One of my favorite parts of open source is getting to meet and collaborate with a variety of people around the world. As someone with no background in coding, I find it amazing how getting involved in open source enabled me to become a maintainer of one of the largest projects in the cloud native ecosystem. My journey is one of the reasons I love being a mentor through LFX, being able to give back and helping other people get into open source. This past cycle I got to work with Oluchi Nwenyi to make Cilium’s value clearer to end users. Together, we built new outcome focused pages for the Cilium website including Zero Trust Networking, Network Automation, Cost and Carbon Savings, Multi-Cloud Connectivity, Tool Consolidation and help connect features to the problems that end users are actually trying to solve. Demonstrating this value is something open source projects often struggle to do. For me, they highlight not just the opportunity of the project, but also the opportunity of open source itself. I'm away bikepacking this week at Sneak Peaks (follow along here) so let’s 🐝 -gin.
View in browser
echo-newsletter-90

eCHO news is your bi-weekly wrap up of all things eBPF and Cilium. If you want to keep up on the latest in cloud native networking, observability, and security this is your quelle

9th September 2025

 

One of my favorite parts of open source is getting to meet and collaborate with a variety of people around the world. As someone with no background in coding, I find it amazing how getting involved in open source enabled me to become a maintainer of one of the largest projects in the cloud native ecosystem. My journey is one of the reasons I love being a mentor through LFX, being able to give back and helping other people get into open source.

 

This past cycle I got to work with Oluchi Nwenyi to make Cilium’s value clearer to end users. Together, we built new outcome focused pages for the Cilium website including Zero Trust Networking, Network Automation, Cost and Carbon Savings, Multi-Cloud Connectivity, Tool Consolidation and help connect features to the problems that end users are actually trying to solve. Demonstrating this value is something open source projects often struggle to do. For me, they highlight not just the opportunity of the project, but also the opportunity of open source itself. I'm away bikepacking this week at Sneak Peaks (follow along here) so let’s 🐝 -gin.

The Technical

Monitoring MCP Traffic Using eBPF: Part 1

Learn the motivations and design of MCPSpy

 

Tracing DNS Queries in Real Time with eBPF

DNS queries and responses can be processed directly in the kernel using eBPF

 

The Mathematics of Maglev: An Analysis of Consistent Hashing in eBPF Load Balancers

Haven't seen math with letters like this since college calculus

 

Under the Hood with Go TLS and eBPF
Implementing TLS capture process for Go applications

 

Kubernetes Security with Cilium and Tetragon: A Comprehensive Lab Study

Diving deep into a defense-in-depth security architecture for Kubernetes

 

Native Routing and LoadBalancers with Cilium BGP in Kubernetes

Setting up Cilium with the BGP control plane and replacing kube-proxy and MetalLB with a native routing approach.

 

Sazidul0/Real-Time-eBPF-Intrusion-Detection-System

An eBPF-powered intrusion detection system with an end-to-end pipeline for kernel event monitoring, analysis, and visualization

 

ErikKarlgren/sikte

eBPF-based observability tool for performance research on Linux

 

Austinhamilton1/usbshield

eBPF-driven sandboxing for USB subsystems

 

vuvietnguyenit/gpu-memleak-trace

eBPF-based tool can trace GPU memory leaks by processes in Linux

 

MikolajKolek/ebpf-memory-monitor

Monitoring the VmPeak of a process and checking if it tried to exceed RLIMIT_AS

🐝

 

The Ecosystem

Cilium Technical Outcome Pages

Five new pages on the Cilium website covering Zero Trust Networking, Network Automation, Cost and Carbon Savings, Multi-Cloud Connectivity, and Tool Consolidation

 

eBPF and the Systems Trilemma
or how eBPF is reshaping OS Design for Safety, Performance, and Programmability

 

Rewiring the 5G Data Plane: XDP/eBPF and UPF

"eUPF sustained ~9.6 Gbps in both directions, about 6–8× more than Open5GS and ~30% more than UPG-VPP"

 

Help Us Map The State of Kubernetes Networking

Survey to determine what is state of the art and what is messy cables in a cabinet

 

The Unsung Hero of eBPF: The Verifier 🛡️
Think of the verifier as a security guard + code reviewer + optimizer

 

Supercharging OpenShift and KubeVirt with Cilium and eBPF

Building zero-trust networking across containers, VMs, and clusters with an OpenShift, Cilium, and KubeVirt stack

 

🐝

 

The How To

RKE2 Setup with Cilium CNI on OnPrem Servers 
"Canal is great but Cilium offers more features for security/network/observability"

🐝

 

The Video

End of summer slowdown?

🐝

 

The Events

Railroad to eBPF
Meetup in Vienna on September 18th

 

CiliumCon

November 10th in Atlanta. Schedule out now!

🐝 

The Livestreams

eCHO Episode 193: Benchmarks Don’t Lie: The Real Cost of Security Agents… or Is It eBPF?

eCHO Episode 193: Benchmarks Don’t Lie: The Real Cost of Security Agents… or Is It eBPF?

  

eCHO Episode 194: Tetragon Everywhere

 

eCHO Episode 194: Tetragon Everywhere

Upcoming Stream

eCHO Episode 195: Coming up in Cilium

The Post of the Week

The weirdest Kubernetes node?   A 2018 smartphone (OnePlus 6 ) running as a Kubernetes node with Cilium.  It’s currently hosting ArgoCD Server and Grafana without any issues.   After a bit of struggling to tweak the Linux kernel from postmarketOS (adding netfilter and VLAN modules so Cilium could run properly), the end result was pure satisfaction. 😄

As always, if you’ve seen a blog post, a tool, or anything else eBPF or Cilium related that you think the rest of the community should hear about, send them my way. You can either hit reply or join the #echo-news channel on Cilium Slack. You can also find all of the past episodes on the website.

🐝

To make sure you keep getting these emails, please add bill@isovalent.com to your address book or otherwise mark me as a permitted sender.

 

Know a friend that needs to be in the know? Forward this to them

Was this forwarded to you? Sign up today!

Written and sent by Bill Mulligan. Any feedback is welcome!

KC+CNC_NA_Headshot_241114_William_Mulligan_8154 (1)

I work for Isovalent at Cisco which is leading the eBPF-Powered Revolution in Cloud Native Networking, Observability, and Security with Cilium and Tetragon

logo-wordmark-isovalent-vertical-dark@2x
LinkedIn
X

Cisco/Isovalent, LLC, 755 Sycamore Drive, Milipitas, CA 95035, United States

Unsubscribe Manage preferences