PageSourceSearch

https://cilium.io/component---src-templates-blog-post-jsx-content-…-cilium-17-index-md-8842fa9b950e1f74c4e6.js

js cilium.io collected 2026-09-24 08:29:51 UTC 90,398 bytes, 2 lines download raw bytes

1"use strict";(self.webpackChunkcilium_io=self.webpackChunkcilium_io||[]).push([[9031],{452:function(e,n,t){t.r(n),t.d(n,{Head:function(){return u},default:function(){return m}});var a=t(8453),l=t(6540);function i(e){const n=Object.assign({span:"span",p:"p",ul:"ul",li:"li",strong:"strong",a:"a",h2:"h2",em:"em",h3:"h3"},(0,a.RP)(),e.components),{YoutubeIframe:t}=n;return t||function(e,n){throw new Error("Expected "+(n?"component":"object")+" `"+e+"` to be defined: you likely forgot to import, pass, or provide it.")}("YoutubeIframe",!0),l.createElement(l.Fragment,null,l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 1008px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/46b6910730789a2ff19fe8f3ba202e7a/96ad1/ogimage.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 59.12698412698413%; position: relative; bottom: 0; left: 0; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/46b6910730789a2ff19fe8f3ba202e7a/2ff5b/ogimage.webp 252w,\n/static/46b6910730789a2ff19fe8f3ba202e7a/4d583/ogimage.webp 504w,\n/static/46b6910730789a2ff19fe8f3ba202e7a/905a7/ogimage.webp 1008w,\n/static/46b6910730789a2ff19fe8f3ba202e7a/bb9f8/ogimage.webp 1512w,\n/static/46b6910730789a2ff19fe8f3ba202e7a/83a93/ogimage.webp 2016w,\n/static/46b6910730789a2ff19fe8f3ba202e7a/71b50/ogimage.webp 3584w"\n              sizes="(max-width: 1008px) 100vw, 1008px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/46b6910730789a2ff19fe8f3ba202e7a/019e0/ogimage.png 252w,\n/static/46b6910730789a2ff19fe8f3ba202e7a/0dcb2/ogimage.png 504w,\n/static/46b6910730789a2ff19fe8f3ba202e7a/832a9/ogimage.png 1008w,\n/static/46b6910730789a2ff19fe8f3ba202e7a/19357/ogimage.png 1512w,\n/static/46b6910730789a2ff19fe8f3ba202e7a/29ed2/ogimage.png 2016w,\n/static/46b6910730789a2ff19fe8f3ba202e7a/96ad1/ogimage.png 3584w"\n            sizes="(max-width: 1008px) 100vw, 1008px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/46b6910730789a2ff19fe8f3ba202e7a/832a9/ogimage.png"\n            alt="Introduction"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",l.createElement(n.p,null,"We are excited to announce the Cilium 1.7 release. A total of 1551 commits have\nbeen contributed by a community of 141 developers, many of whom made their\nfirst contributions this cycle. Cilium 1.7 brings with it a trove of exciting\nnew features:"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"Hubble:")," We've heard lots of positive feedback on Hubble since the\n",l.createElement(n.a,{href:"/blog/2019/11/19/announcing-hubble"},"announcement"),". To make\ncluster connectivity easier to visualize and debug, we've released a new\nHubble UI as open source so you can tweak and extend it too! We've also been\nworking on various improvements to the core Hubble implementation, including\nbetter correlation between network flow data and Kubernetes resources.\n(",l.createElement(n.a,{href:"#hubble"},"More details"),")"),"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"Cilium Cluster-wide Network Policies:")," The 1.7 release brings the\nmuch-anticipated Cluster-wide CNP feature. This allows users to apply\nbaseline network policies which apply to pods across the cluster, regardless\nof the namespace that the pod resides in.\n(",l.createElement(n.a,{href:"#ccnp"},"More details"),")"),"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"Kube-proxy replacement with Direct Server Return:")," As presented at\n",l.createElement(n.a,{href:"https://www.youtube.com/watch?v=bIRwSIwNHC0"},"Kubecon US 2019")," and ",l.createElement(n.a,{href:"https://fosdem.org/2020/schedule/event/containers_bpf/"},"FOSDEM 2020"),", this release rounds out the full service\nfeature set for replacing kube-proxy and additionally adds support for Direct Server\nReturn (DSR). This further improves the latency and performance of the kube-proxy\nreplacement in Cilium. Moreover, our kube-proxy replacement comes out of\nbeta and is automatically enabled in environments with newer kernels.\n(",l.createElement(n.a,{href:"#kubeproxy-removal"},"More details"),")"),"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"Extending L7 policies with TLS introspection:")," We've added supp
1ort to\nCilium to configure Envoy TLS certificates via Kubernetes resources or local\nfiles. This allows Cilium to transparently observe HTTP calls and enforce\nAPI-aware policies on TLS-encrypted sessions.\n(",l.createElement(n.a,{href:"#tls-visibility"},"More details"),")"),"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"L7 visibility annotations for pods:")," Previously, to gain L7 visibility\ninto traffic in the cluster, users would need to write network policies that\nput pods into a default deny posture. Visibility annotations now allow users\nto gain L7 visibility into network traffic first, then subsequently craft\nfull network policies using these insights.\n(",l.createElement(n.a,{href:"#visibility-annotations"},"More details"),")"),"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"Pure Go eBPF library:")," This is the first Cilium release to begin using the\npure Go eBPF library co-written between the Cilium community and CloudFlare.\nThis streamlined library already allowed Cilium to jettison CGo, improving\nperformance and reducing binary sizes.\n(",l.createElement(n.a,{href:"#pure-go-ebpf-library"},"More details"),")"),"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"Improvements to scalability")," through ",l.createElement(n.a,{href:"#endpoint-slice"},"Kubernetes EndpointSlice support")," and\n",l.createElement(n.a,{href:"#scalability"},"Cilium agent improvements"),", development on ",l.createElement(n.a,{href:"#upstream-linux"},"upstream Linux"),",\nrunning our ",l.createElement(n.a,{href:"#managed-ci"},"testing environment on managed Kubernetes"),",\n",l.createElement(n.a,{href:"#helm"},"distributing Cilium via Helm repositories"),"... ",l.createElement(n.strong,null,"and much more!"),"\nFor more highlights, see the ",l.createElement(n.a,{href:"#17Highlights"},"1.7 Release Highlights"),"."),"\n"),"\n",l.createElement(n.h2,null,"What is Cilium?"),"\n",l.createElement(n.p,null,"Cilium is open source software for transparently providing and securing the\nnetwork and API connectivity between application services deployed using Linux\ncontainer management platforms such as Kubernetes."),"\n",l.createElement(n.p,null,"At the foundation of Cilium is a new Linux kernel technology called eBPF, which\nenables the dynamic insertion of powerful security, visibility, and networking\ncontrol logic within Linux itself. eBPF is utilized to provide functionality\nsuch as multi-cluster routing, load balancing to replace kube-proxy,\ntransparent encryption as well as network and service security. Besides\nproviding traditional network level security, the flexibility of eBPF enables\nsecurity with the context of application protocols and DNS requests/responses.\nCilium is tightly integrated with Envoy and provides an extension framework\nbased on Go. Because eBPF runs inside the Linux kernel, all Cilium\nfunctionality can be applied without any changes to the application code or\ncontainer configuration."),"\n",l.createElement(n.p,null,"See the section ",l.createElement(n.strong,null,l.createElement(n.a,{href:"https://cilium.readthedocs.io/en/stable/intro/"},"Introduction to Cilium"))," for a more detailed general\nintroduction to Cilium."),"\n",l.createElement(n.h2,null,"New ",l.createElement(n.a,{href:"https://github.com/cilium/cilium/blob/master/USERS.md"},"USERS.md")," file: Who is using Cilium?"),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">* N: Adobe, Inc.\n  D: Adobe\'s Project Ethos uses Cilium for multi-tenant, multi-cloud clusters\n  U: L3/L4/L7 policies\n  L: https://youtu.be/39FLsSc2P-Y\n\n* N: CENGN - Centre of Excellence in Next Generation Networks\n  D: CENGN is using Cilium in multiple clusters including production and development clusters (self-hosted k8s, On-premises)\n  U: L3/L4/L7 network policies, Monitoring via Prometheus metrics &amp; Hubble\n  L: https://www.youtube.com/watch?v=yXm7yZE2rk4\n  Q: @rmaika @mohahmed13\n\n* N: Datadog\n  D: Datadog is using Cilium in AWS (self-hosted k8s)\n  U: ENI Networking, Service load-balancing, Encryption\n  Q: @lbernail, @roboll\n[...]</code></pre></div>'}}),"\n",l.createElement(n.p,null,"(",l.createElement(n.a,{href:"https://github.com/cilium/cilium/blob/master/USERS.md"},"Full USERS.md file"),")"),"\n",l.createElement(n.p,null,"Sharing experiences and learning from other users is essential. We are\nfrequently asked who is using a particular feature of Cilium to get in contact\nwith other users to share experiences and best-practices. While the Cilium\nSlack community allows users to get in touch, it can be challenging to find\nusers of a particular feature quickly."),"\n",l.createElement(n.p,null,"If you are using Cilium, please consider ",l.createElement(n.a,{href:"https://github.com/cilium/cilium/edit/master/USERS.md"},"adding yourself as a user")," with a quick\ndescription of your use case by opening a pull request to this file and adding\na section describing your usage of Cilium. If you are open to others contacting\nyou about your use of Cilium on Slack, add your Slack nick as well."),"\n",l.createElement("a",{name:"hubble"}),"\n",l.createElement(n.h2,null,"Hubble"),"\n",l.createElement(n.p,null,l.createElement(n.em,null,"Contributed by Sebastian Wicki and 
