When you need to overcome your fear and build your own data-driven eBPF firewall - Niek Temme

Описание к видео When you need to overcome your fear and build your own data-driven eBPF firewall - Niek Temme

Why and how we built a custom eBPF firewall for our use case of running up to ten thousand firecracker micro vms per node, 1M Envoy clusters and receiving updates through a go control plane.

This session is about a production use case that highlights the performance and flexibility of XDP, overcoming our fear of eBPF programming and information exchange between our control plane and eBPF.

The use case is for Bubl, a pre-launch startup with a mission to restart privacy safe innovation on personal data, by allowing innovative companies to create privacy safe services in the cloud.

By providing insight into our journey, our challenges and the solution we came up with we can help other companies get started with eBPF for networking and show how to integrate its flexibility with other applications.

Covered topics
10.000 vm’s per node, 1M Envoy TLS/SNI clusters, IPv6 load balancing
Why we went for a custom solution
Our journey and result
Interacting with control plane

Whether you are just starting to learn about eBPF, you're looking for further material or you're a seasoned contributor to major eBPF projects, the eBPF & Cilium Community is here to support you. Join the community on Slack 24/7 for help with, and discussions about eBPF and Cilium: https://ebpf.io/slack.

—-

Cilium is an open source software for providing, securing and observing network connectivity between container workloads - cloud native, and fueled by the revolutionary Kernel technology eBPF.

Learn more on the website: https://cilium.io/
Follow us on Twitter:   / ciliumproject  
Download and contribute on Github: https://github.com/cilium/cilium

—-

eBPF is a revolutionary technology with origins in the Linux kernel that can run sandboxed programs in an operating system kernel. It is used to safely and efficiently extend the capabilities of the kernel without requiring to change kernel source code or load kernel modules.

Learn more on the website: https://ebpf.io/

#ebpf #cilium #cloudnative

Комментарии

Информация по комментариям в разработке