TikTok's IPv6 Journey to Cilium - Pitfalls and Lessons Learned
CNCF [Cloud Native Computing Foundation] via YouTube
Get 20% off all career paths from fullstack to AI
Build AI Apps with Azure, Copilot, and Generative AI — Microsoft Certified
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
Learn about TikTok's migration to Cilium for Kubernetes networking and security in IPv6-only datacenters through this conference talk. Discover the unique challenges faced when implementing Cilium in an IPv6-only environment, as most battle-testing has been done with IPv4 and dual-stack configurations. Explore the technical limitations encountered, including Cilium's lack of tunneling support over IPv6 requiring native routing mode configuration. Understand the specific IPv6-related bugs discovered during implementation, such as NDP traffic being incorrectly dropped by Cilium Network Policy, DNS policy issues preventing traffic to IPv6 DNS servers, and broken debugging tools when IPv4 BPF maps are absent. Examine the NodePort timeout issue that prevented full replacement of kube-proxy and learn the techniques developed to overcome these obstacles. Gain insights into the lessons learned from deploying advanced security features like mutual authentication alongside high-performance networking and enhanced observability in a production IPv6-only Kubernetes environment.
Syllabus
TikTok's IPv6 Journey To Cilium: Pitfalls and Lessons Learned - Giri Kuncoro & Joseph Pallamidessi
Taught by
CNCF [Cloud Native Computing Foundation]