1Sergey Generalov")),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 1008px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/aa2f9af8628edc26f6c8473854d97a8a/6190c/hubble-arch.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 76.98412698412697%; position: relative; bottom: 0; left: 0; background-image: url(\'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAPCAYAAADkmO9VAAAACXBIWXMAABYlAAAWJQFJUiTwAAAC+0lEQVR42mWUWW/bVhCF8+cLFAiCvjZA0wDtQ1O4QFsUcePAdVxHthxXjkWtlkRqoxZSJMVNtmSR934dSU7quPNASnNmzp1z54BPkFBaE0QxlWqVwWjMcp1t0gRBQLvdwTQtavUGnudt89PpdJtvtdtUazWGts2neKKUYiYFfqvJTACvfc1Ufsdxwtzz6ZstrhsGQ7ODO5lws7ihZ7VoNSsMO2186fUkH4XhjnCdK/xhF46fkdk1lnsviff3CKUx9ueYtRJPn35Fo2QQeS5RlGDVL/nm2dcY51f4Y5tKqUQoaraEWZ4z6vcYGK/x+9ckpTOc85OtXN91aV595N2bA4xyC3c8Zj6fY1x84PjgLacfqnQ7Ju1qBX822xFuHnEUCUGKPRjiOA6B3NXNYsEiTZnJ/55l4Trutm61WuGIxE1N1+oSygGxyF3e3v5H+Ck2xUkcClFCkkTMXIdESF2ZNIpjyUk+jlgsUjkwYSITa1now9gS7pKaLNc4keKwltH3cqauj1LZDteKu0wRpDlHjYzWZIdryT8k/TzhYqUJbzTxTc5vhTFOuMYchnipNAh+e6eZL0SFvP8oTug6Syw7wI2V2O7RhOlSU+7nXPZyTEfhtD8yKJ8wqpzRq1elSWMMckrdDFPuftqp0r88ErzISOzjzldfEka3mgsz58fCnchVDK4Oqbx5iVX4mUHpAC/RnHdyXhVXHNSgVy5g7H9H5/0e06t9HP/2nk7fb1kI/+nm/Fpac26C3fwL6/QHxo3XjK9PtoQXVs7vpTvOLOg3z+gUvmdU28czj5kGyy8JI7m7Yjvnl4s17+q5mLXI+d/PqRdf4HQPZVGao1bOT4L/2ZADh5eUTr7FOH1BOHzL+PGEmwtvTRR1W2EHmjQeM7HLDHsGfbsny9A0p4rySGH5oih2BL/C7hsMbIsgyf6/5VWmt9KCVMvHQaYWFW662f4OX4ulfMH8ZIfH93i6Av3Yhw8jkY1PQiUWUp/9+dC7G3tt8EDspNQOf2jsfwGKXV6rtyR7JgAAAABJRU5ErkJggg==\'); background-size: cover; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/aa2f9af8628edc26f6c8473854d97a8a/2ff5b/hubble-arch.webp 252w,\n/static/aa2f9af8628edc26f6c8473854d97a8a/4d583/hubble-arch.webp 504w,\n/static/aa2f9af8628edc26f6c8473854d97a8a/905a7/hubble-arch.webp 1008w,\n/static/aa2f9af8628edc26f6c8473854d97a8a/bb9f8/hubble-arch.webp 1512w,\n/static/aa2f9af8628edc26f6c8473854d97a8a/b1c39/hubble-arch.webp 1944w"\n              sizes="(max-width: 1008px) 100vw, 1008px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/aa2f9af8628edc26f6c8473854d97a8a/019e0/hubble-arch.png 252w,\n/static/aa2f9af8628edc26f6c8473854d97a8a/0dcb2/hubble-arch.png 504w,\n/static/aa2f9af8628edc26f6c8473854d97a8a/832a9/hubble-arch.png 1008w,\n/static/aa2f9af8628edc26f6c8473854d97a8a/19357/hubble-arch.png 1512w,\n/static/aa2f9af8628edc26f6c8473854d97a8a/6190c/hubble-arch.png 1944w"\n            sizes="(max-width: 1008px) 100vw, 1008px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/aa2f9af8628edc26f6c8473854d97a8a/832a9/hubble-arch.png"\n            alt="Hubble Architecture"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",l.createElement(n.p,null,"The development cycle of Cilium 1.7 coincided with the\n",l.createElement(n.a,{href:"/blog/2019/11/19/announcing-hubble"},"a first preview release of Hubble"),"\n-- an observability tool specifically designed for Cilium. Hubble is able to\nobtain deep visibility into the network traffic of Kubernetes application and\nservices by tapping into Cilium's eBPF data path. This information can then be\nqueried via Hubble CLI and UI, for example for\n",l.createElement(n.a,{href:"/blog/2019/12/18/how-to-debug-dns-issues-in-k8s"},"interactive troubleshooting of DNS issues"),".\nFor monitoring, Hubble provides an extensible metrics framework which\nintegrates nicely into Prometheus and Grafana. For more information please refer\nto the ",l.createElement(n.a,{href:"https://github.com/cilium/hubble/tree/master/tutorials/deploy-hubble-and-grafana"},"tutorial on setting up Hubble Metrics with Grafana"),"."),"\n",l.createElement(n.p,null,"Several features in Cilium 1.7 have been added with Hubble in mind: The\n",l.createElement(n.a,{href:"#visibility-annotations"},"L7 visibility annotations for pods")," for example allows\nHubble to extract application-layer information from DNS and HTTP traffic.\nThe ",l.createElement(n.a,{href:"https://docs.cilium.io/en/v1.7/api/"}
1,"Cilium API")," has also been extended in\nthis release to allow Hubble to annotate the observed network flows with\nadditional meta-data, such as mapping Kubernetes ClusterIPs to their respective\nservice names."),"\n",l.createElement("a",{name:"hubble-ui"}),"\n",l.createElement(n.h3,null,"Hubble UI"),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 1008px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/2e1ecf6fa94e4a3450155a4660881927/81437/servicemap.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 42.46031746031746%; position: relative; bottom: 0; left: 0; background-image: url(\'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAYAAAD5nd/tAAAACXBIWXMAABYlAAAWJQFJUiTwAAABPklEQVR42k1S2W4EMQib///RSt20kwtCrqGGrFZ9QCQBbAO5as+aatTWWfsUeILnj8kw37SbX6JjtRMbx+Rt50x6EYuGQNoa61pLqRUHZiEHHzj30byocES8+r2/iebuOrb4WUB0CYpqzZpzUgao3QuRk4g03fsBeEUXSb++g6aUQDJh3RXdMWhMv05spFfrgqSqzITi7QpNnd1rLe7H6q6KGSopK1HFmyCX9PcuOkHwPA9yxFpmjfEAiIgnCtjuXFzhXNMVmr1C0LUnbPndOolxOuBa21Wi5aYJ7VYCAM4MhRUk4eeoHmO4usoAfCGvVpUmZ7aYW0EXuZx6y7sIwfvGgNH6BouBDiTaQgggTc5i7I24gDwCJPviDHCs05XFfYbcTXrxJNugbUomufdvM893cLO397f5vP2zNkj/AH38bjVoYepfAAAAAElFTkSuQmCC\'); background-size: cover; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/2e1ecf6fa94e4a3450155a4660881927/2ff5b/servicemap.webp 252w,\n/static/2e1ecf6fa94e4a3450155a4660881927/4d583/servicemap.webp 504w,\n/static/2e1ecf6fa94e4a3450155a4660881927/905a7/servicemap.webp 1008w,\n/static/2e1ecf6fa94e4a3450155a4660881927/bb9f8/servicemap.webp 1512w,\n/static/2e1ecf6fa94e4a3450155a4660881927/83a93/servicemap.webp 2016w,\n/static/2e1ecf6fa94e4a3450155a4660881927/81130/servicemap.webp 2576w"\n              sizes="(max-width: 1008px) 100vw, 1008px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/2e1ecf6fa94e4a3450155a4660881927/019e0/servicemap.png 252w,\n/static/2e1ecf6fa94e4a3450155a4660881927/0dcb2/servicemap.png 504w,\n/static/2e1ecf6fa94e4a3450155a4660881927/832a9/servicemap.png 1008w,\n/static/2e1ecf6fa94e4a3450155a4660881927/19357/servicemap.png 1512w,\n/static/2e1ecf6fa94e4a3450155a4660881927/29ed2/servicemap.png 2016w,\n/static/2e1ecf6fa94e4a3450155a4660881927/81437/servicemap.png 2576w"\n            sizes="(max-width: 1008px) 100vw, 1008px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/2e1ecf6fa94e4a3450155a4660881927/832a9/servicemap.png"\n            alt="Hubble UI Service Map"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",l.createElement(n.p,null,"Hubble UI enables zero-effort automatic discovery of the service dependency graph for Kubernetes Clusters at L3/L4 and even L7, allowing user-friendly visualization and filtering of those dataflows as a Service Map. First presented during ",l.createElement(n.a,{href:"/blog/2019/11/19/announcing-hubble"},"the Hubble announcement"),", we provided users with a preview release docker image, allowing everyone to try ",l.createElement(n.a,{href:"https://github.com/cilium/hubble/blob/master/tutorials/deploy-hubble-servicemap/README.md"},"Hubble Service Map in a Minikube")," while working on open sourcing the code itself."),"\n",l.createElement(n.p,null,"We are happy to announce, Hubble UI code is now open sourced and available under Cilium's GitHub organization: ",l.createElement(n.a,{href:"https://github.com/cilium/hubble-ui"},"https://github.com/cilium/hubble-ui")),"\n",l.createElement(n.p,null,"During Cilium 1.7 development cycle several performance improvements were made to Hubble UI to work better in small multi-node cluster
1s; however we still consider Hubble UI in preview release stage and encourage the community to provide feedback on ",l.createElement(n.a,{href:"https://github.com/cilium/hubble/issues"},"Hubble Github page")," or ",l.createElement(n.a,{href:"https://slack.cilium.io"},"Cilium Slack #hubble channel"),"."),"\n",l.createElement("a",{name:"ccnp"}),"\n",l.createElement("a",{name:"cilium-cluster-wide-network-policies"}),"\n",l.createElement(n.h2,null,"Cilium Cluster-wide Network Policies"),"\n",l.createElement(n.p,null,l.createElement(n.em,null,"Contributed by Deepesh Pathak and André Martins")),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 1008px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/b0e982bfc594fbaa808889e84c31ad25/85912/ccnp.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 38.49206349206349%; position: relative; bottom: 0; left: 0; background-image: url(\'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAYAAAD5nd/tAAAACXBIWXMAABYlAAAWJQFJUiTwAAABjUlEQVR42nWQC2/SYBSG9/9/xuKmggsFotvoShn0Qks/WqCVqx1QKQILuzgcMxuPxXhJUN7kTU7OyXnynnOw2fBTauuRI3WG1uhT8kYEX14Ipjve9uLv+J9XNKMV4fyRX+t/dPC70LsPnDdv8cZfsYI+jnOBcFUcUaQmFJy6ihAXuIFHY7LGHT8QTFY8v2z+BW5b4eIbVv+acnDNpfeJkmmiizqGsKnWayiGTlGvULQ8zP491d4SP7pjh/c3YXe6RjbqyOo5SqVMxa7hdbqIcIkiQuTyJYq2hWrYnoPojRCDxT7ghv7sibxqksoekZIOSWUOyXxIY7QSmPWRt9Ib0tlXvMsfc5K4oJt4Vzf/P3mr3nTFmRORMcaceXPk1g3v3ZhKO6boXpG1huSsEZI2opDMjHCFGy4S4J6E7dmaU6WGdJxDtT3KjRZSLkv+VKaQJHydPyFTkElLWUq6S0lrYndinvf9MFo+YXenWP4I0w/RmwOsVkStPUl+NcfwI6rtxJ0hVX+IVh/Qi2/Z1Q9vbD6q2zdO7AAAAABJRU5ErkJggg==\'); background-size: cover; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/b0e982bfc594fbaa808889e84c31ad25/2ff5b/ccnp.webp 252w,\n/static/b0e982bfc594fbaa808889e84c31ad25/4d583/ccnp.webp 504w,\n/static/b0e982bfc594fbaa808889e84c31ad25/905a7/ccnp.webp 1008w,\n/static/b0e982bfc594fbaa808889e84c31ad25/bb9f8/ccnp.webp 1512w,\n/static/b0e982bfc594fbaa808889e84c31ad25/83a93/ccnp.webp 2016w,\n/static/b0e982bfc594fbaa808889e84c31ad25/9d2d4/ccnp.webp 2218w"\n              sizes="(max-width: 1008px) 100vw, 1008px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/b0e982bfc594fbaa808889e84c31ad25/019e0/ccnp.png 252w,\n/static/b0e982bfc594fbaa808889e84c31ad25/0dcb2/ccnp.png 504w,\n/static/b0e982bfc594fbaa808889e84c31ad25/832a9/ccnp.png 1008w,\n/static/b0e982bfc594fbaa808889e84c31ad25/19357/ccnp.png 1512w,\n/static/b0e982bfc594fbaa808889e84c31ad25/29ed2/ccnp.png 2016w,\n/static/b0e982bfc594fbaa808889e84c31ad25/85912/ccnp.png 2218w"\n            sizes="(max-width: 1008px) 100vw, 1008px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/b0e982bfc594fbaa808889e84c31ad25/832a9/ccnp.png"\n            alt="Cluster-wide Network Policies"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",l.createElement(n.p,null,"This release introduces Cilium Cluster-wide Network Policies (CCNP). Prior to\nCilium 1.7, all Cilium network policies were namespaced, so there was no easy\nway to configure a baseline policy that applies across the entire cluster.