1"use strict";(self.webpackChunkcilium_io=self.webpackChunkcilium_io||[]).push([[5011],{6452:function(e,n){n.A={thomasGraf:{header:"Thomas Graf",bio:'Thomas Graf is a Co-Founder of Cilium and the CTO & Co-Founder of <a href="https://isovalent.com/?utm_source=website-cilium&utm_medium=referral&utm_campaign=cilium-enterprise">Isovalent</a>, the company behind Cilium. Before that, Thomas spent 15 years as\n a kernel developer working on the <a href="https://kernel.org">Linux kernel</a> in networking, security and eventually eBPF.'},lizRice:{header:'<a href="https://twitter.com/lizrice">Liz Rice</a>',bio:'Liz is Chief Open Source Officer at <a href="https://isovalent.com/?utm_source=website-cilium&utm_medium=referral&utm_campaign=cilium-enterprise" target="_blank" rel="noopener noreferrer">Isovalent</a>, the company behind Cilium. She is also chair of the CNCF\'s Technical Oversight Committee, and the author of Container Security published by O\'Reilly.'},luanGuimaraes:{header:"Luan Guimarães",bio:"Luan is a Brazilian rock climber, amateur musician, and\n programmer and am enthusiastic about free software communities and other\n open knowledge initiatives. He has been working as a Site Reliability\n Engineer at Wildlife Studios, using and building infrastructure tools on\n top of Kubernetes in order to support millions of users around the world."},joshVanLeeuwen:{header:"Josh Van Leeuwen",bio:"Josh interned at Jetstack during the summer of 2017 before continuing to\n work part time during his final year of study at the University of Bristol.\n During this year, Josh developed a Kubernetes custom controller that\n automates the delegation of RBAC permissions based on time and event\n triggers. This work was later awarded the best Software Development Tool\n Final Year Project. Josh now works full time at Jetstack where if heâs not\n writing more Go, heâs making good food."},howardHao:{header:"Howard Hao",bio:" Howard Hao has been working as a Site Reliability Engineer for five years at\n Ect888.com since graduating from Shanghai Jiao Tong University. His team\n consists of 7 members and has been focusing on the construction of\n container orchestration platform like Kubernetes for one and a half years."},sergeyGeneralov:{header:"Sergey Generalov",bio:"Sergey is a member of the technical staff at Isovalent\n and focuses on helping Cilium users solve challenges related\n to network policies, monitoring, and connectivity troubleshooting\n by building tools like Network Policy Editor, Hubble UI and more."},liWenquan:{header:"Li Wenquan",bio:"Hello everyone, I am Li Wenquan from China. You can call me David. I\n started my Docker journey from 2014 and now work as a project manager of\n enterprise container platform, which is built on Kubernetes and Mesos. I\n got to know Cilium project from Kubecon, it is so interesting and\n promising. I've learned a lot from it, such as BPF, XDP and how to replace\n kube-proxy in a elegant way and I'd love to contribute to it."},alexanderAlemayhu:{header:"Alexander Alemayhu",bio:"Alexander Alemayhu is a software engineer at Isovalent,\n the company behind Cilium. He has been working on eBPF and Linux\n kernel technologies for several years, focusing on networking and observability solutions."},DanielBorkmann:{header:"Daniel Borkmann",bio:"Daniel Borkmann is a Distinguished Software Engineer, Isovalent at Cisco"},ThomasGraf:{header:"Thomas Graf",bio:"Thomas Graf is the CTO & Co-Founder Isovalent and also the Vice President Security Cisco"},JedSalazar:{header:"Jed Salazar",bio:"Jed Salazar is a Senior Solutions Architect, Isovalent"},JedSalazarandJoeStringer:{header:"Jed Salazar and Joe Stringer",bio:"Jed Salazar is a Senior Solutions Architect at Isovalent\n and Joe Stringer is a Principal Engineer, Isovalent at Cisco"},JosephIrving:{header:"Joseph Irving",bio:"Joseph Irving is a Platform Engineer Lead at RVU (Uswitch)"},BillMulligan:{header:"Bill Mulligan",bio:"Bill Mulligan is a Cilium and eBPF Community Pollinator,\n Isovalent at Cisco and a Governing Board Member of the eBPF Foundation."},OndrejBlazek:{header:"Ondrej Blazek",bio:"Ondrej Blazek is an Infrastru
1cture Engineer at Seznam.cz"},LeonardCohnenandMoritzEckert:{header:"Leonard Cohnen and Moritz Eckert",bio:"Leonard Cohnen and Moritz Eckert are team members at Edgeless Systems"},PolArroyo:{header:"Pol Arroyo",bio:"Pol Arroyo is a DevOps Engineer at Hetzner Cloud."},JedSalazarandMartynasPumputis:{header:"Jed Salazar and Martynas Pumputis",bio:"Jed Salazar is a Senior Solutions Architect, Isovalent and Martynas Pumputis is a Principal Software Engineer, Isovalent at Cisco"},ShedrackAkintayo:{header:"Shedrack Akintayo",bio:"Shedrack Akintayo is a Community Manager at\n Isovalent helping build the eBPF and Cilium open source communities"},AmirKheirkhahan:{header:"Amir Kheirkhahan",bio:"Amir Kheirkhahan is a DevOps Specialist at DB Schenker handling design, development,\n deployment and maintenance of wide range of devops toolchain on top of Kubernetes clusters"},PaulArah:{header:"Paul Arah",bio:"Paul Arah is a Community Builder focused on Security at Isovalent (Cisco)"},HimalKumar:{header:"Himal Kumar, Bhaskar Dutta, Arman Pashamokhtari",bio:"Himal Kumar, Bhaskar Dutta, Arman Pashamokhtari are all part of the\n CanopusAI team Real Time Network Observability, powered by eBPF and Agentic AI"},DoniaChaiehloudj:{header:"Donia Chaiehloudj",bio:"Donia Chaiehloudj is a Senior Software Engineer and Community Oriented at Isovalent.