View in browser
echo-newsletter-25

 eCHO news in your bi-weekly wrap up of all things eBPF and Cilium. If you want to keep up on the latest in cloud native networking, observability, and security this is your quelle

21st February 2023

 
Lots of news this week, but the biggest one is that Cilium 1.13 is out now! There is a lot in it, but some of the highlights are:
  • Service Mesh and Ingress: Production-ready Gateway API implementation: HTTP Routing, TLS Termination, HTTP Traffic Splitting/weighting, HTTP Header Modification, L7 load-balancing, and sharing Kubernetes LoadBalancer Resources
  • BIG TCP and veth replacement: Have larger packages to ease load on CPU and interfaces and a replacement for veth devices to reduce latency and increase performance
  • IPAM for LoadBalancer Services and BGP Services Advertisement: Have a native, elegant way to allocate IPs to LB services
  • NAT46/64: IPv6-only Kubernetes clusters can access IPv4-only systems (with NAT64) or can be reachable from IPv4-only clients (with NAT46)
  • Introductory support for SCTP on Kubernetes: Cilium 1.13 provides basic SCTP support
  •  mTLS datapath:  mTLS support on the datapath level
Isovalent has a full write up of all the features so check that out before reading the rest of the news. Now let's 🐝 gin!

The Technical

Packet, packet, who’s got the packet?

pwru solving packet problems in the wild

 

BIG Performances with BIG TCP on Cilium

Learn how BIG TCP led to a 42% increase in transactions per seconds, 2.2x lower p99 latency, and a 15% increase in throughput

 

Kubernetes eBPF Traffic Analysis With Kubeshark

"Kubeshark lets you perform L4/L7 traffic analysis for a variety of protocols" and this video analyzes how

 

Seven Core Issues about eBPF

An introduction to eBPF and how it works from Alibaba

 

How debugging Go programs with Delve and eBPF is faster

Learn how eBPF is faster than ptrace for tracing

 

eunomia-bpf/wasm-bpf

"WebAssembly eBPF library, toolchain and runtime"

 

eunomia-bpf/GPTtrace

"Generate eBPF programs and tracing with ChatGPT and natural language" who needs kernel devs anyways? 🤣

🐝

 

The Ecosystem

Cilium 1.13 – Gateway API, mTLS datapath, Service Mesh, BIG TCP, SBOM, SNI NetworkPolicy

Cilium 1.13 is out and packed with new features, dive into them and get hands on with labs

 

Netzwerkverkehr: Cilium 1.13 leitet Übergang von der Ingress zur Gateway API ein

Coverage of the release auf Deutsch from Heise

 

ebpf.io homepage

More of an update than news, but ebpf.io has a new simplified look and you should check it out!

 

What is eBPF? Brightboard Lesson

For anyone that likes whiteboard markers and see through screens

 

Is eBPF The End Of Kubernetes Sidecar Containers?

Viktor Farcic makes a foray into the debate with his latest video

 

What Kubernetes CNI to use with F5 BIG-IP

The video summarized: Cilium

 

Eine Einführung in API-Gateways und die Cilium Implementation der Kubernetes Gateway-API

Learn about Cilium and Gateway API in German

 

Cloud Native Networking Using eBPF

A quick intro to CNIs and where Cilium fits in

 

eBPF and Cilium article series from Neel Shah

Including getting started, features, and with Kubernetes

 

What is eBPF?

A quick intro from Deepesha Burse

 

Four Cilium trends to watch in 2023

#5 will really surprise you

 

Introducing Oligo: Leading Application Security to Runtime

Another security startup based on eBPF launches

 

How AWS uses eBPF to identify security risks

More security products jumping on the eBPF bandwagon

 

Cilium Wars: Scaling Up Your Network with Jedi-like Cilium Handling Techniques

Very quick introduction to Cilium mind tricks

 

Ingress Node Firewall Operator

"A combination of XDP+eBPF provides a flexible, high performance mechanism to allow early detection and packet filtering"

 

CloudNativeSecurityCon 2023: Identifying Suspicious Behaviors with eBPF

Short coverage of eBPF at SecurityCon

 

Cilium Registers Massive Growth In Contribution And Adoption In 2022

TFIR covers the Cilium annual report

🐝

 

The How To

Tracing the Linux kernel using Exein Pulsar: a 5 Minute Tutorial

Learn how to install Pulsar and uses eBPF to trace events in the kernel space

 

Azure CNI Powered by Cilium

Learn how to run Cilium on AKS

🐝

 

The Events

Découverte de Cilium et intégration dans AKS

Intro to Cilium on February 28th in Lyon

 

Virtual Cilium Security Workshop

Tetragon, Zero Trust and visibility webinar on March 1st

 

Kubernetes Community Days France 2023

Catch a few talks about Cilium in Centre Pompidou on March 7th

 

Isovalent Workshop Tour

In-person Cilium training coming to a European city near you March 8th-June 7th

 

CiliumCon

The first ever CiliumCon is happening on April 18th at KubeCon + CloudNativeCon

🐝

The Videos

eCHO Episode 79: Transparent Encryption with IPsec and WireGuard

eCHO Episode 79: Transparent Encryption with IPsec and WireGuard

  

eCHO Episode 80: 

Kepler

 

eCHO Episode 80: Kepler

Upcoming Stream

eCHO Episode 81: Windows XDP

Add to your calendar

The Tweet of the Week

tweet: Spotted in the wild:  @ParcaDev  server debugging  @ciliumproject .  One #eBPF project debugging the other. 🤝

As always, if you’ve seen a blog post, a tool, or anything else eBPF or Cilium related that you think the rest of the community should hear about, send them my way. You can either hit reply or join the #echo-news channel on Cilium Slack. You can also find all of the past episodes on the website.

🐝

To make sure you keep getting these emails, please add bill@isovalent.com to your address book or otherwise mark me as a permitted sender.

 

Know a friend that needs to be in the know? Forward this to them

Was this forwarded to you? Sign up today!

Written and sent by Bill Mulligan. Any feedback is welcome!

Bill Mulligan

I work at Isovalent which is leading the eBPF-Powered Revolution in Cloud Native Networking, Observability, and Security with Cilium

isovalent
LinkedIn
Twitter

Isovalent, 20830 Stevens Creek Blvd. #1047, Cupertino, CA 95014, United States

Unsubscribe Manage preferences