\nCluster-wide policies streamline the application of a standard default posture\nby allowing the cluster maintainer to apply a single policy which applies to\npods in all namespaces, regardless of the policies that exist in individual\nnamespaces. Cluster-wide policies are essential in various cases, such as:"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"Automatically applying a default-deny policy to all namespaces as they're\ncreated;"),"\n",l.createElement(n.li,null,"Allowing requests to a baseline set of allowed destinations like kube-dns,\nDNS destinations used by all apps, or known IP ranges;"),"\n",l.createElement(n.li,null,"Reducing management overhead of network policies in high-scale environments."),"\n"),"\n",l.createElement(n.p,null,"The ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">CiliumClusterwideNetworkPolicy</code>'}})," resource specification is the same as that\nof existing ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">CiliumNetworkPolicy</code>'}}),' CRD with the only difference in the scope of\nthe policy, denoted by the "kind" field in the YAML. Resource-based Access\nControl (RBAC) can be defined separately for CCNP so users modifying policies\nin one namespace won\'t roll back the baseline policies. The policy example\nbelow grants any pod with the label ',l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">group: my-app</code>'}})," in the entire cluster the\nprivilege to perform DNS requests via kube-dns:"),"\n",l.createElement(n.h3,null,"Policy Example"),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="yaml"><pre class="language-yaml"><code class="language-yaml"><span class="token key atrule">apiVersion</span><span class="token punctuation">:</span> <span class="token string">\'cilium.io/v2\'</span>\n<span class="token key atrule">kind</span><span class="token punctuation">:</span> CiliumClusterwideNetworkPolicy\n<span class="token key atrule">description</span><span class="token punctuation">:</span> <span class="token string">\'Default deny and allow egress to kube-dns pod.\'</span>\n<span class="token key atrule">metadata</span><span class="token punctuation">:</span>\n  <span class="token key atrule">name</span><span class="token punctuation">:</span> <span class="token string">\'clusterwide-policy-example\'</span>\n<span class="token key atrule">spec</span><span class="token punctuation">:</span>\n  <span class="token key atrule">endpointSelector</span><span class="token punctuation">:</span>\n    <span class="token key atrule">matchLabels</span><span class="token punctuation">:</span>
1\n      <span class="token key atrule">group</span><span class="token punctuation">:</span> my<span class="token punctuation">-</span>app\n  <span class="token key atrule">egress</span><span class="token punctuation">:</span>\n    <span class="token punctuation">-</span> <span class="token key atrule">toEndpoints</span><span class="token punctuation">:</span>\n        <span class="token punctuation">-</span> <span class="token key atrule">matchLabels</span><span class="token punctuation">:</span>\n            <span class="token key atrule">\'k8s:io.kubernetes.pod.namespace\'</span><span class="token punctuation">:</span> kube<span class="token punctuation">-</span>system\n            <span class="token key atrule">k8s-app</span><span class="token punctuation">:</span> kube<span class="token punctuation">-</span>dns\n      <span class="token key atrule">toPorts</span><span class="token punctuation">:</span>\n        <span class="token punctuation">-</span> <span class="token key atrule">ports</span><span class="token punctuation">:</span>\n            <span class="token punctuation">-</span> <span class="token key atrule">port</span><span class="token punctuation">:</span> <span class="token string">\'53\'</span></code></pre></div>'}}),"\n",l.createElement(n.p,null,"With the new Kubernetes CRD introduced in this release for cluster-wide policy,\nit's now simpler to create network policies which apply to the entire cluster."),"\n",l.createElement("a",{name:"kubeproxy-removal"}),"\n",l.createElement(n.h2,null,"Kube-proxy replacement with Direct Server Return"),"\n",l.createElement(n.p,null,l.createElement(n.em,null,"Contributed by Martynas Pumputis, Daniel Borkmann, Sebastian Wicki and André Martins")),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 960px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/2ee1b50a2a6e0a672e1292bb826c165e/7d769/dsr.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 56.34920634920635%; position: relative; bottom: 0; left: 0; background-image: url(\'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAIAAADwazoUAAAACXBIWXMAAAsTAAALEwEAmpwYAAACL0lEQVR42m1RWW8SYRSdv2mMjypV0UjUshUDlKEwhKUsBRwHStlCXKABFGhZnCEMDBTC6sADsSRAhJCImKBsXiFp+uB5+HJv7jn3npwPWa/Xm83miqFjIV/i3O80obhB9tFjWyz+bLaYTCaNRoNhmHK5XCwWS6VStVqt1Wrz+RyB8Y/pTy0qNkj2fEaJGd03oHyfHSuWGBgBg6bpTCaTTCbr9TrULMvCImhbrRYynU7tNqNVJyP0Uq9ViUmeqg+4x4cvzCohQ2fZdptlvwIoisrlcolEIp/PDwaD4XBIkiRCM3mtUkiFT+PvcY8Nw8RcdJ+j5O+9s8oJ3Ji4uBiNRpVKBQ7C2+l04CzsGo/HhUIBMejVOlTwRiNS8h/I+Y+lrx7p5C+PJM9PjTLHiVpv0IPVdDoNVHipLbLZbDAY7Pf7yLP7d3QSjlFyjzAfycQ8LSo6syiIY3kA1wRwLBj6EA5HIKdms9nr9cAtiFOpVLfbhUQQIY+jPXjoVNw9d2HYa65NJ/PaVZC5XinwvtV6fG6fzw/xgNVd1OB8Nputt0AcLscJbnbier/HbtEprJjIZToMe82fLqNfmCzhIECw+87fW+zq1Wr173KtXgvGI4QVJTRPjAqeViEwaaSxiL/YuIolE79mMyCBANg3spsaWS1XVC5rtqi8TrXbYz0LuEOxcCpPhePR6+tvwFgulzvqzurmFhDol4tli23HSTJTyKVpMnr5OU2mR99Ht5X/xV/9DPYXImmBEgAAAABJRU5ErkJggg==\'); background-size: cover; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/2ee1b50a2a6e0a672e1292bb826c165e/2ff5b/dsr.webp 252w,\n/static/2ee1b50a2a6e0a672e1292bb826c165e/4d583/dsr.webp 504w,\n/static/2ee1b50a2a6e0a672e1292bb826c165e/10c02/dsr.webp 960w"\n              sizes="(max-width: 960px) 100vw, 960px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/2ee1b50a2a6e0a672e1292bb826c165e/019e0/dsr.png 252w,\n/static/2ee1b50a2a6e0a672e1292bb826c165e/0dcb2/dsr.png 504w,\n/static/2ee1b50a2a6e0a672e1292bb826c165e/7d769/dsr.png 960w"\n            sizes="(max-width: 960px) 100vw, 960px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/2ee1b50a2a6e0a672e1292bb826c165e/7d769/dsr.png"\n            alt="DSR Gopher"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",l.createElement(n.p,null,"This release brings many improvements and adds additional features to Cilium's\nkube-proxy replacement in eBPF, first introduced in Cilium\n",l.createElement(n.a,{href:"/blog/2019/08/20/cilium-16"},"v1.6"),". The eBPF-based kube-proxy\nreplacement implements handling of Kubernetes services of type ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">ClusterIP</code>'}}),",\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">NodePort</code>'}}),", ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">ExternalIPs</code>'}})," and ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">LoadBalancer</code>'}}),"."),"\n",l.createElement(n.p,null,"Kube-proxy replacement in eBPF has many benefits when compared to the vanilla\nkube-proxy of Kubernetes, such as better performance, reliability and\ndebuggability. See ",l.createElement(n.strong,null,l.createElement(n.a,{href:"https://docs.cilium.io/en/stable/gettingstarted/kubeproxy-free/"},"Kubernetes without kube-proxy")),"\nfor a quick-start guide and advanced configuration options. In addition, see\n",l.createElement(n.a,{href:"https://www.youtube.com/watch?v=bIRwSIwNHC0"},"Kubecon US 2019")," and ",l.createElement(n.a,{href:"https://fosdem.org/2020/schedule/event/containers_bpf/"},"FOSDEM 2020")," for implementation details and performance\nbenchmarks."),"\n",l.createElement(n.p,null,"In this release, Cilium's eBPF-based kube-proxy replacement has been stabilized\nand as a result moved from beta status to general availability. New Cilium\ndeployments via Helm transparently enable the kube-proxy replacement components\nby default if supported by the underlying Linux kernel, meaning, even if run\nalongside a kube-proxy environment, users still benef
1it from the eBPF-based\ndata path optimizations."),"\n",l.createElement(n.p,null,"Check out our ",l.createElement(n.strong,null,l.createElement(n.a,{href:"http://www.youtube.com/watch?v=bIRwSIwNHC0&t=110"},"2 minute Cilium demo")),"\non running Kubernetes without kube-proxy and netfilter/iptables being compiled\nout of the kernel:"),"\n",l.createElement(t,{embedId:"bIRwSIwNHC0?start=113&modestbranding=1&autoplay=1"}),"\n",l.createElement(n.h2,null,"Direct Server Return"),"\n",l.createElement(n.p,null,"When accessing a Kubernetes service from outside via NodePort, ExternalIPs or\nLoadBalancer, a Kubernetes worker node might redirect the request to\nanother node. This happens when a service endpoint runs on a different node\nthan the request was sent to. Before the redirect, the request is SNAT'd, which\nmeans that the backend won't see the source IP address of a client. Also, the\nreply will be sent through the initial node back to the client, which introduces\nadditional latency."),"\n",l.createElement(n.p,null,"To avoid that, Kubernetes offers ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">externalTrafficPolicy=Local</code>'}})," which helps to\npreserve the client source IP address by dropping a request to a service if a\nreceiving node does not run any service endpoint. However, this complicates\nload-balancer implementations, and can lead to uneven load balancing."),"\n",l.createElement(n.p,null,"To address the problem, we have implemented Direct Server Return for Kubernetes\nservices with the help of eBPF. This not only preserves the client source IP\naddress, but also allows us to avoid an extra hop when sending a reply back to\nthe client as shown in the figures below:"),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 1008px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/ddc4cd7b45e012ff15f400313c5a8042/0aaa4/dsr-without.