\n She has been working on Cilium and eBPF technologies, focusing on networking and security solutions."},KatieMeinders:{header:"Katie Meinders",bio:"Katie Meinders is a Community Builder at Isovalent where\n she helps grow the Cilium and eBPF communities through storytelling,\n social media, showcasing user success, and building connections across the open source ecosystem."},PeaceSandy:{header:"Peace Sandy",bio:"Peace Sandy is an LFX mentee who contributed to improving Cilium SEO, AEO, and\n AIO during her mentorship period."},NehaAggarwal:{header:"Neha Aggarwal",bio:"Neha Aggarwal is a Principal Engineer at Microsoft."},CharityMbisi:{header:"Charity Mbisi",bio:"Charity Mbisi is an LFX mentee who contributed to improving Cilium's SEO, AEO, and AIO during his mentorship period.\n Professionally, Charity Mbisi is a Software Engineer consulting in the Fin-tech and banking industry, specializing in building cloud native computing solutions and optimized service delivery."},andreMartinsAndFerozSalam:{header:"André Martins and Feroz Salam",bio:"André Martins is a Cilium maintainer and Software Engineer, Isovalent at Cisco.\n Feroz Salam is a member of the Cilium Security Team and a Security Engineer, Isovalent at Cisco."},ChristianHernandez:{header:"Christian Hernandez",bio:"Christian is a well rounded technologist with experience in infrastructure engineering, systems administration, enterprise architecture, tech support, advocacy, and product management. Passionate about OpenSource and containerizing the world one application at a time. He is currently a maintainer of the Argo Project and OpenGitops. Currently, he works as a Technical Marketing Engineer and Tech Lead at Cisco. He focuses on GitOps practices, DevOps, Kubernetes, Network Security, and Containers."},AkilaInduranga:{header:"Akila Induranga",bio:'Akila is a Senior Software Engineer at WSO2, and a maintainer of <a href="https://openchoreo.dev/" target="_blank" rel="noopener noreferrer">OpenChoreo</a>, an open-source internal developer platform for Kubernetes and a CNCF sandbox project.\n He works on the platform\'s observability and networking layers, including the Cilium-based networking module that brings identity-based policy and Hubble observability to OpenChoreo cells.'}}},7346:function(e,n,t){t.r(n),t.d(n,{Head:function(){return h},default:function(){return p}});var a=t(8453),i=t(6540),o=t(6452);function r(e){const n=Object.assign({span:"span",h4:"h4",em:"em",p:"p",a:"a",strong:"strong",h2:"h2",ul:"ul",li:"li"},(0,a.RP)(),e.components),{BlogAuthor:t}=n;return t||function(e,n){throw new Error("Expected "+(n?"component":"object")+" `"+e+"` to be defined: you likely forgot to import, pass, or provide it.")}("BlogAuthor",!0),i.createElement(i.Fragment,null,i.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n class="gatsby-resp-image-wrapper"\n style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 960px; "\n >\n <a\n class="gatsby-resp-image-link"\n href="/static/ac1f93cba534bc1339f78127e9fa7125/7d769/kubeconNA.png"\n style="display: block"\n target="_blank"\n rel="noopener"\n >\n <span\n class="gatsby-resp-image-background-image"\n style="padding-bottom: 56.34920634920635%; position: relative; bottom: 0; left: 0; background-image: url(\'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAIAAADwazoUAAAACXBIWXMAAAsTAAALEwEAmpwYAAAByklEQVR42lWQTUsbQRjH99yrIFRB/AIF6dVDD0JvnhQqYj9AKfYuPfllWje2voGWdo2olYh6VUlIk83Ozr5lNtnsS3Y3ye62/8zUgD+Gh+c/M8+rtLhVebt9u7h1/ebz9cLm2fTK7uza/tzG4cza8asP568/VRY+3sy+v5rbuJhaVV4sH0lLX16ufp1fl2fefZMu79nPO+3gd31HeZTL1R3lQVYeSuXHUrkq/6qWTmu75freeeP72R9Zqcmn1cMr9eCydlKp/7jRpTwb2aZOSdM2NH6IRVuOSeB3mRn5naDn+t124LGgx0LfDXtuEvlpHBVFLsXJwHaYTk3dsAgstahhEy6p6RhW2zAdfmMx1wvCJAjjYVbgpKNcGg6HjuPoum5yjCeEdF3X8zzf95MkKYri73OkwWCAyCZHVdVGo9HiqBw8UUoRn+d5lmUjDvz/wRBIb1mWbdvOEzZHXLY5QgK0Az8MQ+Q
1aB0OgAmJQocuB0+l0JhLEcRxFEZpP0xQWEvOOZ0Zj6JYQomka4cBhjCHG5SARSgVBgEjROcpiBRIGwCe8RRzhwMYc+P1+X1yKsn2O2N+4MtoWexZ2MhhGFRJdYASRCwuebPsfjaw9jTQ4A00AAAAASUVORK5CYII=\'); background-size: cover; display: block;"\n ></span>\n <picture>\n <source\n srcset="/static/ac1f93cba534bc1339f78127e9fa7125/2ff5b/kubeconNA.webp 252w,\n/static/ac1f93cba534bc1339f78127e9fa7125/4d583/kubeconNA.webp 504w,\n/static/ac1f93cba534bc1339f78127e9fa7125/10c02/kubeconNA.webp 960w"\n sizes="(max-width: 960px) 100vw, 960px"\n type="image/webp"\n />\n <source\n srcset="/static/ac1f93cba534bc1339f78127e9fa7125/019e0/kubeconNA.png 252w,\n/static/ac1f93cba534bc1339f78127e9fa7125/0dcb2/kubeconNA.png 504w,\n/static/ac1f93cba534bc1339f78127e9fa7125/7d769/kubeconNA.png 960w"\n sizes="(max-width: 960px) 100vw, 960px"\n type="image/png"\n />\n <img\n class="gatsby-resp-image-image"\n src="/static/ac1f93cba534bc1339f78127e9fa7125/7d769/kubeconNA.png"\n alt="Cilium Talks at KubeCon"\n title=""\n loading="lazy"\n decoding="async"\n style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n />\n </picture>\n </a>\n </span>'}}),"\n",i.createElement(n.h4,null,i.createElement(n.em,null,"October 4th, 2024")),"\n",i.createElement(n.h4,null,i.createElement(n.em,null,"Author: