Another KubeCon in the books ☸️ I lost track a while ago, but I think this is somewhere around 20 KubeCons for me and it was the biggest one yet with almost 13,000 people. We ran out of eBPF Children's Books and people were turned away from the Cilium maintainers track session because it was too full, but I still feel so lucky for all of the people I did get to meet and interact with in London.
View in browser
echo-newsletter-79

eCHO news is your bi-weekly wrap up of all things eBPF and Cilium. If you want to keep up on the latest in cloud native networking, observability, and security this is your quelle

8th April 2025

 

Another KubeCon in the books ☸️ I lost track a while ago, but I think this is somewhere around 20 KubeCons for me and it was the biggest one yet with almost 13,000 people. We ran out of eBPF Children's Books and people were turned away from the Cilium maintainers track session because it was too full, but I still feel so lucky for all of the people I did get to meet and interact with in London.

 

Beyond the AI hype on the keynote stage, the biggest hallway track topics I ran into were around multi cluster, DRA, and authentication. I expect we’ll be hearing a lot more about all three soon, and I’ll try to dig into each of them in more detail in upcoming posts. I seem to have come down with the classic post KubeCon bug and am trying to rest up so let’s 🐝 -gin.

The Technical

What If CI/CD Pipelines Had Built-in Security and Observability with eBPF?

Adding eBPF to GitHub Actions with code on GitHub

 

Modularizing your Aya program with tail calls

Chaining programs together

 

Exposing apps in Kubernetes: from services to Gateway API

Samples with Cilium

 

Kubernetes Networking: eBPF in Action — Filtering Packets Like a Pro

IP-blocking with XDP

 

dorkamotorka/tcmonitor-ebpf

"Repository for monitoring TC Return codes using eBPF"

 

nvibert/cilium-weekly

"A repo listing all the Cilium Weekly videos!"

 

elijahu1/ebpf-container-security

"eBPF container escape detector prototype"

 

Kiinitix/KernelFaaS

"high-performance serverless execution layer that runs functions directly inside the Linux kernel using eBPF"

 

theihor/bpfvv

"BPF Verifier Visualizer"

 

microsoft/jbpf

"Userspace eBPF instrumentation and control framework for deploying control and monitoring functions in a secure manner"

 

ShinoLeah/eDBG

"eBPF-based lightweight debugger for Android"

🐝

 

The Ecosystem

Falco vs. Tetragon: A Runtime Security Showdown for Kubernetes

Tetragon "functions like a bouncer" and runs with <1% overhead

 

The future of Kubernetes networking: Cilium and other CNIs with Canonical Kubernetes

"Canonical decided to integrate Cilium as the default CNI to reflect our commitment to delivering a modern, security-maintained, high-performance K8s experience"

 

What eBPF Means for Observability vs. Security

"eBPF for observability is often the easiest entry point" definitely agree with myself

 

The Next Evolution of DigitalOcean Kubernetes: Introducing Features that Unlock Superior Scalability for Growing Businesses

DO adds support for managed Cilium, KPR, and Hubble

 

A Bootiful Podcast: Johannes Bechberger, Java engineer at SAP

Interview with the creator of hello-ebpf

 

Unveiling the Power of Small Open Source Contributions: A Journey in Fixing Quotes in Cilium Documentation

"consider documentation fixes as a valuable entry point [to open source]"

 

eBPF Swag Store

Just launched, buy any eBPF branding things you need

🐝

 

The How To

VMs are moving to Kubernetes, learn how Cilium can solve your networking with:

Kubevirt on EKS Anywhere and Red Hat OpenShift Virtualization on ROSA

 

Enhancing AWS EKS Cost Efficiency: Leveraging ENI Prefix Delegation for Optimal Resource Utilization

Increase pod capacity and cost efficiency with Cilium

 

Cloud Annotations for Gateway API & Ingress with Cilium

Learning the Load Balancer service on EKS and AKS

 

Tetragon TracingPolicy: Hands-On

Walking through the 4 parts of a policy

 

Mastering Cilium Network Policies: Zero-Trust Security for Kubernetes

Protect your Flask app from L3-L7

 

Tetragon Series

From Default Settings and Built-in Observability for Kubernetes to Enforcing Sensitive File Access with a Namespaced TracingPolicy

 

Dual-Stack: Rancher RKE2 With Cilium on Proxmox

Why choose between v4 and v6?

🐝

 

The Video

How Confluent Migrated Kubernetes Networking Across AWS, Azure & GCP

With Cilium of course :D

 

SRv6 uSID host networking - mpls/srv6/ai wc paris25

with Cilium as the CNI

🐝

 

The Events

Architecting Seamless Security: Integrated Vulnerability Mitigation with Isovalent + Splunk

Online webinar, April 10th

 

Kubernetes Network Policies Done Right

Online webinar, April 15th

🐝 

The Livestreams

eCHO Episode 175:

Tetragon 1.3/1.2 release review

eCHO episode 175: Tetragon 1.3/1.2 release review

  

eCHO Episode 176: Kubecon Europe and CiliumCon Preview!

eCHO Episode 176:  Kubecon + CloudNativeCon Europe and CiliumCon Preview!

Upcoming Stream

eCHO Episode 177: KubeCon Wrap Up

The Post of the Week

#KubeCon Ready for the biggest Cloud Native Wonka to date 🍫🍫🍫🍫🍫  Bonus, every chocolate bar is secured with eBPF 😎  Hope I’m making my security friends proud 😇  The will you get a golden ticket Corsair 🏴‍☠️

As always, if you’ve seen a blog post, a tool, or anything else eBPF or Cilium related that you think the rest of the community should hear about, send them my way. You can either hit reply or join the #echo-news channel on Cilium Slack. You can also find all of the past episodes on the website.

🐝

To make sure you keep getting these emails, please add bill@isovalent.com to your address book or otherwise mark me as a permitted sender.

 

Know a friend that needs to be in the know? Forward this to them

Was this forwarded to you? Sign up today!

Written and sent by Bill Mulligan. Any feedback is welcome!

KC+CNC_NA_Headshot_241114_William_Mulligan_8154 (1)

I work for Isovalent at Cisco which is leading the eBPF-Powered Revolution in Cloud Native Networking, Observability, and Security with Cilium and Tetragon

logo-wordmark-isovalent-vertical-dark@2x
LinkedIn
X

Cisco/Isovalent, LLC, 755 Sycamore Drive, Milipitas, CA 95035, United States

Unsubscribe Manage preferences