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 43.65079365079365%; position: relative; bottom: 0; left: 0; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/ddc4cd7b45e012ff15f400313c5a8042/2ff5b/dsr-without.webp 252w,\n/static/ddc4cd7b45e012ff15f400313c5a8042/4d583/dsr-without.webp 504w,\n/static/ddc4cd7b45e012ff15f400313c5a8042/905a7/dsr-without.webp 1008w,\n/static/ddc4cd7b45e012ff15f400313c5a8042/bb9f8/dsr-without.webp 1512w,\n/static/ddc4cd7b45e012ff15f400313c5a8042/83a93/dsr-without.webp 2016w,\n/static/ddc4cd7b45e012ff15f400313c5a8042/c360b/dsr-without.webp 2122w"\n              sizes="(max-width: 1008px) 100vw, 1008px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/ddc4cd7b45e012ff15f400313c5a8042/019e0/dsr-without.png 252w,\n/static/ddc4cd7b45e012ff15f400313c5a8042/0dcb2/dsr-without.png 504w,\n/static/ddc4cd7b45e012ff15f400313c5a8042/832a9/dsr-without.png 1008w,\n/static/ddc4cd7b45e012ff15f400313c5a8042/19357/dsr-without.png 1512w,\n/static/ddc4cd7b45e012ff15f400313c5a8042/29ed2/dsr-without.png 2016w,\n/static/ddc4cd7b45e012ff15f400313c5a8042/0aaa4/dsr-without.png 2122w"\n            sizes="(max-width: 1008px) 100vw, 1008px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/ddc4cd7b45e012ff15f400313c5a8042/832a9/dsr-without.png"\n            alt="Without DSR (SNAT)"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",l.createElement("br"),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 1008px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/b4488d749f6e74376e90dcff34c1ab6b/0aaa4/dsr-with.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 41.26984126984127%; position: relative; bottom: 0; left: 0; background-image: url(\'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAIAAAB2/0i6AAAACXBIWXMAAAsTAAALEwEAmpwYAAABXklEQVR42nWQyXKCQBCGef/3iJfEyuIhOSSpGBfiVmqCZCnZBBGBYRkGGAdmyAjmYlW6uubQPV//f7fAWMXjVc5u37yRrIqy2Vsqc9VLMOV13mw+SGbeHkbDj40oWaJkDlemCw/CsVOx7id8WEZzI55qcKKGEx3tgR858602dvQJgT/LTXolmu3Bdat7cTPuiGtghTVcUray04WFRko0+HJnRsJhPwI5eI+cBQ6kCmuKm41U527y2H
1ppd2bPIy3aHmFui9EQYW7UBvHGDQEiPiKkZI1tPpoQGmfESwqQUNtLfVj4CckJFXKoB5vubv0E7X6RKrTe8IgxVhQF4VxZVv+EwMqUZPscuXlshrufFNgYhYRwrMRZEFiiq/c9o1dCibGyuR+rTik0IvxNg50yvjeGl5EyLWo1Rg8YWUmgQaDQ3Kkqeq7ceKyzwvgAE0TZyfrOcWT5W9UM9lc5g38BAoe9lMPjzWwAAAAASUVORK5CYII=\'); background-size: cover; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/b4488d749f6e74376e90dcff34c1ab6b/2ff5b/dsr-with.webp 252w,\n/static/b4488d749f6e74376e90dcff34c1ab6b/4d583/dsr-with.webp 504w,\n/static/b4488d749f6e74376e90dcff34c1ab6b/905a7/dsr-with.webp 1008w,\n/static/b4488d749f6e74376e90dcff34c1ab6b/bb9f8/dsr-with.webp 1512w,\n/static/b4488d749f6e74376e90dcff34c1ab6b/83a93/dsr-with.webp 2016w,\n/static/b4488d749f6e74376e90dcff34c1ab6b/c360b/dsr-with.webp 2122w"\n              sizes="(max-width: 1008px) 100vw, 1008px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/b4488d749f6e74376e90dcff34c1ab6b/019e0/dsr-with.png 252w,\n/static/b4488d749f6e74376e90dcff34c1ab6b/0dcb2/dsr-with.png 504w,\n/static/b4488d749f6e74376e90dcff34c1ab6b/832a9/dsr-with.png 1008w,\n/static/b4488d749f6e74376e90dcff34c1ab6b/19357/dsr-with.png 1512w,\n/static/b4488d749f6e74376e90dcff34c1ab6b/29ed2/dsr-with.png 2016w,\n/static/b4488d749f6e74376e90dcff34c1ab6b/0aaa4/dsr-with.png 2122w"\n            sizes="(max-width: 1008px) 100vw, 1008px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/b4488d749f6e74376e90dcff34c1ab6b/832a9/dsr-with.png"\n            alt="With DSR"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",l.createElement(n.h3,null,"Support for Kubernetes Services with External IPs"),"\n",l.createElement(n.p,null,"We have added support for services which are exposed with ",l.createElement(n.a,{href:"https://kubernetes.io/docs/concepts/services-networking/service/#external-ips"},"External IPs"),".\nFor each incoming packet with the destination IP set to one of those ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">externalIPs</code>'}}),"\nthe traffic will be redirected to one of the pods being backed by that service."),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="yaml"><pre class="language-yaml"><code class="language-yaml"><span class="token key atrule">apiVersion</span><span class="token punctuation">:</span> v1\n<span class="token key atrule">kind</span><span class="token punctuation">:</span> Service\n<span class="token key atrule">metadata</span><span class="token punctuation">:</span>\n  <span class="token key atrule">name</span><span class="token punctuation">:</span> external<span class="token punctuation">-</span>service\n  <span class="token key atrule">namespace</span><span class="token punctuation">:</span> kube<span class="token punctuation">-</span>system\n<span class="token key atrule">spec</span><span class="token punctuation">:</span>\n  <span class="token key atrule">ports</span><span class="token punctuation">:</span>\n    <span class="token punctuation">-</span> <span class="token key atrule">name</span><span class="token punctuation">:</span> service<span class="token punctuation">-</span>port\n      <span class="token key atrule">protocol</span><span class="token punctuation">:</span> TCP\n      <span class="token key atrule">port</span><span class="token punctuation">:</span> <span class="token number">8080</span>\n  <span class="token key atrule">externalIPs</span><span class="token punctuation">:</span>\n    <span class="token punctuation">-</span> 10.0.0.1\n    <span class="token punctuation">-</span> 10.0.0.2\n    <span class="token punctuation">-</span> 10.0.0.3</code></pre></div>'}}),"\n",l.createElement(n.h3,null,"Optimizations for Service Endpoint Selection"),"\n",l.createElement(n.p,null,"Accessing a Kubernetes service from a Cilium-managed node via ClusterIP,\nNodePort, ExternalIPs or Lo
1adBalancer is handled through socket-based\nload balancing in eBPF. This means that instead of performing slower DNAT on\nthe packet itself in lower layers of the stack, the backend is selected once,\nfor example, during the TCP ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">connect(2)</code>'}})," syscall where the kernel proceeds with\ndirectly connecting to the service' backend address."),"\n",l.createElement(n.p,null,"For any NodePort and ExternalIPs service, we implemented an optimization where the\nbackend can directly be selected on the local node for traffic from the host namespace\nor from Cilium-managed Kubernetes pods. This is different compared to the regular\nkube-proxy implementation that would need an additional hop in the network in\norder to first reach the related node address of the service which in turn would\nthen forward the request to a remote backend in the worst case."),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 1008px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/ae8ca98fe1a89b33ebd09f7dfc2d6eff/f9c4a/sock-1.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 51.1904761904762%; position: relative; bottom: 0; left: 0; background-image: url(\'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAKCAIAAAA7N+mxAAAACXBIWXMAAAsTAAALEwEAmpwYAAABm0lEQVR42o3PyW+bQBQHYP//9/ZWuYeoOVRtlEZqUiUHJ7aDs4EXouBAgGExDMwwLMPOQLFzSSyl6k96mpFG33tvBt0uKqwkMwGQABipG2zhLKcesSaePkZg3FLJiyoRZKZPDS8zYAK8OC3ZYGfb71z87RJeiWC0tC54bbr2PYwjX4a2FCK1otZUij+fOifc5Mdk/IvjRqK9CcstrupGMGLBTOYmFYxkYaW8kaIAJnCObCF0F22mP7vFtWweXg2H55+O+aMbNbBJtcWMdXrAFMSWgDzIjuxXL5hleZIGMnEfibvqCssmxZOTrgzMiZoI8NrNMK0GZeqEcIXsZQjFkrpFFvUm8p5Cb81Kr+/cfZxBmeiRcxu7N00s1MUmTzH174g9Q8a0jh47VjHWtu22+uzj10O02MNL/mwQyQglEACU1f8a+Q63R7fx1wv+ePbn5/X57/u7mULCrO4fiqJQFEVVVU3T+guldB+XNVtYyRk/OhgNDy6/nK3G93oa7XDTNPGb1HW9j/tf6ShXUb62w7nsqH6uobz4j73/Arh/KAbIeXhPAAAAAElFTkSuQmCC\'); background-size: cover; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/ae8ca98fe1a89b33ebd09f7dfc2d6eff/2ff5b/sock-1.webp 252w,\n/static/ae8ca98fe1a89b33ebd09f7dfc2d6eff/4d583/sock-1.webp 504w,\n/static/ae8ca98fe1a89b33ebd09f7dfc2d6eff/905a7/sock-1.webp 1008w,\n/static/ae8ca98fe1a89b33ebd09f7dfc2d6eff/bb9f8/sock-1.webp 1512w,\n/static/ae8ca98fe1a89b33ebd09f7dfc2d6eff/83a93/sock-1.webp 2016w,\n/static/ae8ca98fe1a89b33ebd09f7dfc2d6eff/809f4/sock-1.webp 2112w"\n              sizes="(max-width: 1008px) 100vw, 1008px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/ae8ca98fe1a89b33ebd09f7dfc2d6eff/019e0/sock-1.png 252w,\n/static/ae8ca98fe1a89b33ebd09f7dfc2d6eff/0dcb2/sock-1.png 504w,\n/static/ae8ca98fe1a89b33ebd09f7dfc2d6eff/832a9/sock-1.png 1008w,\n/static/ae8ca98fe1a89b33ebd09f7dfc2d6eff/19357/sock-1.png 1512w,\n/static/ae8ca98fe1a89b33ebd09f7dfc2d6eff/29ed2/sock-1.png 2016w,\n/static/ae8ca98fe1a89b33ebd09f7dfc2d6eff/f9c4a/sock-1.png 2112w"\n            sizes="(max-width: 1008px) 100vw, 1008px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/ae8ca98fe1a89b33ebd09f7dfc2d6eff/832a9/sock-1.png"\n            alt="With kube-proxy"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",l.createElement("br"),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 1008px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/d44178be2d2269fa9d29275dd7a77bc5/f9c4a/sock-2.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 49.20634920634921%; position: relative; bottom: 0; left: 0; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/d44178be2d2269fa9d29275dd7a77bc5/2ff5b/sock-2.webp 252w,\n/static/d44178be2d2269fa9d29275dd7a77bc5/4d583/sock-2.webp 504w,\n/static/d44178be2d2269fa9d29275dd7a77bc5/905a7/sock-2.webp 1008w,\n/static/d44178be2d2269fa9d29275dd7a77bc5/bb9f8/sock-2.webp 1512w,\n/static/d44178be2d2269fa9d29275dd7a77bc5/83a93/sock-2.webp 2016w,\n/static/d44178be2d2269fa9d29275dd7a77bc5/809f4/sock-2.webp 2112w"\n              sizes="(max-width: 1008px) 100vw, 1008px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/d44178be2d2269fa9d29275dd7a77bc5/019e0
