Supply chain security is a topic that needs little introduction, but still goes many layers deep. My colleagues André Martins and Feroz Salam, did a great write up of the defense in depth strategy Cilium uses to secure its CI/CD pipeline. I love how it skips the theoretical and goes right into the implementation, like why we use two-phase checkouts for pull_request_target and the gaps that we are still trying to close. ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
View in browser
echo-newsletter 108

eCHO news is your bi-weekly wrap up of all things eBPF and Cilium. If you want to keep up on the latest in cloud native networking, observability, and security this is your quelle

19th May 2026

 

Supply chain security is a topic that needs little introduction, but still goes many layers deep. My colleagues André Martins and Feroz Salam, did a great write up of the defense in depth strategy Cilium uses to secure its CI/CD pipeline. I love how it skips the theoretical and goes right into the implementation, like why we use two-phase checkouts for pull_request_target and the gaps that we are still trying to close.

 

My other favorite security write up from this week is how Cloudflare mitigated the “Copy Fail” Linux vulnerability with eBPF. Instead of waiting for a full kernel rollout, they used eBPF to surgically block the vulnerable code path at runtime. As I said last week, the future of runtime security is live patching and enforcement in the kernel. I need to go jump in a hot spring so let’s 🐝 -gin.

The Technical

Securing CI/CD for an open source project: lessons from Cilium

An in depth look at what Cilium does to harden its supply chain

 

Tetragon 1.7: Precision filtering, richer context, and better performance

including fentry sensor support and CEL-in-BPF evaluation

 
Performance comparison Cilium native routing on Azure Kubernetes Service BYOCNI
Native routing: 12 Gbit/s. VXLAN: 7.6. WireGuard: 2.1
 
Adding KASAN support to eBPF
Slides from LSFMMBPF showing how to get KASAN to cover JITed eBPF instruction
 
Kubernetes Watches Your CPU. Nobody’s Watching Your Egress.
A 44-line eBPF kprobe and Go DaemonSet to close the K8s egress visibility gap
 
Detecting CopyFail and DirtyFrag by thinking outside the box
eBPF LSM hook at security_socket_setsockopt is key
 
How much code are you testing?
Test coverage for any binary with just eBPF uprobes
 
azqzazq1/SunnyDayBPF
eBPF-based post-syscall user-buffer telemetry deception research technique 
 
W4ilops/eBPF-VM
eBPF virtual machine in Rust
 
AlexeyVasilev/PcapConstrictorBPF
experimental Linux TC eBPF packet recorder
 
bensanmorris/security_observability
Real-time observability of your certificate estate, certificate, process and k8s context
 
stepbrobd/rfm
eBPF network flow analysis agent for Linux routers

🐝

 

The Ecosystem

The Kernel Knows First: Why eBPF Is Becoming the Ground Truth Layer for AI-Native Infrastructure

"without the telephone game of logs, metrics, and dashboards" Hubble is a natural fit for MCP data

 

How Microsoft is governing thousands of Kubernetes clusters without manual intervention

ClusterMesh handles networking across thousands of K8s clusters  

 

How Cloudflare responded to the “Copy Fail” Linux vulnerability

A bpf-lsm program that blocked the vulnerable code path in hours

 

Cilium: niet alleen meer een CNI

A Dutch recap of Cilium at KubeCon Amsterdam 🌷

🐝

 

The How To

What's New: vCluster Multi-tenancy Pt.2

Cilium L2 Announcements for stable LoadBalancer IPs in a multi-tenant vCluster setup

 

Bare-Metal Kubernetes HA: Floating IPs Over BGP With Cilium and UniFi's UCG-Fiber

A Cilium 1.19 quirk that silently breaks the apiserver path and a five-line YAML fix

 

Networking on Talos Linux with Cilium

Everything Cilium can replace on a Talos cluster: kube-proxy, Ingress, MetalLB...

 

From ENI Math to eBPF: Migrating EKS Off the AWS VPC CNI

EKS's native VPC CNI hits a ceiling on pod density

 

Migrating EKS from AWS VPC CNI to Cilium with Zero Downtime

The design rule: A node should belong to exactly one CNI generation

🐝

 

The Video

Maybe next year LSF/MM/BPF will have videos

🐝

 

The Events

ACM SOSP'26 Workshop on eBPF and Kernel Extensions

September 29th in Prague, CfP open through June 19

 

Linux Plumbers Conference

October 5-7th in Prague, CfP open though July 24

 

P99CONF

October 21-22nd, virtual, CfP open through May 29

 

CiliumCon

November 9 in Salt Lake City, CfP open though June 21

🐝 

The Livestreams

eCHO Episode 208: Tetragon & OpenClaw Lab Preview

eCHO Episode 208: Tetragon & OpenClaw Lab Preview

  

eCHO Episode 209: Cilium on VKS with the Broadcom VKS team

eCHO Episode 209: Cilium on VKS with the Broadcom VKS team

The Post of the Week

CiliumCon CfP

As always, if you’ve seen a blog post, a tool, or anything else eBPF or Cilium related that you think the rest of the community should hear about, send them my way. You can either hit reply or join the #echo-news channel on Cilium Slack. You can also find all of the past episodes on the website.

🐝

To make sure you keep getting these emails, please add bill@isovalent.com to your address book or otherwise mark me as a permitted sender.

 

Know a friend that needs to be in the know? Forward this to them

Was this forwarded to you? Sign up today!

Written and sent by Bill Mulligan and Katie Meinders. Any feedback is welcome!

LF_KCCNC_headshot_251113_Bill_Mulligan_9686
1755685839473

I work for Isovalent at Cisco which is leading the eBPF-Powered Revolution in Cloud Native Networking, Observability, and Security with Cilium and Tetragon

logo-wordmark-isovalent-vertical-dark@2x
LinkedIn
Bluesky_Logo.svg

Cisco/Isovalent, LLC, 755 Sycamore Drive, Milipitas, CA 95035, United States

Unsubscribe Manage preferences