It looks like this might be the issue: Established TCP connections were destroyed when Envoy receives configuration from Pilot
I’m consistently seeing xDS updates being pushed the app just a second before the connections terminate.
The issue that @zhaohuabing reported seems to have been a consul thing.
According to the comment on the issue, it seems that the termination of downstream connections is to be expected.
I don’t what could be causing the xDS updates, tho. We don’t use consul.