Loading…
Attending this event?
Cilium + eBPF Day clear filter
Tuesday, November 12
 

9:10am MST

Confluent's Multi-Cloud Journey to Cilium: Pitfalls and Lessons Learned - Nimisha Mehta & Alvaro Aleman, Confluent
Tuesday November 12, 2024 9:10am - 9:35am MST
Confluent Cloud is a data streaming platform built on thousands of Kubernetes clusters across AWS, Azure & GCP. Confluent migrated clusters to use Cilium for its advanced security features like transparent encryption and DNS name-based network policies, along with performance, scalability & observability improvements. The main challenge was executing a live migration without disrupting stateful workloads, complicated by the risks of replacing a low-level component like the CNI. The process required meticulous planning to ensure intra-cluster connectivity during migration, while accommodating each cloud provider's unique network config. This talk shares the journey of migrating to Cilium, highlighting obstacles and lessons learned. We will explore uninstalling pre-existing CNIs, setting up Cilium & addressing cloud-specific issues to maintain connectivity. Benefits like transparent encryption, policies, and Hubble observability, along with the challenges faced, will also be discussed.
Speakers
avatar for Alvaro Aleman

Alvaro Aleman

Software Engineer, Confluent
Alvaro is a software engineer with a deep passion for infrastructure and open source. He has been working with Kubernetes since 2017 and is a maintainer of the popular controller-runtime library.
avatar for Nimisha Mehta

Nimisha Mehta

Software Engineer, Confluent
Nimisha is a Software Engineer working on Confluent's Kubernetes Platform team. Previously, she helped build Oracle Cloud’s managed Kubernetes service. Apart from learning about distributed systems and infrastructure, she enjoys volunteering, cycling & cooking.
Tuesday November 12, 2024 9:10am - 9:35am MST
Salt Palace | Level 1 | Grand Ballroom BD
  Cilium + eBPF Day, Use Cases

9:45am MST

Insightful Traffic Monitoring: Harnessing Cilium for Comprehensive Network Observability - Sudheendra Murthy & Adithya Yavanamanda, eBay
Tuesday November 12, 2024 9:45am - 10:10am MST
eBay's cloud consists of thousands of microservices running on millions of containers across hundreds of Kubernetes clusters. In this dynamic & complex cloud environment, mapping dependencies between microservices is crucial. This session delves into how eBay innovatively and scalably uses Cilium, powered by eBPF, to monitor traffic flows, generate real-time traffic events and construct a comprehensive dependency graph of microservice interactions across hundreds of K8s clusters.

The presentation will cover:
  • The innovative use of eBPF and Cilium to monitor traffic events in near real-time 
  • How traffic events are mapped to different microservices
  • The architecture and design of the scalable solution to handle the large volume data
  • The integration of OpenTelemetry for efficient traffic event stream processing
  • Key challenges and solutions in building and maintaining the dependency graph
  • Insights and lessons learned from integrating eBPF and Cilium into eBay’s infrastructure
Speakers
avatar for Adithya Yavanamanda

Adithya Yavanamanda

Software Engineer, eBay
Software engineer interested in distributed systems, currently working on securing large scale kubernetes infrastructure at eBay Inc meandering between all layers from linux kernel to distributed control planes.
avatar for Sudheendra Murthy

Sudheendra Murthy

Principal Engineer & Cloud Architect, eBay
Sudheendra is a Principal Engineer and Cloud Architect in the Cloud Infrastructure group at eBay. He has more than 14 years of experience in cloud technologies including Kubernetes, Micro-segmentation, SDN, OpenStack and designing highly scalable and performant systems.
Tuesday November 12, 2024 9:45am - 10:10am MST
Salt Palace | Level 1 | Grand Ballroom BD
  Cilium + eBPF Day, Use Cases

