Istio is a service mesh control plane that manages network traffic, security policies, and observability for Kubernetes microservices without modifying application code. It injects a sidecar proxy (Envoy) into every pod, intercepts all network traffic, and applies policies (routing, retries, circuit breaking, mTLS) transparently. Advanced configuration involves virtual services (traffic routing), destination rules (traffic policies), authorization policies (access control), and telemetry collection for distributed tracing and metrics.