls with meshed services, no configuration option for this particular feature.
There's no pervasiveness with linkerd, one need to add `linkerd.io/inject: enabled` annotation to the target service and restart deployment.