11:15am MST

Reinventing Seccomp for Fun and Profiles - Amit Schendel, ARMO & Dor Serero, Microsoft
Tuesday November 12, 2024 11:15am - 11:40am MST
Seccomp has long been a critical security feature in the Linux kernel, as a powerful tool for access control. With the emergence of eBPF, the landscape of kernel security has started evolving rapidly. It offers opportunities for improving and extending security policies. In this talk we will show how to achieve some of seccomp's capabilities and extend them using eBPF and KRSI in security use cases. The talk will give an overview of Seccomp in general and in Kubernetes, focus on its importance in securing containerized workloads. We will review applicable eBPF capabilities, showing how it changes the way we can inspect and filter syscalls at runtime. We will introduce KRSI and LSM, showing how they can enhance kernel security. The session will end with a demo of our PoC that leverages eBPF and KRSI to create a modern alternative to seccomp. Illustrating a real-world option, will provide attendees with practical knowledge on how to reinvent Seccomp for enhanced security.
Speakers
avatar for Amit Schendel

Amit Schendel

Sr. Security Researcher, ARMO
Passionate about security research and low-level programming with a focus on kernel drivers (Windows & Linux). Proficient in C++, Python, and Go. Excited about tackling complex challenges at the intersection of cybersecurity, system-level development and cloud technologies.
avatar for Dor Serero

Dor Serero

Principal Software Engineer, Microsoft
Dor Serero is a Principal Software Engineer at Microsoft. Dor is passionate about distributed systems and security. Outside of work, you can find Dor spending time with his wife and two daughters or holding a video game controller.
Tuesday November 12, 2024 11:15am - 11:40am MST
Salt Palace | Level 1 | Grand Ballroom BD
  Cilium + eBPF Day, Use Cases

5:00pm MST

⚡ Lightning Talk: Don't Get Blown up! Avoiding Configuration Gotchas for Tetragon Newbies - Pratik Lotia, Reddit
Tuesday November 12, 2024 5:00pm - 5:10pm MST
This talk will dive into five common configuration pitfalls that beginners encounter when using Tetragon for runtime observability on their workloads. We'll explore the implications of each gotcha and provide clear steps to avoid them. The talk will also cover best practices for configuring Tetragon in a Kubernetes environment.
Speakers
avatar for Pratik Lotia

Pratik Lotia

Senior Cloud Security Engineer, Reddit
Pratik Lotia is an infrastructure security engineer at Reddit, where he is responsible for building tools and processes for implementing security best practices for cloud native environments. He has extensive experience working on security projects for public & private clouds and... Read More →
Tuesday November 12, 2024 5:00pm - 5:10pm MST
Salt Palace | Level 1 | Grand Ballroom BD
  Cilium + eBPF Day, Use Cases

5:15pm MST

⚡ Lightning Talk: Applying Cilium at Edge with KubeEdge - Tomoya Fujita, Sony Corporation of America
Tuesday November 12, 2024 5:15pm - 5:25pm MST
Applications at edge environment can be platform dependent, complicated and distributed in regions, and the number of devices significantly increases. Our final goal is to create the infrastructure that can be applied to the entire environment crossing over the cloud and edge in common. Working with KubeEdge and Cilium, we are now successfully able to use Cilium with KubeEdge hosted nodes at edge environment. This means, enabling wireguard VPN with Cilium can provide the transparent network connectivity with the nodes running in the cloud infrastructure, so that edge nodes running at edge environment just appear to be a member of cluster system but with edge autonomy feature provided by KubeEdge. We would like to share our technical insights and experience with using Cilium at edge with KubeEdge, and what are the future development and contribution with Cilium community.
Speakers
avatar for Tomoya Fujita

Tomoya Fujita

Senior Staff Software Engineer, Sony Corporation of America
Software Engineer, Sony Corporation of America System software architect and developer in Sony Corporation R&D Center. A member of ROS(Robot Operating System) TSC(Technical Steering Committee): https://index.ros.org/doc/ros2/Governance/ Github: https://github.com/fujitatomoya
Tuesday November 12, 2024 5:15pm - 5:25pm MST
Salt Palace | Level 1 | Grand Ballroom BD
  Cilium + eBPF Day, Use Cases
 

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
  • AppDeveloperCon
  • ArgoCon
  • BackstageCon
  • Breaks
  • Cilium + eBPF Day
  • Cloud Native AI + Kubernetes Day
  • Cloud Native StartupFest
  • Cloud Native University
  • Data on Kubernetes Day
  • EnvoyCon
  • Istio Day
  • Kubernetes on Edge Day
  • Observability Day
  • OpenFeature Summit
  • OpenTofu Day
  • Platform Engineering Day
  • WasmCon