Shedrack Akintayo, Isovalent at Cisco")),"\n",i.createElement(n.p,null,"Following a remarkable period of growth and innovation, the Cilium community is gathering for the fourth Cilium + eBPF Day and the ninth KubeCon + CloudNativeCon North America 2024. With the recent ",i.createElement(n.a,{href:"https://github.com/cilium/cilium/releases/tag/v1.16.0"},"release of Cilium 1.16"),", featuring the highly anticipated and powerful Cilium ",i.createElement(n.strong,null,"netkit"),", the project is again at the forefront of the cloud native ecosystem. This release is generating significant buzz, showcasing how Cilium and eBPF continue to revolutionize networking, observability, and security."),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/co-located-events/cilium-ebpf-day/"},"Cilium + eBPF Day")," promises to be an immersive exploration into the world of Cilium, Tetragon, Hubble, and eBPF. The agenda is packed with insightful talks from end users, core contributors, and community members, covering topics like migrating to Cilium, network policy scalability and enforcement, Cilium at the edge, and many more. Speakers from leading companies, including Microsoft, Isovalent at Cisco, Red Hat, eBay, Sony, and The New York Times, will share their experiences and insights, making this a valuable learning opportunity. Weâd also like to thank our sponsors for their generous support in making this event possible."),"\n",i.createElement(n.p,null,"At the broader ",i.createElement(n.a,{href:"https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/"},"KubeCon + CloudNativeCon North America 2024"),", Cilium is poised to be a significant part of the discourse, reflecting its leading influence in the cloud native community. Letâs run through all the ways you can learn about Cilium at the events to equip yourself with the knowledge to harness the power of Cilium and eBPF, enhance your networking capabilities, and make your platforms more secure, performant, and observable."),"\n",i.createElement(n.p,null,"Now, letâs dive into each of the talks on Cilium at the events!"),"\n",i.createElement(n.h2,null,"Cilium + eBPF Day 2024"),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://colocatedeventsna2024.sched.com/event/1j2dF/cilium-ebpf-day-welcome-opening-remarks"},"Cilium + eBPF Day | Welcome + Opening Remarks - Bill Mulligan, Isovalent & Vlad Ungureanu, Palantir Technologies")),"\n",i.createElement(n.p,null,"Tuesday, November 12, 2024, 09:00 am - 09:10 am MST"),"\n",i.createElement(n.p,null,"The Opening Session for Cilium + eBPF Day NA 2024"),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://colocatedeventsna2024.sched.com/event/1izpN/confluents-multi-cloud-journey-to-cilium-pitfalls-and-lessons-learned-nimisha-mehta-alvaro-aleman-confluent"},"Confluent's Multi-Cloud Journey to Cilium: Pitfalls and Lessons Learned - Nimisha Mehta & Alvaro Aleman, Confluent")),"\n",i.createElement(n.p,null,"Tuesday, November 12, 2024, 9:10 am - 9:35 am MST"),"\n",i.createElement(n.p,null,"Confluent Cloud is a data streaming platform built on thousands of Kubernetes clusters across AWS, Azure & GCP. Confluent migrated clusters to use Cilium for its advanced security features like transparent encryption and DNS name-based network policies, along with performance, scalability & observability improvements. The main challenge was executing a live migration without disrupting stateful workloads, complicated by the risks of replacing a low-level component like the CNI. The process required meticulous planning to ensure intra-cluster connectivity during migration while accommodating each cloud provider's unique network config. This talk shares the journey of migrating to Cilium, highlighting obstacles and lessons learned. We will explore uninstalling pre-existing CNIs, setting up Cilium & addressing cloud-specific issues to maintain connectivity. Benefits like transparent encryption, policies, and Hubble observability, along with the challenges faced, will also be discussed."),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://colocatedeventsna2024.sched.com/event/1izpm/insightful-traffic-monitoring-harnessing-cilium-for-comprehe
1nsive-network-observability-sudheendra-murthy-adithya-yavanamanda-ebay"},"Insightful Traffic Monitoring: Harnessing Cilium for Comprehensive Network Observability - Sudheendra Murthy & Adithya Yavanamanda, eBay")),"\n",i.createElement(n.p,null,"Tuesday, November 12, 2024, 9:45 am - 10:10 am MST"),"\n",i.createElement(n.p,null,"eBay's cloud consists of thousands of microservices running on millions of containers across hundreds of Kubernetes clusters. In this dynamic & complex cloud environment, mapping dependencies between microservices is crucial. This session delves into how eBay innovatively and scalably uses Cilium, powered by eBPF, to monitor traffic flows, generate real-time traffic events, and construct a comprehensive dependency graph of microservice interactions across hundreds of K8s clusters."),"\n",i.createElement(n.p,null,"The presentation will cover:"),"\n",i.createElement(n.ul,null,"\n",i.createElement(n.li,null,"The innovative use of eBPF and Cilium to monitor traffic events in near real-time"),"\n",i.createElement(n.li,null,"How traffic