Cilium v1.5 Documentation
BPF runs inside the Linux kernel, Cilium security policies can be applied and updated without any changes to the applica�on code or container configura�on. Why Cilium? The development of modern datacenter individual containers ge�ng started or destroyed as the applica�on scales out / in to adapt to load changes and during rolling updates that are deployed as part of con�nuous delivery. This shi� toward highly As a precau�on, we will use Is�o’s service rou�ng feature to canary the v2 deployment to prevent breaking the end-to-end applica�on completely if it is faulty. Before deploying v2 , to prevent any traffic0 码力 | 740 页 | 12.52 MB | 1 年前3Cilium v1.6 Documentation
BPF runs inside the Linux kernel, Cilium security policies can be applied and updated without any changes to the application code or container configuration. Why Cilium? The development of modern datacenter individual containers getting started or destroyed as the application scales out / in to adapt to load changes and during rolling updates that are deployed as part of continuous delivery. This shift toward highly a precaution, we will use Istio’s service routing feature to canary the v2 deployment to prevent breaking the end-to-end application completely if it is faulty. Before deploying v2, to prevent any traffic0 码力 | 734 页 | 11.45 MB | 1 年前3Cilium v1.11 Documentation
Verifying Your Development Setup Requirements Vagrant Setup Local Development in Vagrant Box Making Changes Add/update a golang dependency Add/update a new Kubernetes version Optional: Docker and IPv6 Debugging tests Testing individual packages Running individual tests Automatically run unit tests on code changes BPF and XDP Reference Guide BPF Architecture Instruction Set Helper Functions Maps Object Pinning eBPF runs inside the Linux kernel, Cilium security policies can be applied and updated without any changes to the application code or container configuration. What is Hubble? Hubble is a fully distributed0 码力 | 1373 页 | 19.37 MB | 1 年前3Cilium v1.7 Documentation
request merged Development Setup Requirements Vagrant Setup Local Development in Vagrant Box Making Changes Add/update a golang dependency Debugging Building Container Images Developer images Official release tests Testing individual packages Running individual tests Automatically run unit tests on code changes BPF and XDP Reference Guide BPF Architecture Instruction Set Helper Functions Maps Object Pinning BPF runs inside the Linux kernel, Cilium security policies can be applied and updated without any changes to the application code or container configuration. Why Cilium? The development of modern datacenter0 码力 | 885 页 | 12.41 MB | 1 年前3Cilium v1.10 Documentation
Verifying Your Development Setup Requirements Vagrant Setup Local Development in Vagrant Box Making Changes Add/update a golang dependency Add/update a new Kubernetes version Optional: Docker and IPv6 Debugging tests Testing individual packages Running individual tests Automatically run unit tests on code changes BPF and XDP Reference Guide BPF Architecture Instruction Set Helper Functions Maps Object Pinning eBPF runs inside the Linux kernel, Cilium security policies can be applied and updated without any changes to the application code or container configuration. What is Hubble? Hubble is a fully distributed0 码力 | 1307 页 | 19.26 MB | 1 年前3Cilium v1.9 Documentation
of Origin Development Setup Requirements Vagrant Setup Local Development in Vagrant Box Making Changes Add/update a golang dependency Add/update a new Kubernetes version Optional: Docker and IPv6 Debugging tests Testing individual packages Running individual tests Automatically run unit tests on code changes BPF and XDP Reference Guide BPF Architecture Instruction Set Helper Functions Maps Object Pinning eBPF runs inside the Linux kernel, Cilium security policies can be applied and updated without any changes to the application code or container configuration. What is Hubble? Hubble is a fully distributed0 码力 | 1263 页 | 18.62 MB | 1 年前3Cilium v1.8 Documentation
of Origin Development Setup Requirements Vagrant Setup Local Development in Vagrant Box Making Changes Add/update a golang dependency Optional: Docker and IPv6 Debugging Building Container Images Developer tests Testing individual packages Running individual tests Automatically run unit tests on code changes BPF and XDP Reference Guide BPF Architecture Instruction Set Helper Functions Maps Object Pinning BPF runs inside the Linux kernel, Cilium security policies can be applied and updated without any changes to the application code or container configuration. What is Hubble? Hubble is a fully distributed0 码力 | 1124 页 | 21.33 MB | 1 年前3The Tale of Smokey and the Crypto Bandits
Attempt #1 - The Postmortem Iteration is key ● Built a tool to automatically reload falco on rule changes ● Rules: monitor well known IPs, binary names, forbidden k8s actions ● Action: Notify to slack0 码力 | 14 页 | 926.57 KB | 1 年前3bpfbox: Simple Precise Process Confinement with eBPF and KRSI
confinement mechanisms are difficult to use SELinux AppArmor TOMOYO ▶ Can we do any better? 2 / 7 eBPF Changes the Game eBPF enables: ▶ Fine-grained system introspection ▶ Integration of cross-layer state (kprobes0 码力 | 8 页 | 528.12 KB | 1 年前3
共 9 条
- 1