1/sock-2.png 252w,\n/static/d44178be2d2269fa9d29275dd7a77bc5/0dcb2/sock-2.png 504w,\n/static/d44178be2d2269fa9d29275dd7a77bc5/832a9/sock-2.png 1008w,\n/static/d44178be2d2269fa9d29275dd7a77bc5/19357/sock-2.png 1512w,\n/static/d44178be2d2269fa9d29275dd7a77bc5/29ed2/sock-2.png 2016w,\n/static/d44178be2d2269fa9d29275dd7a77bc5/f9c4a/sock-2.png 2112w"\n            sizes="(max-width: 1008px) 100vw, 1008px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/d44178be2d2269fa9d29275dd7a77bc5/832a9/sock-2.png"\n            alt="With Cilium"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",l.createElement(n.p,null,"This latency improvement of saving an additional hop for packets is transparent\nto applications and made possible in Cilium given every Cilium-managed node\nhas a global view of Kubernetes services and their backends, and internal knowledge\nof security identities of remote Cilium-managed nodes."),"\n",l.createElement(n.h3,null,"Miscellaneous Improvements"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"Support for services of the ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">LoadBalancer</code>'}})," type was added, and we have\nsuccessfully tested the kube-proxy replacement with ",l.createElement(n.a,{href:"https://metallb.universe.tf/"},"MetalLB"),"."),"\n",l.createElement(n.li,null,"The kube-proxy replacement in Cilium now fully supports the aforementioned\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">externalTrafficPolicy</code>'}})," setting for both ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">NodePort</code>'}})," and ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">LoadBalancer</code>'}}),"\nservices. For services with the ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">Local</code>'}})," traffic policy, requests to nodes\nwithout any local service endpoints will be dropped rather than forwarded,\ntherefore avoiding any unwanted additional hops."),"\n",l.createElement(n.li,null,"To accommodate external load balancers which have to learn about the\navailability of service endpoints on individual nodes, this release of Cilium\nnow also supports Kubernetes' ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">healthCheckNodePort</code>'}})," field. The Cilium\nuser-space agent now serves a service health check for each Kubernetes service\nof type ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">LoadBalancer</code>'}})," with ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">externalTrafficPolicy=Local</code>'}}),"."),"\n",l.createElement(n.li,null,"For each NodePort service kube-proxy opens a socket in the host namespace,\nand binds the NodePort port to it in order to prevent other applications\nfrom reuse. For a large number of services, this adds a lot of resource\noverhead in the kernel, potentially allocating and binding thousands of sockets.\nCilium's kube-proxy replacement avoids this issue entirely, does not allocate\na single socket, and instead uses the eBPF ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">bind(2)</code>'}})," hook through its socket-based\nload balancing mechanism to consult its eBPF service map and reject an\napplication's ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">bind(2)</code>'}})," request on these ports with an error code."),"\n",l.createElement(n.li,null,"Cilium's socket-based load balancing in eBPF now also supports IPv4-in-IPv6\nservice address translation. This allows IPv4 service backend selection out\nof the ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">connect(2)</code>'}}),"/",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">sendmsg(2)</code>'}})," hook of IPv6-only applications. This is\noften enabled by default in language runtimes such as in case of Java."),"\n",l.createElement(n.li,null,"We have developed an extensive kube-proxy compatibility test suite with over 350\ntest cases which now runs as part of our Cilium CI infrastru
1cture to ensure\nsame semantics for our eBPF kube-proxy replacement."),"\n"),"\n",l.createElement("a",{name:"tls-visibility"}),"\n",l.createElement(n.h2,null,"TLS visibility for L7 policies (beta)"),"\n",l.createElement(n.p,null,l.createElement(n.em,null,"Contributed by Jarno Rajahalme")),"\n",l.createElement(n.p,null,"Cilium Network Policy (CNP) specification has two new experimental extensions\n(subject to change in coming releases) for policy enforcement on TLS protected\nHTTP connections. Firstly, the port-level policy rule definition is extended\nwith TLS contexts, one for terminating the client-initiated TLS connection in\nthe Cilium host proxy, and the other for originating TLS for the upstream proxy\nconnection. In order for this proxy TLS interception to work, the client pod\nmust be configured with your local CA certs that are also used to create the TLS\nsecrets for the port rule. A new ",l.createElement(n.a,{href:"https://docs.cilium.io/en/v1.7/gettingstarted/tls-visibility",title:"Inspecting TLS Encrypted Connections with Cilium"},"Getting Started\nGuide")," has step-by-step\ninstructions for this."),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 598px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/9446f6491de3acded2b66ad176adf131/89d5f/tls.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 78.57142857142857%; position: relative; bottom: 0; left: 0; background-image: url(\'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAQCAYAAAAWGF8bAAAACXBIWXMAAC4jAAAuIwF4pT92AAAC+ElEQVR42oWTTW8TZxDHt1wqVAn11Ev5Bq3UO4eKYzlUaiu+QdsLKtxQD1yo1GMvKAiiFEGpFdoQCBaNSkRKiUiAOM7GL7Ebmjhx8PolXme9
1Xnvttfftx+O1k9iFhpFmV/PMPPPM/Oc/EgPieS74Xt+w2PnjE5RfJfLjR8mFjqJOvIcVlrAL94MQ37PxfX8wBRLdg+Cw5/BFwsBy6qiTx9kclciMvcPmmIT+2xHcuxKdbKgX4znBnZ1SkXRqtZ9wQLKZCG2r3jN8Gyt2nsaDj9idOYH66DQVoW7kCzxdDkJyWzKubfBscZkro9d6CbX8MlohilFOkZz/geT6LPG8TPxlhGRxlRUlRnTtCYnCOqnyGol8nJgSJa0kWIuOkJFHqWXDaJkJarkZJL2yRbW8gWkUBYZQNXcp1XLsGHmKep5t+QKPb50iOf05Su4hO/WK8L+kXCviir4beg5NWaRaWBJFrQ63LCYxZLnCdFfPkf/zM5qPP8VR5/tw7MUdYH/IUPx99QTohXINpVRlS9nFandEhCN87sB0/d4DwSPefysclu4dq+NitmzMZkdU7O3X9X9yaMJG+ifqS9/SWD4r9DuM6Bks+RtcPTbU+l5Hb0g4gInXoRL+mI0rEv9ePcLG1R4PnUlB7M2f++Hu4RU6bndb+gl9B+Pvk5TGJYoT75O/fRw9/AH29Ls4yu+9eGeP2CUuXRrBstpIrmPhOmawIS9WbgqyzmG5Ng1ToyboU01cpP7sa4z4j2i5B+iVOIZRoC1azKTvkU3fwaxrzM7cwWpWkHYFsQsbf6HmFqlszxFNTTEpX+fh01+YWr5Pcu4r6tc/xLx1jEfPv+fuSpjZ5+NMyTdJvZhGSU9SSI7R2A6xGb2MZNsd2u0Wdqe9D2z322zptERHTuRLstcktJDY4cwI3Sa71ft9rD3XCdbVahl0rMYwhn4wtQN+OcJslhZQ/wmhpm9gausHfOr/fd97O232Kq2oKk8WIiwsxpibX0JeSQz5X2eHzytXyo8tE8xEyAAAAABJRU5ErkJggg==\'); background-size: cover; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/9446f6491de3acded2b66ad176adf131/2ff5b/tls.webp 252w,\n/static/9446f6491de3acded2b66ad176adf131/4d583/tls.webp 504w,\n/static/9446f6491de3acded2b66ad176adf131/a5481/tls.webp 598w"\n              sizes="(max-width: 598px) 100vw, 598px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/9446f6491de3acded2b66ad176adf131/019e0/tls.png 252w,\n/static/9446f6491de3acded2b66ad176adf131/0dcb2/tls.png 504w,\n/static/9446f6491de3acded2b66ad176adf131/89d5f/tls.png 598w"\n            sizes="(max-width: 598px) 100vw, 598px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/9446f6491de3acded2b66ad176adf131/89d5f/tls.png"\n            alt="TLS visibility"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",l.createElement(n.p,null,"Secondly, the HTTP rule level is extended with new header matches that can\nperform header manipulations on mismatching headers. The header value being\nmatched can be sourced from a Kubernetes Secret, so no secret information needs to be\nspecified directly in the CNP. The supported mismatch actions include ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">LOG</code>'}}),", ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">ADD</code>'}}),",\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">DELETE</code>'}})," and ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">REPLACE</code>'}}),". These allow a policy to either just inspect and log\nincorrect header values, or replace incorrect values with the correct\nones. Applying the ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">REPLACE</code>'}})," mismatch action on an client authorization header\nmakes it possible to never expose secret tokens to application pods."),"\n",l.createElement(n.p,null,"Using these new facilities with ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">toFQDNs</code>'}})," rules allows not only limiting TLS\ntraffic to external services on specific domain names, but also enforcing and\naccess logging the HTTP metadata (path, method, headers, etc.), preventing\npotentially malicious exfiltration of data, for example."),"\n",l.createElement("a",{name:"visibility-annotations"}),"\n",l.createElement(n.h2,null,"L7 protocol visibility via pod annotations"),"\n",l.createElement(n.p,null,l.createElement(n.em,null,"Contributed by Ian Vernon and Joe Stringer")),"\n",l.createElement(n.p,null,"When users run Cilium as the CNI, by default the only visibility that is\navailable via tools like ",l.createElement(n.a,{href:"https://github.com/cilium/hubble/"},"Hubble")," or ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">cilium monitor</code>'}})," is information at layers\n2, 3 and 4 as individual packets pass through the Cilium eBPF data path. Users\ncan apply ",l.createElement(n.a,{href:"http://docs.cilium.io/en/stable/policy/language/#l7-policy"},"Layer 7 Policy")," to add API-aware visibility and enforcement on the\nnetwork streams in the cluster, but for any visibility to be effective without\ndropping any other traffic, users would need to craft full policies for the\nselected endpoints to allow all expected traffic to/from those endpoints."),"\n",l.createElement(n.p,null,"To allow users to gain introspection into the API calls being made without\nhaving to craft full policies for their endpoints, we've added supp