events are mapped to different microservices"),"\n",i.createElement(n.li,null,"The architecture and design of the scalable solution to handle the large volume of data"),"\n",i.createElement(n.li,null,"The integration of OpenTelemetry for efficient traffic event stream processing"),"\n",i.createElement(n.li,null,"Key challenges and solutions in building and maintaining the dependency graph"),"\n",i.createElement(n.li,null,"Insights and lessons learned from integrating eBPF and Cilium into eBayâs infrastructure"),"\n"),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://colocatedeventsna2024.sched.com/event/1izr8/panel-exploring-ebpf-use-cases-in-cloud-native-security-oshrat-nir-armo-anna-kapuscinska-isovalent-now-part-of-cisco-whitney-lee-cncf-ambassador-maya-singh-microsoft-cortney-nickerson-kubeshop"},"Panel: Exploring eBPF Use Cases in Cloud-Native Security - Oshrat Nir, ARMO; Anna KapuÅciÅska, Isovalent, now part of Cisco; Whitney Lee, CNCF Ambassador; Maya Singh, Microsoft; Cortney Nickerson, Kubeshop")),"\n",i.createElement(n.p,null,"Tuesday, November 12, 2024, 11:50 am - 12:25 pm MST"),"\n",i.createElement(n.p,null,"Cloud-native security requires a shift in mindset. Workloads are ephemeral, the attack surface has grown, and with it, the complexities. eBPF has emerged as a powerful technology, enabling deep visibility and dynamic security capabilities within the Linux kernel. This panel will explore use cases in which eBPF enhances cloud-native security. We will explore how eBPF can be leveraged to perform real-time monitoring, threat detection, and mitigation across containerized applications and microservices. Our expert panelists will share insights on using eBPF for network security, application profiling, anomaly detection, and enforcing security policies at the kernel level. Additionally, we will discuss the integration of eBPF with popular cloud-native tools and platforms, showcasing practical implementations."),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://colocatedeventsna2024.sched.com/event/1izs0/scaling-network-policy-enforcement-beyond-the-cluster-boundary-with-cilium-hemanth-malla-maxime-visonneau-datadog"},"Scaling Network Policy Enforcement Beyond the Cluster Boundary with Cilium - Hemanth Malla & Maxime Visonneau, Datadog")),"\n",i.createElement(n.p,null,"Tuesday, November 12, 2024, 1:30 pm - 1:55 pm MST"),"\n",i.createElement(n.p,null,"To keep up with infrastructure growth, companies around the world are managing an increasing number of Kubernetes clusters. Enforcing Kubernetes native network policy at scale is already hard enough within a single cluster. Extending this to multiple clusters is even more challenging. Depending on the shape of your infrastructure, your cross-cluster policy requirements may be unique, and thereâs no one-size-fits-all configuration. In this talk, weâll dive deep into how different solutions work in cilium to understand sources of potential bottlenecks. Weâll discuss Clustermesh, KVstoremesh, DNS-based FQDN policy, and a custom variant of KVstoremesh Datadog leverages while meshing at scale. Specifically, weâll discuss how factors like the number of pods, identities, and pod churn will impact scalability and time to policy enforcement. Join us if youâre curious about understanding the latest in cross-cluster policy and leave with actionable insights you can apply to your infrastru
1cture."),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://colocatedeventsna2024.sched.com/event/1izsR/how-to-use-xdp-and-ebpf-to-accelerate-ipsec-throughput-by-400-ryan-drew-isovalent-now-part-of-cisco"},"How to Use XDP and eBPF to Accelerate IPSec Throughput by 400% - Ryan Drew, Isovalent, now part of Cisco")),"\n",i.createElement(n.p,null,"Tuesday, November 12, 2024, 2:05 pm - 2:30 pm MST"),"\n",i.createElement(n.p,null,"The techniques used to increase IPSec network performance are often kept as secrets because they act as a competitive advantage and a lucrative product offering. This talk transparently presents a technique for massively boosting IPSec performance that is simple to implement (less than 200 lines of C), and based entirely on open-source work. An early Proof of Concept (POC) implementation showed an increase in p99 throughput by 412%! This talk will take a deep dive into how it all works, covering: the implementation, the pros and cons of the design, and an analysis of benchmark results. As transparent encryption becomes more crucial for securing data in transit, we hope this talk will enable users required to use IPSec for compliance or infrastru
