Envoy Mesh Acceleration: From Iptables to Fully BPF
CNCF [Cloud Native Computing Foundation] via YouTube
Build the Finance Skills That Lead to Promotions, Not Just Certificates
Free courses from frontend to fullstack and AI
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk examines how iptables traffic redirection affects Envoy and container communication through eBPF sockmaps, then presents an approach that uses eBPF for inbound and outbound traffic without iptables. It also describes control-plane support for DaemonSet deployment and configuration.
Syllabus
Intro
Istio Architecture
Agenda
Pod Initialization
Iptables Rules
Traffic hijacking
Envoy VirtualOutbound
What is eBPF?
Cilium
eBPF Architecture
eBPF Hello World
TCP Inbound
eBPF Map
Smart DNS Proxying
UDP Outbound
Sockmap
eBPF Prog
Duplicate Sock Key
Linux kernel Patch
Deploy
Performance
Taught by
CNCF [Cloud Native Computing Foundation]