A Guided Tour of Cilium Service Mesh - Liz Rice, Isovalent

preview_player
Показать описание

A Guided Tour of Cilium Service Mesh - Liz Rice, Isovalent

The Cilium project is adding Service Mesh features to its existing eBPF-enabled, identity-aware Kubernetes networking capabilities. This demo-driven talk explores how this works, and shows why it’s now possible to create a service mesh without sidecars. - Demonstrate why, before eBPF, the sidecar model was necessary for accessing an application pod’s network traffic - Explore how Cilium uses eBPF programs to connect Kubernetes endpoints - Show how this makes the sidecar model unnecessary for identity-aware connectivity - Demonstrate an example Cilium Service Mesh in use - Compare the resources used (in both userspace and the kernel) for both models Along the way, this talk will clarify some container and kernel concepts so that attendees can leave with a mental model of how eBPF-enabled service mesh really works.
Рекомендации по теме
Комментарии
Автор

Damn. What a clear explanation of L7 policy. The fact it was a hilarious metaphor was just icing on the cake.

DouglasRosser
Автор

Just a great dive into Cilium for newcomers!

romanigorevich
Автор

Excellent session as always from Liz, thanks!

borisaelen
Автор

Could we implement an API Proxy as a Berkely Pack Filter, yeah, yeah, better get estimates!

tomknud