1cture reasons to learn how to speed up their network without having to compromise their security."),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://colocatedeventsna2024.sched.com/event/1mFPd/live-migrating-production-clusters-from-calico-to-cilium-moh-ahmed-raymond-maika-samsungads"},"Live Migrating Production Clusters From Calico to Cilium - Moh Ahmed & Raymond Maika, SamsungAds")),"\n",i.createElement(n.p,null,"Tuesday, November 12, 2024, 2:40 pm - 3:05 pm MST"),"\n",i.createElement(n.p,null,"Engineers may be tasked with rolling out a new Container Networking Interface (CNI) to their environment. Sounds easy enough! Delete the old one, and deploy the new one. Or maybe just deploy a brand new cluster! What if... there was another way? The talk will show how a live, in-place migration of the CNI plugin was performed in production clusters. It will highlight a few approaches that were considered, and what approach was eventually selected before proceeding with the migration process. Lastly, the procedure and steps taken to execute this migration will be shared, along with any lessons learned."),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://colocatedeventsna2024.sched.com/event/1iztI/hubble-beyond-cilium-anubhab-majumdar-mathew-merrick-microsoft"},"Hubble Beyond Cilium - Anubhab Majumdar & Mathew Merrick, Microsoft")),"\n",i.createElement(n.p,null,"Tuesday, November 12, 2024, 3:20 pm - 3:45 pm MST"),"\n",i.createElement(n.p,null,"Hubble is a great solution for finding and fixing network problems in a Kubernetes cluster. However, we noticed that one of the main barriers for people to use Hubble is its dependency on Cilium as the dataplane. In this talk, we'll demonstrate how to decouple Hubble from Cilium, and use Hubble as a powerful Observability/metrics platform on top of any custom data plane. We will show you how to make Hubble work with any data source you want, without changing any code in Hubble. We'll show you an example of one such open source project called Retina and compare how key features work with both Cilium and custom CNI. In a live demo, we will show that you can get the same experience with Hubble regardless of what CNI you use."),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://colocatedeventsna2024.sched.com/event/1izth/lessons-learned-migrating-to-modern-multi-platform-ebpf-programs-dave-tucker-red-hat"},"Lessons Learned Migrating to Modern Multi-Platform eBPF Programs - Dave Tucker, Red Hat")),"\n",i.createElement(n.p,null,"Tuesday, November 12, 2024, 3:55 pm - 4:20 pm MST"),"\n",i.createElement(n.p,null,"Kepler needed to migrate its old eBPF probes developed with BCC to probes that were compiled ahead of time. Maybe you do too? While performing this migration we were able to use some modern features of eBPF, the cilium/ebpf Go library, and bpf2go to make our probes multi-platform. Kepler (Kubernetes-based Efficient Power Level Exporter) is a CNCF project focused on measuring the environmental impact of software. At its core, Kepler uses eBPF to gather metrics from the Linux Kernel, which feeds into an ML model that estimates power consumption for processes, VMs, and Pods. By the end of this session, youâll gain a deeper understanding of eBPF, practical insights into its application in power consumption monitoring, and strategies for modernizing existing eBPF programs. Join us to learn from our experience and take away actionable best practices for your projects!"),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://colocatedeventsna2024.sched.com/event/1izuW/cl-lightning-talk-dont-get-blown-up-avoiding-configuration-gotchas-for-tetragon-newbies-pratik-lotia-reddit"},"â¡ Lightning Talk: Don't Get Blown up! Avoiding Configuration Gotchas for Tetragon Newbies - Pratik Lotia, Reddit")),"\n",i.createElement(n.p,null,"Tuesday, November 12, 2024, 5:00 pm - 5:10 pm MST"),"\n",i.createElement(n.p,null,"This talk will dive into five common configuration pitfalls that beginners encounter when using Tetragon for runtime observability on their workloads. We'll explore the implications of each gotcha and provide clear steps to avoid them. The talk will also cover best practices for configuring Tetragon in a Kubernetes environment."),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://colocatedeventsna2024.sched.com/event/1izuu/cl-lightning-talk-applying-cilium-at-edge-with-kubeedge-tomoya-fujita-sony-corporation-of-america"},"â¡ Lightning Talk: Applying Cilium at Edge with KubeEdge - Tomoya Fujita, Sony Corporation of America")),"\n",i.createElement(n.p,null,"Tuesday, November 12, 2024, 5:15 pm - 5:25 pm MST"),"\n",i.createElement(n.p,null,"Applications in edge environments can be platform-dependent, complicated, and distributed in regions, and the number of devices significantly increases. Our final goal is to create the infrastru
1cture that can be applied to the entire environment crossing over the cloud and edge in common. Working with KubeEdge and Cilium, we are now successfully able to use Cilium with KubeEdge-hosted nodes at edge environment. This means, that enabling wireguard VPN with Cilium can provide transparent network connectivity with the nodes running in the cloud infrastructure so that edge nodes running at edge environment just appear to be a member of the cluster system but with edge autonomy feature provided by KubeEdge. We would like to share our technical insights and experience with using Cilium at Edge with KubeEdge, and what are the future development and contribution to the Cilium community."),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://colocatedeventsna2024.sched.com/event/1jJ2P/cilium-ebpf-day-closing-remarks"},"Cilium + eBPF Day | Closing Remarks - Bill Mulligan, Isovalent & Vlad Ungureanu, Palantir Technologies")),"\n",i.createElement(n.p,null,"Tuesday, November 12, 2024, 5:25 pm - 5:30 pm MST"),"\n",i.createElement(n.p,null,"The Closing Session for Cilium + eBPF Day NA 