View in browser
echo-newsletter-30

 eCHO news is your bi-weekly wrap up of all things eBPF and Cilium. If you want to keep up on the latest in cloud native networking, observability, and security this is your quelle

16th May 2023

 

It's my birthday today so I'm thinking about anniversaries and the start of new things. What surprises me the most about Cilium is that even as it closes in its 8th birthday, I'm most excited about all of the new things being born out of the project. Gateway API and Cilium Mesh both have the potentially to massively increase the scope and impact of Cilium by simplifying ingress and expanding Cilium's network beyond just Kubernetes.

 

When Cilium turns 9, we won't be thinking about Cilium in terms of just Kubernetes, just check out the new Nomad plugin as just one more example. The single plane of glass is very cliche in IT, but if everything on your network has a Cilium identity there is finally a way to provide networking, observability, and security in a consistent way anywhere you need to go. Enough about the future for now, I need to go catch some waves so let's 🐝 gin!

The Technical

eBPF programming on Windows

Not just a peak in the window, but a very deep dive

 

Netreap: A Practical Guide to Running Cilium in Nomad

Find out how Cosmonic runs Cilium on Nomad and they have even put the code up on Github

 

Cilium NetworkPolicy with AWS Security Group rules

"use toGroups rules in Cilium NetworkPolicy to control the traffic between the Kubernetes cluster and an EC2 VM"

 

Learning eBPF: Setting up the environment

Set up two VMs and run a few examples with bpftrace

 

Troubleshooting very slow Wordpress backend (100% CPU usage on uploads) with eBFP and Flamegraphs

Performance analysis in the wild

 

A gentle introduction to XDP

Write a basic program, attach, and remove it

 

Complexity of the BPF Verifier

Recently updated and still concluding "it seems clear that the BPF verifier is getting more complex"

 

google/buzzer

"An eBPF Fuzzer toolchain" read the launch blog here

 

facebookincubator/dns

DNS eBPF library from Meta

 

tw4452852/zbpf

"Write bpf in Zig"

🐝

 

The Ecosystem

Learning eBPF with Liz Rice

Tune into the Screaming in the Cloud podcast

 

How to implement eBPF based egress filtering

"we are just scratching the surface" stimmt

 

Isovalent’s Cilium Mesh bridges gap between Kubernetes and legacy workloads

Liz Rice is interviewed on the Cube

 

Isovalent Cilium Enterprise 1.13: SRv6 L3VPN, Overlapping CIDR Support in Meshed Clusters, FromFQDN Ingress in Network Policy, Hubble Plugin for Grafana and more!

The blog title is the description too :D or read on to find out what Phantom Services are 

 

Open-sourcing traffic mirroring (eBPF package) to the L3AF project

A new project out of Walmart Global Tech

 

Zero Trust Security Journey with Cilium and eBPF

Explained by a high flying analogy

 

Deepfence Introduces eBPFGuard into ThreatStryker

"It protects applications from exploitation by selectively blocking specific kernel function calls based on user-defined policies"

 

Cilium CNI Deep Dive en français

articles comprenant introduction à cilium, politiques réseaux, et usages avancés

 

eBPF : vers la fin des sidecars dans Kubernetes ?

"Enfin, nous conclurons en comparant ces deux approches et en répondant à cette question très controversée : eBPF va-t-il tuer les sidecars dans Kubernetes ?"

 

Starting Cilium

本書は、Kubernetes などの環境にデプロイされたアプリケーション間のネットワーク接続を管理するための OSS である Cilium について解説します。

 

Can eBPF Agent in Kubernetes Be the Key to Better Observability?

TNS covers the launch of Flora

 

How is eBPF disrupting CVE management?

eBPF is eating the CVE

 

What is eBPF and Why Should I Care?

"eBPF is real, and it's spectacular!" what a great reason 🤣

 

Getting Started with Cilium eBPF

A quick intro with links to get started

🐝

 

The How To

Tutorial: Cross-Namespace Routing with Cilium Gateway API

Stop Gateway Sprawl, "we will show how users can centralize their Gateway API management and leverage an elegant Gateway API feature that enables namespaces to access a shared Gateway"

🐝

 

The Events

Virtual Workshop: Golden Signals with Hubble & Grafana

May 16th online

 

Cilium Mesh Introduction & AMA

Join the webinar to hear about the latest Cilium feature launch on May 17th

 

Cilium Workshop with Isovalent & SFEIR - Paris

In person on May 23rd and a meetup

 

What is Cloud Networking & How does it relate to Cloud Native?

Join the GigaOm webinar on May 24th

 

Tietoevry: More than just a CNI

Online on May 25th

 

Cilium Workshop with Isovalent and Conoa - Stockholm

In person on May 25th

 

Isovalent Workshop Tour - Milano - SIGHUP

In person on May 29th

 

What's new in Cilium 1.13 and beyond!

Join the webinar on May 30th

 

Cilium Workshop with Isovalent and SuperOrbital - San Francisco

In person on May 30th

🐝

The Videos

eCHO Episode 89:

Stack Walking

eCHO Episode 89: Stack Walking

  

eCHO Episode 90:

K8ssandra and Cilium Cluster Mesh

eCHO Episode 90: K8ssandra and Cilium Cluster Mesh

Upcoming Stream

eCHO Episode 91: L2 load balancer & ARP announcements

Add to your calendar

The Tweet of the Week

Tweet: the only thing that can stop a bad guy with eBPF is a good guy with eBPF

As always, if you’ve seen a blog post, a tool, or anything else eBPF or Cilium related that you think the rest of the community should hear about, send them my way. You can either hit reply or join the #echo-news channel on Cilium Slack. You can also find all of the past episodes on the website.

🐝

To make sure you keep getting these emails, please add bill@isovalent.com to your address book or otherwise mark me as a permitted sender.

 

Know a friend that needs to be in the know? Forward this to them

Was this forwarded to you? Sign up today!

Written and sent by Bill Mulligan. Any feedback is welcome!

circle headshot

I work at Isovalent which is leading the eBPF-Powered Revolution in Cloud Native Networking, Observability, and Security with Cilium

isovalent
LinkedIn
Twitter

Isovalent, 20830 Stevens Creek Blvd. #1047, Cupertino, CA 95014, United States

Unsubscribe Manage preferences