Cilium - Container Security and Networking Using BPF and XDP
Offered By: Linux Foundation via YouTube
Course Description
Overview
Syllabus
Intro
BPF is revolutionizing... Tracing / Profiling
BPF Revolution #2: XDP-DDoS mitigation
Facebook published BPF/XDP numbers for L3/L4 LB at Netdev 21
BPF Revolution #3: Security
Evolution of Application Design & Delivery Frequency
Network Security for Microservices
Gordon wants to build a service to tweet out all job offerings.
Gordon uses mutual TLS Auth Good thinking Gordon
The security team has L3/L4 network security in place for all services
Back to the drawing board...
Least privilege security for microservices
Kubernetes Integration
Should I encapsulate or not?
L3 Policy (Labels Based)
L3 Policy (CIDR)
Policy - Only allow GET /v1
How are these policies enforced?
What is a sidecar proxy?
Networking Path with a Sidecar
Kernel Proxy
Socket Redirect - Performance?
The Before and After
Cilium Summary
Taught by
Linux Foundation
Tags
Related Courses
The Kernel ReportLinux Foundation via YouTube Detection and Blocking with BPF via YAML
WEareTROOPERS via YouTube Closing the BPF Map Permission Loophole
Linux Plumbers Conference via YouTube Reusing the BPF CI
Linux Plumbers Conference via YouTube Open Source FPGA NVMe Accelerator Platform for BPF Driven ML Processing with Linux - Zephyr
Linux Plumbers Conference via YouTube