2024"),"\n",i.createElement(n.h2,null,"KubeCon + CloudNativeCon"),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://kccncna2024.sched.com/event/1i7lP/cilium-ebpf-wireguard-can-we-tame-the-network-encryption-performance-gap-daniel-borkmann-anton-protopopov-isovalent"},"Cilium, EBPF, WireGuard: Can We Tame the Network Encryption Performance Gap? - Daniel Borkmann & Anton Protopopov, Isovalent")),"\n",i.createElement(n.p,null,"Wednesday, November 13, 2024, 2:30 pm - 3:05 pm MST"),"\n",i.createElement(n.p,null,"To increase data security for cloud and hybrid cloud deployments, many companies, governments, standards, and tenders require data in transit to be protected. However, network encryption comes at a cost - what is the performance impact and how can we reduce it? In this session, we explore how network encryption can be efficiently enforced with Cilium, eBPF, and WireGuard. We dive deep into Ciliumâs integration of WireGuard and elaborate on both the management plane and Ciliumâs eBPF datapath. We analyze and benchmark what performance cost one can expect and explore opportunities in the Linux kernel to reduce that price. This talk is for operators and security teams that need to encrypt network traffic, but also want to minimize its overhead. The audience will walk away understanding whether network encryption needs to come at a high toll and whether there are opportunities for optimizations."),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://kccncna2024.sched.com/event/1i7ma/from-observability-to-enforcement-lessons-learned-implementing-ebpf-runtime-security-anna-kapuscinska-kornilios-kourtis-isovalent"},"From Observability to Enforcement: Lessons Learned Implementing eBPF Runtime Security - Anna KapuÅciÅska & Kornilios Kourtis, Isovalent")),"\n",i.createElement(n.p,null,"Wednesday, November 13, 2024, 5:25 pm - 6:00 pm MST"),"\n",i.createElement(n.p,null,"eBPF is getting widely adopted in cloud native runtime security tools like Falco, KubeArmor, and Tetragon. Using eBPF we can collect relevant security events right in the kernel and pass them to Security Engineers for retroactive attack detection and response. Having reliable and complete visibility is great, but wouldn't it be even better to proactively prevent attacks in progress? This talk covers the Tetragon teamâs experience moving from security observability to enforcement and lessons learned along the way: from defining security models to hardening interactions between the local kernel and distributed Kubernetes systems. It will deep dive into how eBPF-based enforcement works, why it differs from observability, and the challenges of implementing it. The audience will walk away understanding the inner workings and common pitfalls of eBPF-based runtime security."),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://kccncna2024.sched.com/event/1howZ/cilium-connecting-observing-and-securing-kubernetes-and-beyond-with-ebpf-ahmed-bebars-the-new-yor
1k-times-liz-rice-isovalent-cisco-joe-stevens-ascendio"},"Cilium: Connecting, Observing, and Securing Kubernetes and Beyond with eBPF - Ahmed Bebars, The New York Times; Liz Rice, Isovalent @ Cisco; Joe Stevens, Ascend.io")),"\n",i.createElement(n.p,null,"Thursday, November 14, 2024, 11:55 am - 12:30 pm MST"),"\n",i.createElement(n.p,null,"Welcome to Cilium's maintainer track session where you'll get an update on how Cilium is expanding the frontiers of cloud native networking, observability, and security. Cilium is CNCF's most widely adopted CNI, being the default choice for all major cloud providers. This talk dives into the bytecode behind all of the buzz around the project. We'll start with a brief overview of each part of the project before diving into how Cilium is expanding beyond Kubernetes with load balancing and multi-cloud networking and into runtime enforcement with Tetragon. In this session, you'll hear from Cilium contributors and users Isovalent and The New York Times."),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://kccncna2024.sched.com/event/1i7rE/what-agent-to-trust-with-your-k8s-falco-tetragon-or-kubearmor-henrik-rexed-dynatrace"},"What Agent to Trust with Your K8s: Falco, Tetragon, or KubeArmor? - Henrik Rexed, Dynatrace")),"\n",i.createElement(n.p,null,"Thursday, November 14, 2024, 11:55 am - 12:30 pm MST"),"\n",i.createElement(n.p,null,"In the CNCF landscape we have plenty of ebpf-based security solutions that help us protect our k8s cluster from runtime vulnerabilities. On paper though Falco, Tetragon, and KubeArmor look very similar. Eventually, you have to make a choice on which one best fits your needs. To give you additional insights to make your decision join this session. We have run extensive benchmarks against those three solutions and will answer the following questions that came out of our testing: - What are the different feature sets? - What about the performance impact of each agent? - Which privileges does each solution need? - What are the pros and cons of the three options?"),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://kccncna2024.sched.com/#"},"Understanding Kubernetes Networking in 30 Minutes - Ricardo Katz, Broadcom & James Strong, Isovalent at Cisco")),"\n",i.createElement(n.p,null,"Thursday, November 