1ort for\nproxy visibility annotations. Users can annotate the pod indicating the\ndirection, port and protocols active on the port, then Cilium gathers and\ndistributes information about API calls being made to other tools like Hubble.\nIn the image below, the ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">tiefighter</code>'}})," is posting API requests to\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">v1/request-landing</code>'}})," on the ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">deathstar</code>'}}),"... I wonder what that's about!"),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 813px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/ffae16c888d49c5fd28c8758a038ca12/44eb4/tiefighter-l7-visibility.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 50%; position: relative; bottom: 0; left: 0; background-image: url(\'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAKCAIAAAA7N+mxAAAACXBIWXMAAAsTAAALEwEAmpwYAAABZ0lEQVR42kVS25aDIAz0/z9uX3u63aoIGLBeAAGttnYHa3dzcEwCmQyXjCl54qeLzJmqSyX2IT94OAUlxAI4BfE3IszwO4vvH1kwRYh3ipodAxmqNMmbZiQLybmC3witKkWgy9BZNFo0iGus443iQE0ImaaSJLW3aXqR0kLKGOILtm2dNXnNUcxzsl+XSXDGuViWZdu2dVk51VdZQYXq2xBCjPH5fKIw+SEOzhQohuzbYLvBx+Cfu3nv52lSXXsu86tgXDVKzSk5z+B9PB7obEaHnWdFLXpngh9h67ouy4ppUOiuRVsUC62NGY0ZULxL3oDWuyQbX2/NADODs85Ze7/fMa37tqB0wrrvpimO3u/Uy1v80bkkgSNpujZRjBYEyXFWNjpdFUnot9b2fe8Ss8Xm/zuzfUW6zFocgxKWe1sg7qkzg3FuDMGFYLHBGCAHh5VVn7fB0jN44+H85YH7wwApPxyqKkW/6nInZ71JYu0AAAAASUVORK5CYII=\'); background-size: cover; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/ffae16c888d49c5fd28c8758a038ca12/2ff5b/tiefighter-l7-visibility.webp 252w,\n/static/ffae16c888d49c5fd28c8758a038ca12/4d583/tiefighter-l7-visibility.webp 504w,\n/static/ffae16c888d49c5fd28c8758a038ca12/e0a6a/tiefighter-l7-visibility.webp 813w"\n              sizes="(max-width: 813px) 100vw, 813px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/ffae16c888d49c5fd28c8758a038ca12/019e0/tiefighter-l7-visibility.png 252w,\n/static/ffae16c888d49c5fd28c8758a038ca12/0dcb2/tiefighter-l7-visibility.png 504w,\n/static/ffae16c888d49c5fd28c8758a038ca12/44eb4/tiefighter-l7-visibility.png 813w"\n            sizes="(max-width: 813px) 100vw, 813px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/ffae16c888d49c5fd28c8758a038ca12/44eb4/tiefighter-l7-visibility.png"\n            alt="HTTP visibility via pod annotations"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",l.createElement(n.p,null,"The policy documentation describes how to use these pod annotations in ",l.createElement(n.a,{href:"http://docs.cilium.io/en/stable/policy/visibility/"},"more\ndetail"),"."),"\n",l.createElement("a",{name:"ebpf-library"}),"\n",l.createElement("a",{name:"pure-go-ebpf-library"}),"\n",l.createElement(n.h2,null,"Pure Go eBPF library"),"\n",l.createElement(n.p,null,l.createElement(n.em,null,"Contributed by Joe Stringer")),"\n",l.createElement(n.p,null,"During the ",l.createElement(n.a,{href:"https://linuxplumbersconf.org/event/4/sessions/62/#20190911"},"Linux Plumbers 2019 eBPF track"),",\nCilium core developers and Cloudflare engineers co-presented a ",l.createElement(n.a,{href:"https://linuxplumbersconf.org/event/4/contributions/449/"},"proposal"),"\nfor a pure Go eBPF library which would aim to solve eBPF kernel interactions for long-lived\nGo-based daemons like Cilium or Cloudflare's L4 load balancer, without the need to pull in ",l.createElement(n.a,{href:"https://dave.cheney.net/2016/01/18/cgo-is-not-go"},"CGo"),"."),"\n",l.createElement(n.p,null,"This effort is now well under way, and in Cilium 1.7 the ring-buffer used for sending messages\nfrom the eBPF data path to the user space ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">cilium-agent</code>'}})," process has been converted over from the\nprevious CGo implementation to a faster, more efficient implementation with the help of the new\nlibrary."),"\n",l.createElement(n.p,null,"There are various other eBPF libraries in the wild, for example, ",l.createElement(n.a,{href:"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/tools/lib/bpf"},"libbpf")," or ",l.createElement(n.a,{href:"https://github.com/iovisor/bcc/blob/master/src/cc/libbcc.pc.in"},"libbcc"),". While the former\nrepresents the canonical implementation, lives in the Linux kernel tree and is suited for\nC/C++-based applications, it cannot be used in pure Go context. Similarly, that is the case\nfor the latter which has a focus on tracing, wraps libbpf and even LLVM's eBPF backend. Other\nGo-based libraries in this area depend on CGo, complicating builds and having expensive\ncontext switches between C and Go environment as a result to just name a few."),"\n",l.createElement(n.p,null,"With the start of a generic, pure Go eBPF library, we aim to solve both Cilium and Cloudflare's\nproduction needs for orchestrating eBPF, and hope to also enable a much larger Go community to\ninteract with the kernel's eBPF subsystem more easily. The main goals are to cover networking\nuse-cases, to minimise external dependencies, to solve common problems and to have a well-tested\nand highly testable eBPF library in pure Go that can be used in production."),"\n",l.createElement(n.p,null,"Aside from the initial eBPF map, program and ring-buffer interactions, the development on the\nlibrary continues with recent extensions to support the BPF Type Format (BTF) and initial proposals\nfor static data substitution to support templated eBPF programs which only need to be compiled once."),"\n",l.createElement(n.p,null,"To learn more about the eBPF library, visit the project under Cilium's GitHub organization: ",l.createElement(n.a,{href:"https://github.com/cilium/ebpf"},"https://github.com/cilium/ebpf")),"\n",l.createElement("a",{name:"endpoint-slice"}),"\n",l.createElement(n.h2,null,"Kubernetes EndpointSlice support"),"\n",l.createElement(n.p,null,l.createElement(n.em,null,"Contributed by André Martins")),"\n",l.createElement(n.p,null,"In order to have better scalability for a large number of endpoints backed by\na service, Kubernetes 1.16 has introduced ",l.createElement(n.a,{href:"https://kubernetes.io/docs/concepts/services-networking/endpoint-slices
1/"},"EndpointSlice"),".\nSince Kubernetes 1.17 this API has been marked as beta and enabled by default.\nAlthough the API endpoint is enabled by default, the controller that manages\nEndpoint Slices is not and one needs to follow the guide ",l.createElement(n.a,{href:"https://kubernetes.io/docs/tasks/administer-cluster/enabling-endpointslices/#enabling-endpointslices"},"here")," to enable that controller and make use of this new type."),"\n",l.createElement(n.p,null,"Cilium 1.7 introduces a new flag, ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">enable-k8s-endpoint-slice</code>'}}),", which is enabled\nby default and will automatically detect if Endpoint Slices are available in the\ncluster and use those to perform all the service translations in eBPF. Setting\nthis flag to false will fallback to using the v1/Endpoints types available in\nthe cluster."),"\n",l.createElement("a",{name:"scalability"}),"\n",l.createElement(n.h2,null,"Scalability"),"\n",l.createElement(n.p,null,l.createElement(n.em,null,"Contributed by Ian Vernon and André Martins")),"\n",l.createElement(n.h3,null,"CNP node status"),"\n",l.createElement(n.p,null,"As part of the CiliumNetworkPolicy (CNP) scalability improvements, Cilium\nintroduces a new flag: ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">enable-k8s-event-handover</code>'}}),"."),"\n",l.createElement(n.p,null,"When a new CNP is created in the cluster, all Cilium agents will receive an\nevent from Kubernetes and, as soon as they enforce the policy in the data path,\neach one of them will update its status in the status field of the CNP. For a\nlarge number of nodes this can cause high CPU usage in kube-apiserver as for\neach update received from each Cilium agent a new Kubernetes event needs to be\nsent to all remaining nodes. In previous releases, we have supported entirely\ndisabling this feature using the ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">--disable-cnp-status-updates</code>'}})," flag; however\nthis prevents users from understanding the enforcement status of the CNPs."),"\n",l.createElement(n.p,null,"With ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">enable-k8s-event-handover</code>'}})," enabled, the implementation will behave\nslightly differently: Instead of updating its status field in the CNP, each Cilium\nagent will update its status into the KVstore. Cilium Operator will then watch\nfor all of those updates for each CNP from the KVstore and perform incremental\nupdates with all Cilium agent status to each CNP into Kubernetes. In the end,\nthe CNP status will always be present in Kubernetes, but the way it will be\nmore efficiently populated."),"\n",l.createElement(n.h3,null,"Cilium agent"),"\n",l.createElement(n.p,null,"As Cilium does no longer depend on container runtimes, all of the container\nruntimes' dependencies were removed from Cilium causing the cilium-agent binary\nsize to drop from 97M to 74M."),"\n",l.createElement(n.h3,null,"Golang 1.13"),"\n",l.createElement(n.p,null,"Cilium 1.7 is compiled with Golang 1.13 which allows a lot of memory optimizations\nin the ",l.createElement(n.a,{href:"https://golang.org/doc/go1.13#runtime"},"runtime")," and also decreases\nthe memory footprint of Cilium."),"\n",l.createElement("a",{name:"upstream-linux"}),"\n",l.createElement(n.h2,null,"Linux kernel changes"),"\n",l.createElement(n.p,null,l.createElement(n.em,null,"Contributed by Daniel Borkmann")),"\n",l.createElement(n.p,null,"During the Cilium 1.7 development window, we've also worked on a number of\nimprovements to the Linux kernel's eBPF subsystem which we co-maintain. The selected\nchanges highlighted below are generic for all eBPF users, but have been implemented\nin the context of Cilium's and Hubble's eBPF needs. They are part of the just\nreleased 5.5 kernel."),"\n",l.createElement(n.h3,null,"Live-Patching of eBPF programs"),"\n",l.createElement(n.p,null,"Given that Cilium's data path needs to support a wide range of Linux kernels, that\nis, from 4.9 up to the very latest kernel release. A lot of the eBPF data path\nfunctionality has been split into eBPF tail calls in particular for the case of\nhaving Cilium's eBPF kube-proxy replacement enabled. Aside from reducing verifier\ncomplexity on older kernels, the use of eBPF tail calls also allows for atomically\nreplacing pod-specific eBPF features without service disruption on a live system."),"\n",l.createElement(n.p,null,"The x86-64 eBPF JIT compiler in the kernel originally mapped eBPF tail calls into\nan indirect jump, meaning, the target eBPF program address is loaded from the\nBPF tail call map from a given index into register ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">%rax</code>'}})," followed by a ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">jmpq *%rax</code>'}}),".\nDue to the various speculative execution flaws on modern CPUs, we later changed\nthe eBPF JIT to ",l.createElement(n.a,{href:"https://lore.kernel.org/netdev/[email protected]/"},"emit retpolines"),"\ninstead at the cost of performance. Given also that all major compilers have\na
