What architectural differences distinguish premier service mesh platforms when managing fine-grained traffic routing and secure service-to-service communication? Furthermore, why is decoupling sidecar proxy networking from application logic the absolute best approach to zero-trust microservice security?