14, 2024 4:30 pm - 5:05 pm MST"),"\n",i.createElement(n.p,null,'You are learning Kubernetes and started to face concepts like Pod CIDRs, Services, CNI, kube-proxy? Welcome! you have reached the amazing area of Kubernetes networking! We all have already been there and know how complex it may seem on the beginning, but in this talk, Ricardo and James will demystify the Kubernetes network concepts and model on a fun way, exploring how it is designed, why the is a "pause" container on every Pods, how the communication between Pods work, what are kube-proxy and CNI and their importance. In the end of this talk we expect you to get your learning path on Kubernetes Networking clear to better understand not only what are the concepts about, but also see on a live demo how every component correlates and makes the communications possible on a Kubernetes cluster .'),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://kccncna2024.sched.com/event/1hoyj/contribfest-kickstart-your-ebpf-journey-with-tetragon"},"ð¨ Contribfest: Kickstart Your eBPF Journey with Tetragon")),"\n",i.createElement(n.p,null,"Thursday, November 14, 2024, 4:30 pm - 6:00 pm MST"),"\n",i.createElement(n.p,null,"Tetragon and eBPF have a lot of buzz and this is your chance to get involved diving into the bytecode or docs! Tetragonâs docs are still young and your new contributor's perspective will be a superpower for spotting issues or unclear wording in the various quickstarts, guides, and concepts pages. The projectâs CLI, tetra, is another great opportunity for those interested in code contributions around ease of use, testing, and consistency in flags and output. Tetragonâs documentation tech stack uses Markdown, built with Hugo, and a customized Docsy theme. The CLI is written in Go with the Cobra library and uses gRPC to communicate with the agent. While this session should help you get more familiar with Tetragon and can lead to more contributions in the future, those technologies are also used in Kubernetes and many other CNCF projects."),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://kccncna2024.sched.com/event/1i7pZ/pick-my-project-lessons-learned-from-interviewing-20-end-users-for-cloud-native-case-studies-shedrack-akintayo-bill-mulligan-isovalent-at-cisco"},"Pick My Project! Lessons Learned from Interviewing 20+ End Users for Cloud Native Case Studies - Shedrack Akintayo & Bill Mulligan, Isovalent at Cisco")),"\n",i.createElement(n.p,null,"Thursday, November 14, 2024, 5:25 pm - 6:00 pm MST"),"\n",i.createElement(n.p,null,"Cloud native projects can promise the moon
1in their READMEs, but have you ever wondered what causes end users to adopt a project? Shedrack and Bill have interviewed over 20 companies in industries ranging from media to financial services about why they picked a project for their cloud native platform. In this talk, they will reveal what end users truly want when adopting cloud native technologies and what the forcing function is for each of them. Youâll hear firsthand accounts of the triumphs and tribulations faced by companies like Bloomberg, DigitalOcean, The New York Times, and more as well as the specific benefits these organizations are reaping, from enhanced security and observability to improved performance and cost savings. Additionally, theyâll teach other projects their process for creating impactful case studies. By the end, the audience will understand the real-world applications and advantages of cloud native technologies and why end users pick a project."),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://kccncna2024.sched.com/event/1i7qG/seeing-double-implementing-multicast-with-ebpf-and-cilium-louis-delossantos-isovalent-at-cisco"},"Seeing Double? Implementing Multicast with eBPF and Cilium - Louis DeLosSantos, Isovalent at Cisco")),"\n",i.createElement(n.p,null,"Friday, November 15, 2024, 11:55 am - 12:30 pm MST"),"\n",i.createElement(n.p,null,"Multicast is a popular networking technology used in finance, telecommunications, and media CDNs, among others to efficiently replicate and deliver data streams to multiple clients. However, this advantage can be overshadowed by the complexity involved in configuring the necessary infrastructure leaving the overworked platform team rather than the end users seeing double. To combat this complexity, Cilium explored using eBPF to implement pod-to-pod multicast delivery within a Kubernetes cluster. This talk will provide both a high and low-level understanding of how eBPF can be used to implement multicast delivery. It will discuss how Ciliumâs multicast works and the hurdles faced by the project along the way. By the end of this talk, the audience will have a better understanding of how multicast functions, how eBPF can be used in place of traditional multicast infrastructure, and how Cilium can be used as a multicast-enabled CNI, letting your audience - and not you- see double."),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://kccncna2024.sched.com/event/1i7qS/micro-segmentation-and-multi-tenancy-the-brown-mms-of-platform-engineering-jim-bugwadia-nirmata-rachael-wonnacott-fidelity-international?iframe=no"},"Micro-Segmentation and Multi-Tenancy: The Brown M&Ms of Platform Engineering")),"\n",i.createElement(n.p,null,"Friday