thebsdbox's profile picture. Conjurer of cheap tricks 🧙🏼@ciliumproject/@isovalent 

http://github.com/thebsdbox && @kube_vip 

Past: @Heptio, @Docker, @EquinixMetal, @HPE

Dan 🐝

@thebsdbox

Conjurer of cheap tricks 🧙🏼@ciliumproject/@isovalent http://github.com/thebsdbox && @kube_vip Past: @Heptio, @Docker, @EquinixMetal, @HPE

kube-gateway.io or github.com/kube-vip/kube-… the kTLS implementation isn't particularly exciting just punting the traffic into the kernel basically (needs the kernel module loading)

Ok I need to see that code now .Nice



Finally implemented in kernel TLS for mTLS between pods.

thebsdbox's tweet image. Finally implemented in kernel TLS for mTLS between pods.

Power cut two weeks ago resulted in my main @Synology NAS dying, luckily I had a back NAS that mirrors the main… sadly that died as well due to the power cut. 🫠


thebsdbox.co.uk/2025/07/17/egr… Excited to finally get the new egress in kube-vip.io out the door. As we slowly reach a v1.0 release 😱


What I’m now calling egressV2 is pretty much done in @kube_vip, native kernel calls and simple nftables rules should make for a much nicer experience. github.com/kube-vip/kube-…


Dan 🐝 รีโพสต์แล้ว

e in eBPF stands for easy


Only took 9 years

thebsdbox's tweet image. Only took 9 years

Wow ephemeral containers allow for some funky stuff! I can easily apply a ephemeral container that intercepts traffic (with eBPF 🐝) and transparently encrypts it between pods. Doesn't show up as a container, so does that mean it isn't a sidecar 🤔


With a fix to ephemeral containers in v1.33 in @kubernetesio it’s now possible to add mTLS to an existing pod, no admission controller/webhook needed anymore. 🤩


Dan 🐝 รีโพสต์แล้ว

might be biased, but i think the work we are doing at @LoopholeLabs with eBPF is among some of the most interesting use-cases in the entire space youtube.com/watch?v=Y_C4Ti…

d_philla's tweet card. eCHO Episode 171: Migrating and Managing VMs using eBPF

youtube.com

YouTube

eCHO Episode 171: Migrating and Managing VMs using eBPF


Dan 🐝 รีโพสต์แล้ว

We have a blog post coming out soon where we show how outbound XDP can improve application throughput by 2x - with no changes to the host or the application.


Dan 🐝 รีโพสต์แล้ว

Though veth would seem like a perfect fit for container networking, but practitioners soon discovered it had a number bottlenecks that slowed communication rates across containers. thenewstack.io/bytedance-to-n… #NetKit @thenewstack #Linux #eBPF


Dan 🐝 รีโพสต์แล้ว

XFRM Reference Guidefrom @ciliumproject documentation is excellent , best place I found to explain this complex subsystem of the Linux kernel docs.cilium.io/en/latest/refe…


thebsdbox.co.uk/kube-vip/ Made a manifest generator for @kube_vip … quite proud of my little attempt into html/javascript.


Come join @raphink and myself in 40 minutes! youtube.com/watch?v=bnTloC… We will walk through building a service mesh from scratch with some eBPF (and a bit of luck) 🐝

thebsdbox's tweet card. eBPF Episode 163: Creating a service mesh from scratch with eBPF

youtube.com

YouTube

eBPF Episode 163: Creating a service mesh from scratch with eBPF


thebsdbox.co.uk/2024/12/02/Con… Wrote up the second part about building your own service mesh, with eBPF intercepting the traffic we need the final pieces to finish end to end connectivity 😀


Loading...

Something went wrong.


Something went wrong.