1dapted this technique, the Linux kernel community in general has since been\nobsessed with avoiding indirect calls in fast-path code whenever possible. For\nexample, a small ",l.createElement(n.a,{href:"https://lore.kernel.org/netdev/[email protected]/"},"improvement"),"\nto turn eBPF map-related helpers into direct calls showed a ",l.createElement(n.a,{href:"http://vger.kernel.org/lpc-networking2018.html#session-10"},"14% performance gain"),"."),"\n",l.createElement(n.p,null,"Now, for the 5.5 kernel, we ",l.createElement(n.a,{href:"https://lore.kernel.org/bpf/[email protected]/"},"implemented"),"\ntracking of eBPF tail call map indices in the verifier and if the latter determines\nthat a given index is constant from all program paths, as in the vast majority of\ncases in Cilium's eBPF programs, we can emit a direct jump. Once the tail called\nprograms are updated, the eBPF JIT image is patched to directly jump to the new location."),"\n",l.createElement(n.p,null,"To demonstrate this technique, the below example eBPF program implements an eBPF tail\ncall jump to the constant map index ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">0</code>'}}),":"),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">  0: (b7) r3 = 0\n  1: (18) r2 = map[id:526]\n  3: (85) call bpf_tail_call#12\n  4: (b7) r0 = 1\n  5: (95) exit</code></pre></div>'}}),"\n",l.createElement(n.p,null,"The x86-64 eBPF JITed program would emit a retpoline on older kernels (marked in bold):"),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">  0xffffffffc076e55c:\n  [...]                                  _\n  19:   xor    %edx,%edx                |_ index (r3 = 0)\n  1b:   movabs $0xffff88d95cc82600,%rsi |_map (r2 = map[id:526])\n  25:   mov    %edx,%edx                |  index >= array->map.max_entries check\n  27:   cmp    %edx,0x24(%rsi)          |\n  2a:   jbe    0x0000000000000066       |_\n  2c:   mov    -0x224(%rbp),%eax        |  tail call limit check\n  32:   cmp    $0x20,%eax               |\n  35:   ja     0x0000000000000066       |\n  37:   add    $0x1,%eax                |\n  3a:   mov    %eax,-0x224(%rbp)        |_\n  40:   mov    0xd0(%rsi,%rdx,8),%rax   |_prog = array->ptrs[index]\n  48:   test   %rax,%rax                |  prog == NULL check\n  4b:   je     0x0000000000000066       |_\n  4d:   mov    0x30(%rax),%rax          |  goto *(prog->bpf_func + prologue_size)\n  51:   add    $0x19,%rax               |\n  55:   callq  0x0000000000000061       |  retpoline for indirect jump\n  5a:   pause                           |\n  5c:   lfence                          |\n  5f:   jmp    0x000000000000005a       |\n  61:   mov    %rax,(%rsp)              |\n  65:   retq                            |_\n  66:   mov    $0x1,%eax                (next instruction, r0 = 1)\n  [...]</code></pre></div>'}}),"\n",l.createElement(n.p,null,"For 5.5 or later kernels, the same program would get optimized into a direct jump\n(marked in bold) without the need for a retpoline:"),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">  0xffffffffc08e8930:\n  [...]                                  _\n  19:   xor    %edx,%edx                |_ index (r3 = 0)\n  1b:   movabs $0xffff9d8afd74c000,%rsi |_map (r2 = map[id:526])\n  25:   mov    -0x224(%rbp),%eax        |  tail call limit check\n  2b:   cmp    $0x20,%eax               |\n  2e:   ja     0x000000000000003e       |\n  30:   add    $0x1,%eax                |\n  33:   mov    %eax,-0x224(%rbp)        |_\n  39:   jmpq   0xfffffffffffd1785       |_[direct] goto *(prog->bpf_func + prologue_size)\n  3e:   mov    $0x1,%eax                (next instruction, r0 = 1)\n  [...]</code></pre></div>'}}),"\n",l.createElement(n.p,null,"Upon program update, the instruction on address ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">39</code>'}}),", that is ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">jmpq 0xfffffffffffd1785</code>'}}),",\nwould be live-updated with the address of the new target eBPF program. Similarly,\nif the target eBPF program would get deleted from the tail call map, then the ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">jmp</code>'}}),"\nis patched into a same-sized ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">nop</code>'}})," instruction in order to allow a fall-through:"),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">  0xffffffffc08e8930:\n  [...]                                  _\n  19:   xor    %edx,%edx                |_ index (r3 = 0)\n  1b:   movabs $0xffff9d8afd74c000,%rsi |_map (r2 = map[id:526])\n  25:   mov    -0x224(%rbp),%eax        |\n  2b:   cmp    $0x20,%eax               .\n  2e:   ja     0x000000000000003e       .\n  30:   add    $0x1,%eax                .\n  33:   mov    %eax,-0x224(%rbp)        |_\n  39:   nopl   0x0(%rax,%rax,1)         |_ fall-through nop\n  3e:   mov    $0x1,%eax                (next instruction, r0 = 1)\n  [...]</code></pre></div>'}}),"\n",l.createElement(n.p,null,"Thus, instead of redirecting speculation into the ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">pause/lfence</code>'}})," loop, the kernel\neliminates the need to potentially perform any speculation for the jump given the\ndirect address and can therefore execute the generated eBPF code more efficiently."),"\n",l.createElement(n.p,null,"See the ",l.createElement(n.a,{href:"https://lore.kernel.org/bpf/[email protected]/"},"merged patch set")," for further information."),"\n",l.createElement("a",{name:"safe-and-multi-architecture-supported-ebpf-probe-helpers-for-tracing"}),"\n",l.createElement(n.h3,null,"Safe and multi-architecture supported eBPF probe helpers for tracing"),"\n",l.createElement(n.p,null,"Cilium's eBPF data path is able to export tracing information at various aggregation\nlevels through a high-performance, customizable ring-buffer to its user space agent.\n",l.createElement(n.a,{href:"https://github.com/cilium/hubble"},"Hubble"),", which builds on top of Cilium and implements\na fully distributed networking and security observability platform, is then able to\nprovide deep visibility into the communication and behavior of services as well as\nthe networking infrastru
1cture. Additionally, Hubble also enriches the gathered information\nthrough eBPF-based kernel tracing."),"\n",l.createElement(n.p,null,"Since multi-architecture support is in development for the next Cilium 1.8 release,\nwe have ",l.createElement(n.a,{href:"https://lore.kernel.org/bpf/[email protected]/"},"implemented"),"\na new set of eBPF helpers in the kernel which allow for safe and multi-architecture\neBPF-based memory probing."),"\n",l.createElement(n.p,null,"The current set of ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">probe_kernel_read()</code>'}})," and ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">bpf_probe_read_str()</code>'}})," eBPF helpers have\nseveral downsides: while generally safe due to disabling page-faulting, on x86-64,\nthese helpers can still trigger a kernel ",l.createElement(n.a,{href:"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=00c42373d3970b354948ba3b24a34501b1a2505f"},"warning")," when attempting to probe user memory on a non-canonical user access address. This can\nbe problematic since the non-canonical address range is often used in user space\napplications for ",l.createElement(n.a,{href:"https://en.wikipedia.org/wiki/Tagged_pointer"},"tagged")," pointers."),"\n",l.createElement(n.p,null,"Another severe downside is that the two mentioned eBPF helpers are incompatible for non-x86\nbased architectures as they assume usage for probing memory access for kernel space\naddresses as well as user space addresses. However, use for both cases will attempt\nto always access kernel space address space given access is performed under ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">KERNEL_DS</code>'}}),"\nand, while x86 has a non-overlapping address space, other architectures do not,\nmeaning, kernel pointer and user pointer can have the same address value."),"\n",l.createElement(n.p,null,"Therefore, we have added the set of ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">bpf_probe_read_user()</code>'}}),", ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">bpf_probe_read_kernel()</code>'}}),"\nand ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">bpf_probe_read_user_str()</code>'}})," and ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">bpf_probe_read_kernel_str()</code>'}})," eBPF helpers to\nthe kernel for strict access under either ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">USER_DS</code>'}})," or ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">KERNEL_DS</code>'}})," in their allowed\nrange and without the possibility to trigger a non-canonical access warning in the\nkernel."),"\n",l.createElement(n.p,null,"See the ",l.createElement(n.a,{href:"https://lore.kernel.org/bpf/[email protected]/"},"merged patch set")," for further information."),"\n",l.createElement("a",{name:"managed-ci"}),"\n",l.createElement(n.h2,null,"Supporting Cilium testing on managed Kubernetes offerings"),"\n",l.createElement(n.p,null,l.createElement(n.em,null,"Contributed by Maciej Kwiek and Ray Bejjani")),"\n",l.createElement(n.p,null,"Running Cilium end-to-end tests has always been a bit painful because of tight\ncoupling between our testing framework and assumptions about the cluster that\ntests are being run on. This release, we've done a lot of work to make\ndevelopers' lives easier."),"\n",l.createElement(n.p,null,"Cilium 1.7 gives Cilium developers means to run most of our test suite on\nKubernetes clusters managed by providers such as GKE. Developers are also able\nto run only selected tests on our CI GKE clusters, which eases the burden of\nmanaging local clusters and allows for more test-driven development thanks to\nfaster cluster provisioning."),"\n",l.createElement("a",{name:"helm"}),"\n",l.createElement(n.h2,null,"Helm 3 and Helm repository"),"\n",l.createElement(n.p,null,l.createElement(n.em,null,"Contributed by Arthur Evstifeev and Joe Stringer")),"\n",l.createElement(n.p,null,l.createElement(n.a,{href:"https://helm.sh/blog/helm-3-released/"},"Helm3")," was recently released, simplifying the use of helm charts repositories\nand allowing installation without requiring Tiller to be installed in your\ncluster. Extending upon the helm template support introduced initially in\nCilium 1.6, from this release onwards Cilium will be available via a helm\nrepository residing at ",l.createElement(n.a,{href:"https://helm.cil