November 15, 2024 2:00pm - 2:35pm MST"),"\n",i.createElement(n.p,null,"A key requirement for internal developer platforms is that they serve multiple workloads. The reality of platform engineering is that while it seeks to lower the barrier to entry for teams to deliver applications, it must also balance cost and ensure appropriate levels of security. Itâs therefore essential to consider how application components running on shared infrastructure are allowed to communicate with each other and weigh up the cost of each architecture. In industry, we have seen differing approaches to deploying Kubernetes to achieve these goals, from multiple single-tenant clusters through to shared clusters that deliver namespaces-as-a-service. Rachael and Jim will define the concepts of multi-tenancy and micro-segmentation for cloud native systems, explain why they are critical to success with platform engineering. They will also show real-world examples of how they can be implemented, and demonstrate full automation using best practices like GitOps and Policy as Code."),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://kccncna2024.sched.com/event/1i7qb"},"Seccomp and eBPF; Whatâs the Difference? Why Do I Need to Know? - Natalia Reka Ivanko & Duffie Cooley, Isovalent @ Cisco")),"\n",i.createElement(n.p,null,"Friday, November 15, 2024, 2:00 pm - 2:35 pm MST"),"\n",i.createElement(n.p,null,"Containers in Kubernetes share a common Linux kernel so how can we limit access where it isnât required so we can follow the principle of least privilege? Join Natalia and Duffie as they each explore different approaches to harden your container security with Secure Computing (seccomp) and eBPF! The talk will begin with an overview and comparison between seccomp and eBPF and how they both can solve the same problem - limiting access to the Linux Kernel that all c
1ontainers share. This will be a fun talk, showing each solution with a live demo. You will leave this talk with a better understanding of how to limit what system calls a process can make and restrict your containersâ behavior to only access the files, binaries and external DNS names they need and nothing more. Which is the right solution for your environment? Come and learn about two of the commonly used technologies in use today!"),"\n",i.createElement(n.p,null,i.createElement(n.a,{href:"https://kccncna2024.sched.com/#"},"The Key Value of Etcd Over Custom Resources: Scalability - Jef Spaleta, Isovalent at Cisco")),"\n",i.createElement(n.p,null,"Friday, November 15, 2024 2:55 pm - 3:30 pm MST"),"\n",i.createElement(n.p,null,"Cilium defaults to using Kubernetes Custom Resources to hold Cilium specific internal state, however when the cluster is large enough, the Kubernetes API becomes a bottleneck on performance. To scale a cluster to hundreds of nodes, Cilium can be configured to use a dedicated external etcd instance. This talk will discuss the details of what the external etcd looks like from an operator perspective, and explore why Cilium uses an external etcd for enhanced scalability. It will cover how to manage a cluster by bypassing the Kubernetes API and interacting only with the cluster's etcd key-value store - and also why it might be a bad idea. Get a taste of what's possible by bypassing the Kubernetes API and interacting with the etcd API directly, and learn why Cilium has an option to use a dedicated etcd deployment, not shared by the Kubernetes API, for holding Cilium state and the scalability benefits it can bring to your cluster."),"\n",i.createElement(t,o.A.ShedrackAkintayo))}var s=function(e){void 0===e&&(e={});const{wrapper:n}=Object.assign({},(0,a.RP)(),e.components);return n?i.createElement(n,e,i.createElement(r,e)):r(e)};var l=t(8125),c=t(5805),u=t(8838),d=t(2744);const m=e=>{const{data:{mdx:n},children:t}=e,{frontmatter:{path:a,title:o,date:r,tags:s,ogSummary:u}}=n;return i.createElement(d.A,{headerWithSearch:!0},i.createElement(l.A,{path:a,content:t,date:r,title:o,tags:s,summary:u}),i.createElement(c.A,{className:"my-10 md:my-20 lg:my-28"}))},h=e=>{var n,t;let{data:{mdx:a,site:o},location:{pathname:r}}=e;const{frontmatter:{title:s,ogImage:l,ogSummary:c,dateIso:d,tags:m,author:h}}=a,{siteUrl:p}=o.siteMetadata,g=`${c.slice(0,133)}...`,f=`${p}${r}`,b=null!=l&&null!==(n=l.childImageSharp)&&void 0!==n&&null!==(t=n.resize)&&void 0!==t&&t.src?`${p}${l.childImageSharp.resize.src}`:null,y={title:s,description:g,image:l||null,slug:r},w={"@context":"https://schema.org","@type":"BlogPosting",headline:s,description:g,url:f,datePublished:d,dateModified:d,author:h?{"@type":"Person",name:h}:{"@type":"Organization",name:"Cilium",url:p},publisher:{"@type":"Organization",name:"Cilium",url:p,logo:{"@type":"ImageObject",url:`${p}/images/social-preview.jpg`}},...b&&{image:{"@type":"ImageObject",url:b,width:1200,height:630}},...(null==m?void 0:m.length)>0&&{keywords:m.join(", ")}};return i.createElement(u.A,{data:y,type:"article",datePublished:d,jsonLd:w})};function p(e){return i.createElement(m,e,i.createElement(s,e))}}}]); 2//# sourceMappingURL=component---src-templates-blog-post-jsx-content-file-path-src-posts-2024-10-04-cilium-talks-at-kubecon-na-2024-index-md-d88ad8e25236f145ab4c.js.map
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.