Uber's latest blog post talked about how they migrated 3 million cores to Kubernetes and GKE now supports 65,000 nodes in a cluster. The scale of deployment of cloud native workloads is ever increasing and Cilium is innovating to keep pace.  At KubeCon, Google shared the scalability improvements they made in Cilium to achieve this number of nodes. Similarly, Microsoft recently published a blog post talking about how the CiliumEndpointSlice feature enabled them to have 50% faster API server responsiveness, 60% faster pod startup times, and 80% lower in-cluster network latency. To take a space themed saying from my childhood, Cilium is helping cloud native scale "To infinity and beyond." I'm returning to my childhood home for a wedding next week and need to finish my speech so let’s 🐝 -gin.
View in browser
echo-newsletter-81

eCHO news is your bi-weekly wrap up of all things eBPF and Cilium. If you want to keep up on the latest in cloud native networking, observability, and security this is your quelle

6th May 2025

 

Uber's latest blog post talked about how they migrated 3 million cores to Kubernetes and GKE now supports 65,000 nodes in a cluster. The scale of deployment of cloud native workloads is ever increasing and Cilium is innovating to keep pace. 

 

At KubeCon, Google shared the scalability improvements they made in Cilium to achieve this number of nodes. Similarly, Microsoft recently published a blog post talking about how the CiliumEndpointSlice feature enabled them to have 50% faster API server responsiveness, 60% faster pod startup times, and 80% lower in-cluster network latency. To take a space themed saying from my childhood, Cilium is helping cloud native scale "To infinity and beyond." I'm returning to my childhood home for a wedding next week and need to finish my speech so let’s 🐝 -gin.

The Technical

Learn KubeVirt: Deep Dive for VMware vSphere Admins

"Cilium provides the most NSX-like experience"

 

xCapture v3: Linux Performance Analysis with Modern eBPF and DuckDB

"xcapture v3.0.0-alpha is a “nerd preview” release"

 

Why Does My eBPF Program Work on One Kernel but Fail on Another?

Solved with BPF Type Format support and a Github repo

 

You See Me, Now You Don't: BPF Map Attacks via Privileged File Descriptor Hijacking

To guard against attacks, protect against unauthorized manipulation of BPF maps

 

Optimizing eBPF I/O latency accounting when running 37M IOPS, on 384 CPUs

using 21 NVMe SSDs with PCIe5

 

Cilium & Enhanced Networking with Intel 82599 VF in EKS

Learn to leverage SR-IOV

 

Tracing your syscalls with Aya

Part 5 of the Aya tutorial

 

Measuring performance of a command with eBPF utility

Learn how much time a command spends calling a given standard C library function

 

Using Cilium as a standalone NAT46x64 Gateway

Yes, you can use Cilium outside Kubernetes

 

Dual Stack K3s With Cilium And BGP

"In my eternal quest to over-engineer my home network..." What a great start

 

Executing eBPF In Github Actions

Run a program when a PR comes in

 

nouseforaname/bpf-hole

"reimplement pi-hole dns block as an eBPF program"

 

containerscrew/csp

"A Lightweight eBPF tool to monitor Podman egress traffic via cgroup egress hook"

 

SamuelVedel/kerpad

"Touchpad edge motion using ebpf"

 

gotoolkits/lightmon

"a lightweight, Docker/K8s container-aware network traffic monitoring tool based on eBPF"

🐝

 

The Ecosystem

Sinad User Story: Delivering Security and Observability for Workloads with Confidence

"Tetragon is eBPF made simple. It provides precise observability and efficient security"

 

eBPF-Powered Observability Beyond Azure: A Multi-Cloud Perspective with Retina

Easily solve problems like packet drops, DNS resolution failures, and packet capture

 

Why Tetragon Should Be Standard in Every Kubernetes Cluster

The Missing Runtime Security Layer

 

Недостатки Istio по сравнению с Cilium: подробное объяснение

Istio vs Cilium in Russian

 

What Is eBPF? (Audio)

Liz Rice's book now available in audio format

 

High-Scale Kubernetes Networking with Azure CNI Powered by Cilium

CiliumEndpointSlice decreases latency by 80%

🐝

 

The How To

Building a Custom Android System with eBPF Support

How to add eBPF support and use QEMU to run modified BlissOS

 

A Complete Guide to eBPF with Go: Building Modern Observability Tools

From installation to container monitoring and best practices

 

Deploying Cilium Networking on Amazon EKS Hybrid Nodes

Connectivity from on-premises and edge infrastructure into EKS clusters

 

Exposer des apps dans Kubernetes – Du service à la Gateway API

using Cilium

 

Cilium: Support for EFA drivers in EKS

Accelerate HPC and ML with Elastic Fabric Adapter

 

How to use Cilium Hubble for network observability

Intro and installation

🐝

 

The Video

What is eBPF? | eBPF Book Club

Walk through Liz Rice's book with Liz Rice herself

 

Cloud Native Live: Using Cilium to enforce gRPC-aware security policies

Paul and Whitney have a call

🐝

 

The Events

Enhancing AKS Networking and Security with the Isovalent Platform

Virtual workshop, May 22nd

Leveling Up EKS Clusters with the Isovalent Platform
Virtual Workshop, May 28th

The eBPF Library for Go

Meetup in Torino on May 29th

Simplify and Secure Red Hat OpenShift with the Isovalent Platform

Online webinar, June 4th

 

SIGCOMM 2025 eBPF Workshop

September 8-11th in Coimbra

🐝 

The Livestreams

eCHO Episode 178:

A deep dive on Service type LoadBalancer with Cilium

eCHO Episode 178: A deep dive on Service type LoadBalancer with Cilium

  

eCHO Episode 177: Transparent proxies, what are they? and lets implement one with eBPF! 🐝

eCHO Episode 179: Transparent proxies, what are they? and lets implement one with eBPF! 🐝

Upcoming Stream

eCHO Episode 179: TBD

The Post of the Week

Massive shout out the the folks over at  @cilium.io  . The tooling you've built for to make eBPF accessible in Go has opened a new world for me. I never thought I'd be writing C and stuff that runs in the kernel. Thank you! 🙏

As always, if you’ve seen a blog post, a tool, or anything else eBPF or Cilium related that you think the rest of the community should hear about, send them my way. You can either hit reply or join the #echo-news channel on Cilium Slack. You can also find all of the past episodes on the website.

🐝

To make sure you keep getting these emails, please add bill@isovalent.com to your address book or otherwise mark me as a permitted sender.

 

Know a friend that needs to be in the know? Forward this to them

Was this forwarded to you? Sign up today!

Written and sent by Bill Mulligan. Any feedback is welcome!

KC+CNC_NA_Headshot_241114_William_Mulligan_8154 (1)

I work for Isovalent at Cisco which is leading the eBPF-Powered Revolution in Cloud Native Networking, Observability, and Security with Cilium and Tetragon

logo-wordmark-isovalent-vertical-dark@2x
LinkedIn
X

Cisco/Isovalent, LLC, 755 Sycamore Drive, Milipitas, CA 95035, United States

Unsubscribe Manage preferences