View in browser
echo-newsletter-40: eBPF Documentary Trailer Cilium Learning Paths

 eCHO news is your bi-weekly wrap up of all things eBPF and Cilium. If you want to keep up on the latest in cloud native networking, observability, and security this is your quelle

3rd October 2023

 

I case you missed the launch on Twitter or LinkedIn, the trailer and website for the eBPF Documentary: Unlocking the Kernel is out now. If the full documentary is even half as good as the trailer you won't want to miss it! The line that really stands out to me and I think captures both the sentiment of the trailer and the driving force behind eBPF is "It's a revolution not an evolution". eBPF represents a step change in what we are able to do with the kernel and platforms we build on top of it. That's what makes it and the applications that leverage it so powerful.

 

For example, I was at KubeCon China last week and shared the stage with Trip.com who explained how Cilium allowed them to scale their clusters to over 20,000 nodes. That half of the talk is in Chinese so you can also read more about it in the English case study. This is part of my drive to have content about Cilium and eBPF in multiple languages so people can learn about them in their native language. We have also started to translate ebpf.io into multiple languages with the first one being French and more are on the way. Reach out to me if you are interested in helping with another one. I'm in Japan following KubeCon and some sushi is calling my name so let's ๐Ÿ gin!

The Technical

Kube-Proxy and CNI: The Hidden Components of Kubernetes Networking

A deep dive into both and how Cilium makes them better

 

Deep Dive โ€” Inspect Deployment Network Traffic in Kubernetes

"Ciliumโ€™s Hubble, tapping into the power of eBPF, offers an impressive real-time observability platform"

 

Pitfalls of relying on eBPF for security monitoring (and some solutions)

"With care and creativity, eBPF can still be used to build next-generation security tools. But it requires acknowledging and working around eBPFโ€™s constraints, not ignoring them"

 

Building an Efficient Network Flow Monitoring Tool with eBPF - Part 2

"we wrote the kernel space code of our program, saw how to handle both IPv4, IPv6 as well as TCP and UDP segments"

 

camptocamp/tetragon-policy-builder

"Generate TracingPolicies based on Tetragon events" Love the logo!

 

hardenedvault/ved-ebpf

"Kernel Exploit and Rootkit Detection using eBPF"

 

alegrey91/harpoon

"Trace syscalls of user-defined functions, using eBPF"

 

hardos-ebpf-fuzzing/ekcfi

kcfi with eBPF

 

kmesh-net/kmesh

"High Performance ServiceMesh Data Plane Based on Programmable Kernel" aka eBPF

 

eeriedusk/nysm

"An eBPF stealth container meant to make offensive tools fly under the radar of System Administrators"

๐Ÿ

 

The Ecosystem

eBPF Documentary

Yep, we are getting a documentary! You can catch the trailer on Youtube here and catch the world premier at KubeCon in Chicago on November 8th

 

Not Your Grandpaโ€™s Packet Filter: eBPF in Cloud-Native Networking

Find out all the places eBPF is being used beyond just networking

 

Learn Cilium the Easy Way with the Cilium Learning Paths

Which eBee are you?

 

Datadog Project Highlight: Cilium

Learn why Datadog started contributing to Cilium and where they see the project going in the future

 

Cilium โ€“ A Fascinating Comprehensive Guide

"Cilium is a forward-thinking project that has redefined the way organizations approach networking and security"

 

Using eBPF for Network Observability

Seems similar to a Tetragon project I know

 

Senser raises $9.5M to transform IT observability with packet filter technology and AI

"Zero-instrumentation using eBPF is a major change in the observability paradigm that will allow Senser to take on bigger players"

 

Learning eBPF Review

"It moves beyond theObservability and performance lens towards Security and modification behaviour inside the Linux kernel"

๐Ÿ

 

The How To

Architecting for Resilience: Crafting Opinionated EKS Clusters with Karpenter & Cilium Cluster Mesh โ€” Part 1

"Cilium is our networking superhero, ensuring our clusters talk to each other smoothly"

 

Cilium: Installing Cilium on AKS- Mariner in BYOCNI mode

For anyone on AKS wanting to move to Cilium

๐Ÿ

 

The Video

eBPF Documentary Trailer

It's great, go watch it!

 

Can I Use Tetragon Without Cilium?

Yes. Watch the video to find out how and why

๐Ÿ

 

The Events

eBPF Superpowers for SRE

Hear Liz Rice at SRECon in Dublin on October 10th

 

Cilium Workshop with Isovalent and Redpill Linpro - Oslo

October 17th

 

KCD UK

Talks about mutual auth and Tetragon for observability on October 17th

 

Elevating Kubernetes Observability with Cilium & Hubble: Hidden Insights Training

Online training October 19th both EMEA and America's time zones

 

Cilium Workshop with Isovalent and Redpill Linpro - Stockholm

October 19th

 

Cilium Workshop with Isovalent and Kloia - London

November 1st

 

CiliumCon

Now as a full day event at KubeCon Chicago November 6th!

๐Ÿ

The Livestreams

eCHO Episode 108: eBPF test coverage collection with CoverBee

eCHO Episode 108: eBPF Test Coverage with CoverBee

  

eCHO Episode 109: Live Migration from Azure Kubenet to Cilium

eCHO Episode 109: Live Migration from Azure Kubenet to Cilium

Upcoming Stream

eCHO Episode 110: TBD

Add to your calendar

The Tweet of the Week

tweet: Great talk by  @lizrice  about the SUPERPOWERS of eBPF @ #KCDAustria

As always, if youโ€™ve seen a blog post, a tool, or anything else eBPF or Cilium related that you think the rest of the community should hear about, send them my way. You can either hit reply or join the #echo-news channel on Cilium Slack. You can also find all of the past episodes on the website.

๐Ÿ

To make sure you keep getting these emails, please add bill@isovalent.com to your address book or otherwise mark me as a permitted sender.

 

Know a friend that needs to be in the know? Forward this to them

Was this forwarded to you? Sign up today!

Written and sent by Bill Mulligan. Any feedback is welcome!

circle headshot

I work at Isovalent which is leading the eBPF-Powered Revolution in Cloud Native Networking, Observability, and Security with Cilium

isovalent
LinkedIn
Twitter

Isovalent, 20830 Stevens Creek Blvd. #1047, Cupertino, CA 95014, United States

Unsubscribe Manage preferences