1ium.io"},"https://helm.cilium.io"),". All\nCilium guides have been updated to use Helm3 syntax. To use this repository for\ninstallation:"),"\n",l.createElement(n.p,null,l.createElement(n.strong,null,"Example: Configuring Cilium for GKE")),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="bash"><pre class="language-bash"><code class="language-bash">helm repo <span class="token function">add</span> cilium https://helm.cilium.io/\nhelm <span class="token function">install</span> cilium cilium/cilium <span class="token punctuation">\\</span>\n  <span class="token parameter variable">--namespace</span> cilium <span class="token punctuation">\\</span>\n  <span class="token parameter variable">--set</span> <span class="token assign-left variable">global.cni.binPath</span><span class="token operator">=</span>/home/kubernetes/bin <span class="token punctuation">\\</span>\n  <span class="token parameter variable">--set</span> <span class="token assign-left variable">global.nodeinit.enabled</span><span class="token operator">=</span>true <span class="token punctuation">\\</span>\n  <span class="token parameter variable">--set</span> <span class="token assign-left variable">nodeinit.reconfigureKubelet</span><span class="token operator">=</span>true <span class="token punctuation">\\</span>\n  <span class="token parameter variable">--set</span> <span class="token assign-left variable">nodeinit.removeCbrBridge</span><span class="token operator">=</span>true</code></pre></div>'}}),"\n",l.createElement("a",{name:"17Highlights"}),"\n",l.createElement(n.h2,null,"1.7 Release Highlights"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"Enhancements to kube-proxy replacement in eBPF"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"New Direct Server Return (DSR) mode for better latency and client source IP preservation"),"\n",l.createElement(n.li,null,"Kubernetes ExternalIPs and LoadBalancer service support"),"\n",l.createElement(n.li,null,"NodePort services health check support added"),"\n",l.createElement(n.li,null,"Handling of ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">externalTrafficPolicy=Local</code>'}})," added"),"\n",l.createElement(n.li,null,"IPv4-in-IPv6 support for socket-based load balancing"),"\n",l.createElement(n.li,null,"Optimized endpoint selection for socket-based load balancing"),"\n",l.createElement(n.li,null,"Various SNAT optimizations and better port collision handling"),"\n",l.createElement(n.li,null,"Efficient detection of NodePort and ExternalIPs port reuse via bind hook"),"\n",l.createElement(n.li,null,"New feature probe mode by default for new deployments"),"\n",l.createElement(n.li,null,"Extensive kube-proxy compatibility test suite for Cilium CI"),"\n"),"\n"),"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"Policy"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"TLS visibility policies (beta)"),"\n",l.createElement(n.li,null,"L7 visibility via pod annotations"),"\n",l.createElement(n.li,null,"Support handling remote nodes as separate identity"),"\n",l.createElement(n.li,null,"Improve handling of DNS timeouts with FQDN policy"),"\n"),"\n"),"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"Kubernetes"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"Validated with Kubernetes 1.17"),"\n",l.createElement(n.li,null,"Support dual-stack mode"),"\n",l.createElement(n.li,null,"Support for EndpointSlices"),"\n",l.createElement(n.li,null,"Better CRD validation for Cilium resources"),"\n"),"\n"),"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"Datapath"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"More efficient ring-buffer communication between eBPF and cilium-agent"),"\n",l.createElement(n.li,null,"Support more flexible aggregation of connection events"),"\n",l.createElement(n.li,null,"Better bounding on dumping large maps"),"\n",l.createElement(n.li,null,"Improved handling of large CIDR policies"),"\n",l.createElement(n.li,null,"Detect feature support using bpftool"),"\n",l.createElement(n.li,null,"Support for forwarding ICMP fragmentation needed messages via agent option"),"\n",l.createElement(n.li,null,"Support binding to NodePorts"),"\n"),"\n"),"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"Scalability and Resource consumption"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"Offload ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">CiliumNetworkPolicy</code>'}})," status reporting to KVstore and cilium-operator"),"\n",l.createElement(n.li,null,"Optimize footprint using Go 1.13"),"\n",l.createElement(n.li,null,"Remove dependency on container runtime (CRI)."),"\n"),"\n"),"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"CLI"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"Improved information in the ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">cilium status</code>'}})," command"),"\n",l.createElement(n.li,null,"Command completion for zsh"),"\n"),"\n"),"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"Documentation"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"Use Helm 3 for deployment instructions"),"\n",l.createElement(n.li,null,"Add a dedicated repository for Cilium helm charts."),"\n",l.createElement(n.li,null,"Various fixes for chaining and managed Kubernetes guides"),"\n"),"\n"),"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"Istio"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"Support for 1.4.3"),"\n"),"\n"),"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"Kernel changes"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"Live-patching eBPF programs"),"\n",l.createElement(n.li,null,"Multi-architecture support improvements"),"\n"),"\n"),"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"Hubble"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"Hubble graphical user interface"),"\n",l.createElement(n.li,null,"Correlate additional metadata with network flows"),"\n"),"\n"),"\n",l.createElement(n.li,null,l.createElement(n.strong,null,"Continuous Integration / Testing"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"Support for running the Cilium CI in GKE and EKS managed clusters"),"\n"),"\n"),"\n"),"\n",l.createElement(n.p,null,"See the ",l.createElement(n.a,{href:"https://github.com/cilium/cilium/blob/v1.7/CHANGELOG.md"},"Changelog"),"\nfor full notes on changes during the Cilium 1.7 development cycle."),"\n",l.createElement(n.h2,null,"Getting Started"),"\n",l.createElement(n.p,null,"New to Cilium? Follow one of the ",l.createElement(n.a,{href:"https://docs.cilium.io/en/v1.7/gettingstarted/"},"Getting Started\nGuides"),"."),"\n",l.createElement(n.h2,null,"Upgrade Instructions"),"\n",l.createElement(n.p,null,"As usual, follow the ",l.createElement(n.a,{href:"https://cilium.readthedocs.io/en/v1.7/install/upgrade/#upgrading-minor-versions"},"upgrade\nguide"),"\nto upgrade your Cilium deployment. Feel free to ping us on\n",l.createElement(n.a,{href:"https://slack.cilium.io"},"Slack"),"."),"\n",l.createElement(n.h2,null,"Release"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"Release Notes & Binaries: ",l.createElement(n.a,{href:"https://github.com/cilium/cilium/releases/tag/v1.7.0"},"1.7.0")),"\n",l.createElement(n.li,null,"Container image: ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">docker.io/cilium/cilium:v1.7.0</code>'}})),"\n"))}var s=function(e){void 0===e&&(e={});const{wrapper:n}=Object.assign({},(0,a.RP)(),e.components);return n?l.createElement(n,e,l.createElement(i,e)):i(e)};var r=t(8125),o=t(5805),c=t(8838),d=t(2744);const p=e=>{const{data:{mdx:n},children:t}=e,{frontmatter:{path:a,title:i,date:s,tags:c,ogSummary:p}}=n;return l.createElement(d.A,{headerWithSearch:!0},l.createElement(r.A,{path:a,content:t,date:s,title:i,tags:c,summary:p}),l.createElement(o.A,{className:"my-10 md:my-20 lg:my-28"}))},u=e=>{var n,t;let{data:{mdx:a,site:i},location:{pathname:s}}=e;const{frontmatter:{title:r,ogImage:o,ogSummary:d,dateIso:p,tags:u,author:m}}=a,{siteUrl:g}=i.siteMetadata,h=`${d.slice(0,133)}...`,b=`${g}${s}`,f=null!=o&&null!==(n=o.childImageSharp)&&void 0!==n&&null!==(t=n.resize)&&void 0!==t&&t.src?`${g}${o.childImageSharp.resize.src}
1`:null,w={title:r,description:h,image:o||null,slug:s},y={"@context":"https://schema.org","@type":"BlogPosting",headline:r,description:h,url:b,datePublished:p,dateModified:p,author:m?{"@type":"Person",name:m}:{"@type":"Organization",name:"Cilium",url:g},publisher:{"@type":"Organization",name:"Cilium",url:g,logo:{"@type":"ImageObject",url:`${g}/images/social-preview.jpg`}},...f&&{image:{"@type":"ImageObject",url:f,width:1200,height:630}},...(null==u?void 0:u.length)>0&&{keywords:u.join(", ")}};return l.createElement(c.A,{data:w,type:"article",datePublished:p,jsonLd:y})};function m(e){return l.createElement(p,e,l.createElement(s,e))}}}]);
2//# sourceMappingURL=component---src-templates-blog-post-jsx-content-file-path-src-posts-2020-02-18-cilium-17-index-md-8842fa9b950e1f74c4e6.js.map

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.