Главная
Study mode:
on
1
Intro
2
Istio Architecture
3
Agenda
4
Pod Initialization
5
Iptables Rules
6
Traffic hijacking
7
Envoy VirtualOutbound
8
What is eBPF?
9
Cilium
10
eBPF Architecture
11
eBPF Hello World
12
TCP Inbound
13
eBPF Map
14
Smart DNS Proxying
15
UDP Outbound
16
Sockmap
17
eBPF Prog
18
Duplicate Sock Key
19
Linux kernel Patch
20
Deploy
21
Performance
Description:
Explore Envoy mesh acceleration techniques in this conference talk that transitions from iptables to fully BPF-based solutions. Delve into the challenges of transparent traffic hijacking and its impact on system performance. Examine current solutions, including Cilium and lightweight approaches, and understand how iptables redirections affect sockmap match results for inbound and outbound traffic. Discover a novel iptables-free solution that utilizes eBPF for traffic direction, provides transparent outbound traffic redirection, and offers an integrated control plane for Daemonset deployment. Learn about eBPF architecture, sockmap implementation, and performance improvements in this comprehensive exploration of service mesh acceleration techniques.

Envoy Mesh Acceleration: From Iptables to Fully BPF

CNCF [Cloud Native Computing Foundation]
Add to list
0:00 / 0:00