Главная
Study mode:
on
1
Intro
2
Agenda
3
What is transparent
4
Why is this interesting
5
Brief overview
6
IPSec modes
7
Packets
8
State
9
BPF
10
IP Priority
11
Keys
12
SPiffy
13
Cilium Agent
14
BPF Program
15
Subnet Mode
16
KTLS
17
Cilium Envoy
18
Pain Points
19
L7 Pain Points
20
Key Management
21
BPF Progress
22
Questions
Description:
Explore seamless transparent encryption in dynamic environments using BPF and Cilium in this Linux Plumbers Conference talk. Dive into the challenges of providing encryption in Kubernetes-like environments and learn how Cilium leverages BPF and Linux encryption capabilities to offer L3/L7 encryption and authentication at node and service layers. Discover how to apply encryption to entire nodes or specific services with simple configuration flags. Gain insights into Cilium's management of encrypted traffic and its monitoring interface for compliance auditing. Examine the Linux datapath and control plane implementation, and understand how Cilium integrates with evolving encryption standards like IPsec, mTLS, SPIFFE, and Istio. Explore proposed Linux kernel extensions to improve efficiency and ease adoption of these protocols, including BPF helpers, hardware support, and scaling solutions. Witness a live demo of Cilium implementing transparent encryption and engage in a discussion covering various aspects such as IPSec modes, key management, and future developments in BPF technology. Read more

Seamless Transparent Encryption with BPF and Cilium

Linux Plumbers Conference
Add to list
0:00 / 0:00