View in browser
echo-newsletter-43

 

 eCHO news is your bi-weekly wrap up of all things eBPF and Cilium. If you want to keep up on the latest in cloud native networking, observability, and security this is your quelle

28th November 2023

 

After KubeCon, I headed home to celebrate Thanksgiving with my family for the first time in 4 years. If this edition seems a bit shorter or I missed anything important the last week, it is because I was entertaining and cooking for our 25 person Thanksgiving. Did I not add your article or was there a great blog post that you think should be included in this newsletter? Contact me and I'll be sure to add it. Email, slack, DMs, passenger pigeons, and smoke signals all work and I love to hear from the community (that means you!).

 

Organzing a community, like Cilium and eBPF, is kind of like organizing Thanksgiving dinner. It works best when everyone pitches in a bit to spread the load. With that in mind, I want to help you contribute to the community too. Want to submit to Cilium + eBPF Day? Let me help you with the CfP. Have a great case study about how you use Cilium? Let me write it up for you. Want to write a blog about your favorite feature in Cilium? Let me review it and add to the Cilium blog. Communities, like communal meals, work best when everyone adds a small contribution. Let me help you make yours!

 

I already have a few CfPs to review (and can't wait to see yours) so let's 🐝 gin!

The Technical

Connecting your Kubernetes island to your network with Cilium BGP

Learn the power and flexibility Cilium's BGP can bring to your network - and pitfalls to watch out for 

 

The Secure Path Forward for eBPF runtime: Challenges and Innovations

"we'll navigate through the complexities of securing eBPF, addressing open questions and the challenges they pose to system architects and developers alike" - a great overview

 

navarrothiago/upf-bpf

"An In-Kernel Solution Based on BPF/XDP for 5G UPF"

 

alegrey91/harpoon

"Trace syscalls of user-defined functions, using eBPF πŸ”"

 

alibaba/kubeskoop

"KubeSkoop automatic construct network traffic graph of Pod in the Kubernetes cluster, monitoring and analysis of the kernel's critical path by eBPF, to resolve most of Kubernetes cluster network problems"

 

ackerschoice/bpfhacks

"eBPF hacks"

🐝

 

The Ecosystem

Case Study: ilionx

Learn how Cilium helped them replace two additional tools in their network security stack

 

Buzzing Across Space: The Illustrated Children's Guide to eBPF

My co-author Quentin wrote up the backstory of how the book came to bee

 

It is time to let go on your service mesh dream

"We could smoothly transition away from our existing service mesh by thoroughly understanding Cilium's identity model, setting up encryption, and leveraging the Gateway API for control"

 

eBPF: The Key Technology to Observability

A deep dive into why eBPF needs to replace traditional APM tools

 

Tetragon 1.0 Promises a New Era of Kubernetes Security and Observability

"As Tetragon continues to evolve, it appears set to remain a powerful and efficient tool for Kubernetes security by offering a unique combination of deep observability and minimal performance impact"

 

EBPF-Based Security Solutions: Exploring Weaknesses And Mitigation Techniques

1 and 2 can be mitigated by switching to Tetragon and 3 is make sure you keep things up to date

 

🐝

 

The How To

Tutorial: Deploying Red Hat OpenShift with Cilium

"Cilium has been available in the Red Hat Ecosystem Catalog since 2021, as well as being certified as a Certified OpenShift CNI Plug-in" find out how to deploy it

 

Isovalent, Azure Linux, and Azure Kubernetes Service come together

Learn how to install, migrate, and/or upgrade your AKS clusters to Azure CNI powered by Cilium

 

Cilium: ENI Prefix Delegation in EKS

Learn how to overcome IP address limitations

 

Cilium: The IPAM conundrum-AKS

Check which applications, services, and pods are using which IP addresses and triage issues

 

Cilium: Fixed IP allocation vs. Prefix delegation in AKS

Comparing Overlay and VNet for IP allocation in Azure

🐝

 

The Video

Setting Up a Cybersecurity Honeypot with Tetragon to Trigger Canary Tokens

Follow along video from the blog post

 

Using Tetragon With Your Existing Kubernetes Container Network Interface

Hint: it doesn't need to be Cilium

🐝

 

The Events

Linux Plumbers Conference

All the talks, slides, and live stream and up on the website. So much cool stuff coming out of the community!

 

Cilium Workshop with Isovalent, Microsoft & Sopra Steria - Oslo

November 28th

 

Cilium Workshop with Isovalent, Microsoft & Sopra Steria - Trondheim

November 29th

 

What's new in Cilium 1.14!

Webinar on November 30th

 

Tetragon 1.0 has Landed: What’s New and Exciting in Kubernetes Security?

Webinar on December 7th

 

Cilium 1.14 Release

Hands-on virtual workshop on December 14th

 

Cilium Workshop with Isovalent & Redpill Linpro - Copenhagen

January 11th

 

Cilium Workshop with Isovalent and Sue - Geldermalsen

January 25th

 

Cilium + eBPF Day

Coming back to KubeCon Paris and the CfP closes on December 3rd πŸ˜… Let me know if you need help

🐝

The Livestreams

eCHO Episode 115: KubeCon CiliumCon NA 2023 Review

eCHO Episode 115: KubeCon/CiliumCon NA 2023 Review

  

eCHO Episode 116: Revealing Security Blindspots with Tetragon

eCHO Episode 116: Revealing Security Blindspots with Tetragon

Upcoming Stream

eCHO Episode 116: A Tour of the Cilium Helm Values

Add to your calendar

The Tweet of the Week

Screenshot 2023-11-28 at 15.29.32

As always, if you’ve seen a blog post, a tool, or anything else eBPF or Cilium related that you think the rest of the community should hear about, send them my way. You can either hit reply or join the #echo-news channel on Cilium Slack. You can also find all of the past episodes on the website.

🐝

To make sure you keep getting these emails, please add bill@isovalent.com to your address book or otherwise mark me as a permitted sender.

 

Know a friend that needs to be in the know? Forward this to them

Was this forwarded to you? Sign up today!

Written and sent by Bill Mulligan. Any feedback is welcome!

circle headshot

I work at Isovalent which is leading the eBPF-Powered Revolution in Cloud Native Networking, Observability, and Security with Cilium

isovalent
LinkedIn
Twitter

Isovalent, 20830 Stevens Creek Blvd. #1047, Cupertino, CA 95014, United States

Unsubscribe Manage preferences