The schedule for CiliumCon at KubeCon North America in Salt Lake City this November is now live. There is a good combination of end user talks from orgs like OpenAI on debugging inference workloads with eBPF and ESnet on Cluster Mesh, native routing, and multi-pool IPAM in an IPv6-only network, and talks from maintainers and practitioners. Datadog also has a lightning talk on migrating their datapath to netkit at scale, which ties into this issue through an independent benchmark of netkit against bare host networking across five workloads, with netkit coming out ahead on everything except single-threaded, lock-bound cases. ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
View in browser
echo-newsletter 115

eCHO news is your bi-weekly wrap up of all things eBPF and Cilium. If you want to keep up on the latest in cloud native networking, observability, and security this is your quelle

25th August 2026

 

The schedule for CiliumCon at KubeCon North America in Salt Lake City this November is now live. There is a good combination of end user talks from orgs like OpenAI on debugging inference workloads with eBPF and ESnet on Cluster Mesh, native routing, and multi-pool IPAM in an IPv6-only network, and talks from maintainers and practitioners. Datadog also has a lightning talk on migrating their datapath to netkit at scale, which ties into this issue through an independent benchmark of netkit against bare host networking across five workloads, with netkit coming out ahead on everything except single-threaded, lock-bound cases.

 

Elsewhere, this is a shorter issue thanks to the usual August slowdown, but there's still good material on multi-tenant isolation with Cilium, TLS fingerprinting straight from the kernel, and a from-scratch service mesh built on eBPF.

 

The State of Kubernetes Networking 2026 survey will close this month. If you haven't taken it yet, we'd love your input!

 🐝 

The Technical

Linux Bare Host vs. Container with Cilium netkit: What Actually Wins

Benchmarking Cilium's netkit against bare host networking across HTTP, etcd, PostgreSQL, Kafka, and MPI workloads

 

How I isolate and identify tenant traffic with Cilium

Using underlay routing and per-tenant IP pools to isolate traffic on bare-metal Kubernetes

 

JA4 fingerprinting using eBPF

An eBPF program to extract TLS ClientHello bytes and compute JA4 fingerprints

 

Multi-Tenant Kubernetes with Kustomize Templates and ApplicationSets

Using Cilium network policies to isolate client traffic

 

Building a multi-tenant, zero-trust, micro-segmented Kubernetes platform with Cilium

Isolating tenants with Cilium identities instead of network-layer segmentation

 

From SWIM Paper to eBPF Kernel Hooks: Building a Service Mesh Sidecar

A from-scratch service mesh redirects TCP connections using an eBPF cgroup hook

 

OWASP/www-project-kubefim

Monitors file integrity and process execution in Kubernetes at kernel level using eBPF

 

BugrahanYucel/ebpf-mon

Compiles live eBPF-captured container behavior into AppArmor and BPF-LSM enforcement policies

 

wkilabnwi/K-guard

Detects and blocks kernel-level intrusions using eBPF tracepoints and LSM hooks, with Kubernetes pod context enrichment

 

🐝

 

The Ecosystem

Even more formal verification for BPF

Meta proposed formal verification for BPF at the 2026 LSF/MM/BPF Summit

🐝

 

The How To

Use Cilium chaining with OKE VCN-native pod networking

Add Cilium identity and policy enforcement to OKE's VCN-native pod networking using CNI chaining

🐝

 

The Video

Enchant Your AI and APIs with eBPF Magic 🪄

Dan Finneran demoing using eBPF to transparently intercept and control AI agent traffic in Kubernetes

 

(Vlog) GopherCon in Seattle | speaking, teaching eBPF and Go

Behind the scenes with Donia teaching an eBPF workshop at GopherCon

 

🐝

 

The Events

ACM SOSP'26 Workshop on eBPF and Kernel Extensions

September 29th in Prague

 

Linux Plumbers Conference

October 5-7th in Prague, schedule for eBPF Track 

 

CiliumCon

November 9 in Salt Lake City, schedule now live 

🐝 

The Livestreams

eCHO Episode 213: What's New in Cilium 1.20

eCHO Episode 213: What's New in Cilium 1.20

  

eCHO Episode 214: Contributing to Cilium with Hadrien Patte of Datadog

Episode 214: Contributing to Cilium 1.20 with Hadrien Patte of Datadog

The Post of the Week

Screenshot 2026-08-25 at 16.44.42

As always, if you’ve seen a blog post, a tool, or anything else eBPF or Cilium related that you think the rest of the community should hear about, send them my way. You can either hit reply or join the #echo-news channel on Cilium Slack. You can also find all of the past episodes on the website.

🐝

To make sure you keep getting these emails, please add kaoconno@cisco.com to your address book or otherwise mark me as a permitted sender.

 

Know a friend that needs to be in the know? Forward this to them

Was this forwarded to you? Sign up today!

Written and sent by Katie Meinders. Any feedback is welcome!

1755685839473

I work for Isovalent at Cisco which is leading the eBPF-Powered Revolution in Cloud Native Networking, Observability, and Security with Cilium and Tetragon

logo-wordmark-isovalent-vertical-dark@2x
LinkedIn
Bluesky_Logo.svg

Cisco/Isovalent, LLC, 755 Sycamore Drive, Milipitas, CA 95035, United States

Unsubscribe Manage preferences