thebsdbox's profile picture. Conjurer of cheap tricks 🧙🏼@ciliumproject/@isovalent 

http://github.com/thebsdbox && @kube_vip 

Past: @Heptio, @Docker, @EquinixMetal, @HPE

Dan 🐝

@thebsdbox

Conjurer of cheap tricks 🧙🏼@ciliumproject/@isovalent http://github.com/thebsdbox && @kube_vip Past: @Heptio, @Docker, @EquinixMetal, @HPE

Amazing time at #KubeCon last week, fantastic people, amazing projects and an all round wonderful time.

thebsdbox's tweet image. Amazing time at #KubeCon last week, fantastic people, amazing projects and an all round wonderful time.
thebsdbox's tweet image. Amazing time at #KubeCon last week, fantastic people, amazing projects and an all round wonderful time.

Big yes from me 😀

The future is really collaborative and community driven

Itsuugo's tweet image. The future is really collaborative and community driven


Anyone considering SIG-BOULDERING. 🧗🏻 next week at #kubecon


Dan 🐝 reposted

We finally decided to write out how we use XDP in our network plane for live network migrations and more specifically to process outgoing packets! This is the first in a series of promised deep dives into how Loophole's live migration tech works! loopholelabs.io/blog/xdp-for-e…

An eBPF Loophole: Using XDP for Egress Traffic XDP is Linux's fastest packet processor but only handles incoming traffic. We found a loophole in how the kernel determines packet direction to make it work for outgoing traffic too! Blog post with details 👇

LoopholeLabs's tweet image. An eBPF Loophole: Using XDP for Egress Traffic

XDP is Linux's fastest packet processor but only handles incoming traffic. We found a loophole in how the kernel determines packet direction to make it work for outgoing traffic too!  

Blog post with details 👇


Capturing input from other sessions through eBPF 🐝, though my initial idea is enabling hot-keys for various use-cases 😀

thebsdbox's tweet image. Capturing input from other sessions through eBPF 🐝, though my initial idea is enabling hot-keys for various use-cases 😀

kube-gateway.io or github.com/kube-vip/kube-… the kTLS implementation isn't particularly exciting just punting the traffic into the kernel basically (needs the kernel module loading)

Ok I need to see that code now .Nice



Finally implemented in kernel TLS for mTLS between pods.

thebsdbox's tweet image. Finally implemented in kernel TLS for mTLS between pods.

Power cut two weeks ago resulted in my main @Synology NAS dying, luckily I had a back NAS that mirrors the main… sadly that died as well due to the power cut. 🫠


Dan 🐝 reposted

We've just announced the next Cloud Native and Kubernetes Edinburgh event, back after a bit of a break over summer with an absolute banger of a meetup that includes the one and only @thebsdbox meetup.com/cloud-native-k…


thebsdbox.co.uk/2025/07/17/egr… Excited to finally get the new egress in kube-vip.io out the door. As we slowly reach a v1.0 release 😱


What I’m now calling egressV2 is pretty much done in @kube_vip, native kernel calls and simple nftables rules should make for a much nicer experience. github.com/kube-vip/kube-…


Dan 🐝 reposted

e in eBPF stands for easy


Only took 9 years

thebsdbox's tweet image. Only took 9 years

Wow ephemeral containers allow for some funky stuff! I can easily apply a ephemeral container that intercepts traffic (with eBPF 🐝) and transparently encrypts it between pods. Doesn't show up as a container, so does that mean it isn't a sidecar 🤔


With a fix to ephemeral containers in v1.33 in @kubernetesio it’s now possible to add mTLS to an existing pod, no admission controller/webhook needed anymore. 🤩


Dan 🐝 reposted

might be biased, but i think the work we are doing at @LoopholeLabs with eBPF is among some of the most interesting use-cases in the entire space youtube.com/watch?v=Y_C4Ti…

d_philla's tweet card. eCHO Episode 171: Migrating and Managing VMs using eBPF

youtube.com

YouTube

eCHO Episode 171: Migrating and Managing VMs using eBPF


Dan 🐝 reposted

We have a blog post coming out soon where we show how outbound XDP can improve application throughput by 2x - with no changes to the host or the application.


Dan 🐝 reposted

Though veth would seem like a perfect fit for container networking, but practitioners soon discovered it had a number bottlenecks that slowed communication rates across containers. thenewstack.io/bytedance-to-n… #NetKit @thenewstack #Linux #eBPF


Loading...

Something went wrong.


Something went wrong.