View in browser
echo-newsletter-35

 eCHO news is your bi-weekly wrap up of all things eBPF and Cilium. If you want to keep up on the latest in cloud native networking, observability, and security this is your quelle

25th July 2023

 

Cilium 1.14 will be dropping very shortly and while there is a whole laundry list of features you will want to catch up on in the release blog post, probably the most exciting one for many people is next generation mutual authentication. It represents the evolution beyond mTLS towards and architecture that separates authentication and encryption. Check out the full blog if you want to find out why you would benefit from doing that. But with 1.14 it is no longer just words on a page, it's a feature you can try out.

 

If you want to see mutual authentication in action, be sure to check out the eCHO stream on Friday or the hands on lab that just got released. I need some time to try it out myself so let's 🐝 gin!

The Technical

Securing Constellation’s Kubernetes data in transit - network encryption with Cilium

"Our CNI solution of choice is Cilium. It combines great performance with transparent network encryption"

 

Catch Performance Regressions: Benchmark eBPF Program

Learn to benchmark both eBPF and userspace applications

 

Detecting BPFDoor Backdoor Variants Abusing BPF Filters

"Because BPFDoor needs root privileges to work, the reverse shell it opens is also privileged" moral of the story don't let hackers get privilege

 

NatiSand: Native Code Sandboxing for JavaScript Runtimes

"leverages Landlock, eBPF, and Seccomp to control the filesystem, Inter-Process Communication (IPC), and network resources available to binary programs and shared libraries" also on Github

 

grafana/ebpf-autoinstrument

"eBPF-based autoinstrumentation of HTTP and HTTPS services"

 

littlejo/cilium-eks-cookbook

"Multiple ways to install cilium in eks"

 

seifrajhi/awesome-cilium

"A curated list of awesome projects related to cilium"

🐝

 

The Ecosystem

Unleashing the Power of Cilium CNI to Propel Trendyol’s Performance Up to 40%!

"Cilium has proven to be a changer for Trendyol’s Kubernetes clusters. With its advanced capabilities in networking, observability, and security, Cilium has met our expectations, outperforming previous CNIs."

 

From IP to identity: making cattle out of pets in cloud native

"Across clusters, observability, service mesh, and extending beyond Kubernetes, Cilium is able to provide a consistent management experience because it treats identity as a first class citizen in its platform"

 

How to monitor Kubernetes network and security events with Hubble and Grafana

"Think of it like a telescope for your network" my favorite quote about Hubble

 

eBPF in IETF protocols

"Once the IETF BPF working group has finished the standardization of the basics of eBPF the IETF should start to discuss the utilization of eBPF inside various Internet protocols"

 

Use the new eBPF-based sensor for Defender for Endpoint on Linux

Even Microsoft is buying into eBPF

 

Using eBPF in unprivileged Pods

Might want to dive into closing the BPF map permission loophole before diving too deep into this one

 

Deep application visibility, powered by eBPF

Another security start up leveraging eBPF

 

Comparing Networking Solutions for Kubernetes: Cilium vs. Calico vs. Flannel

"Cilium, with its eBPF-powered network architecture, provides advanced networking and security features and excels in offering deep network visibility"

 

K8s & Cilium Study Guide

Resources for the CKA networking part

🐝

 

The How To

Cilium Learning Tracks

Pick from tracks for cloud network engineers, security professionals, platform engineers, platform ops (service mesh), and cloud architects

 

Hubble Series (Part 2): Cilium Hubble for the Enterprise

Get a preview of Timescape to teleport across time in your infrastructure

 

Tutorial: Deploying Isovalent Enterprise for Cilium from Azure Marketplace using ARM Templates and Azure CLI

An extremely in depth how to

 

Mutual Authentication with Cilium

The first hands on mutual auth lab

 

Grafana Network Observability + Hubble Demo

Video turning eBPF bytecode into pretty graphs

 

Mon été avec Cilium et EKS (Partie 2)

"nous allons voir comment installer Cilium avec helm"

 

Cilium BGP Graceful Restart

Learn how how the datapath continues to forward traffic during Agent restart, so there is no traffic disruption in this video

 

Cilium 1.14 Feature: Envoy as a Daemonset

"Envoy can now be deployed as a DaemonSet instead of embedded inside Cilium"

 

Cilium Custom BGP Timers

This video shows you to customize BGP timers with Cilium

 

WireGuard Improvement in 1.14 - Support for L7 Policies

See how WireGuard can work with L7 policies

🐝

 

The Events

Isovalent Security Summer School

Virtual - EMEA date: August 2. AMER: August 10

 

Cilium Virtual Workshop with Isovalent

August 16th

 

Cilium Workshop with Isovalent and Piros - Leuven, Belgium

September 5th

 

Cilium Workshop with Isovalent, CamptoCamp and Exoscale - Geneva

September 14th

 

Cilium Workshop with Isovalent and Redpill Linpro - Oslo

October 17th

 

Cilium Workshop with Isovalent and Redpill Linpro - Stockholm

October 19th

 

CiliumCon CfP is open

Now as a full day event at KubeCon Chicago November 6th. Submit today!

 

eBPF Summit

On September 13th. Register today!

🐝

The Livestreams

eCHO Episode 98:

Exploring the bandwidth manager with Cilium

eCHO Episode 98: Exploring the bandwidth manager with Cilium

  

eCHO Episode 99: Explain Kubernetes Networking and Cilium to Network Engineers

eCHO Episode 99: Explain Kubernetes Networking and Cilium to Network Engineers

Upcoming Stream

eCHO Episode 100: Next-gen mutual authentication in Cilium

Add to your calendar

The Tweet of the Week

ahh the eBPF

As always, if you’ve seen a blog post, a tool, or anything else eBPF or Cilium related that you think the rest of the community should hear about, send them my way. You can either hit reply or join the #echo-news channel on Cilium Slack. You can also find all of the past episodes on the website.

🐝

To make sure you keep getting these emails, please add bill@isovalent.com to your address book or otherwise mark me as a permitted sender.

 

Know a friend that needs to be in the know? Forward this to them

Was this forwarded to you? Sign up today!

Written and sent by Bill Mulligan. Any feedback is welcome!

circle headshot

I work at Isovalent which is leading the eBPF-Powered Revolution in Cloud Native Networking, Observability, and Security with Cilium

isovalent
LinkedIn
Twitter

Isovalent, 20830 Stevens Creek Blvd. #1047, Cupertino, CA 95014, United States

Unsubscribe Manage preferences