Cilium的网络加速秘诀最要的推动作用。 截止 2021.10 ,cilium github 项目已有 9.3K star,Contributors 316位 cilium的特色功能: • 网络功能 • 负载均衡 • 网络安全 • 可观察性 • 多集群连通 注:本 PPT 基于 cilium v1.10.4 进行分析 ��������������� ��������������� �������������������� 开销” eBPF 简介 eBPF 技术 在 Linux kernel 3.19 开始被 引入,可在用户态进行 eBPF 程序编程,编译 后,动态加载到内核指定的 hook 点上,以 VM 方式安全运行,其能过通过 map 存储结 构存储数据,能通过 map 同用户态程序交互, 最终实现内核数据进行修改,或者影响内核处 理请求的结果,或者改变内核处理请求的流程。 极大提升了内核处理事件的效率。0 码力 | 14 页 | 11.97 MB | 1 年前3
Cilium v1.10 Documentationhyperthreading: Enabled name: master platform: {} replicas: 3 metadata: creationTimestamp: null name: cluster-1 networking: clusterNetwork: - cidr: 10.128.0.0/14 hostPrefix: 23 machineNetwork: system:serviceaccount:cilium-test:default priority: null readOnlyRootFilesystem: false runAsUser: type: MustRunAsRange seLinuxContext: type: MustRunAs volumes: null allowHostDirVolumePlugin: false allowHostIPC: : false allowPrivilegedContainer: false allowedCapabilities: null defaultAddCapabilities: null requiredDropCapabilities: null groups: null EOF Deploy the connectivity test You can deploy the “connectivity-check”0 码力 | 1307 页 | 19.26 MB | 1 年前3
Cilium v1.11 Documentationhyperthreading: Enabled name: master platform: {} replicas: 3 metadata: creationTimestamp: null name: cluster-1 networking: clusterNetwork: - cidr: 10.128.0.0/14 hostPrefix: 23 machineNetwork: system:serviceaccount:cilium-test:default priority: null readOnlyRootFilesystem: false runAsUser: type: MustRunAsRange seLinuxContext: type: MustRunAs volumes: null allowHostDirVolumePlugin: false allowHostIPC: : false allowPrivilegedContainer: false allowedCapabilities: null defaultAddCapabilities: null requiredDropCapabilities: null groups: null EOF Deploy the connectivity test You can deploy the “connectivity-check”0 码力 | 1373 页 | 19.37 MB | 1 年前3
Cilium v1.9 Documentationhyperthreading: Enabled name: master platform: {} replicas: 3 metadata: creationTimestamp: null name: cluster-1 networking: clusterNetwork: - cidr: 10.128.0.0/14 hostPrefix: 23 machineNetwork: system:serviceaccount:cilium-test:default priority: null readOnlyRootFilesystem: false runAsUser: type: MustRunAsRange seLinuxContext: type: MustRunAs volumes: null allowHostDirVolumePlugin: false allowHostIPC: : false allowPrivilegedContainer: false allowedCapabilities: null defaultAddCapabilities: null requiredDropCapabilities: null groups: null EOF Deploy the connectivity test You can deploy the “connectivity-check”0 码力 | 1263 页 | 18.62 MB | 1 年前3
Cilium v1.8 Documentationhyperthreading: Enabled name: master platform: {} replicas: 3 metadata: creationTimestamp: null name: cluster-1 networking: clusterNetwork: - cidr: 10.128.0.0/14 hostPrefix: 23 machineNetwork: system:serviceaccount:cilium-test:default priority: null readOnlyRootFilesystem: false runAsUser: type: MustRunAsRange seLinuxContext: type: MustRunAs volumes: null allowHostDirVolumePlugin: false allowHostIPC: : false allowPrivilegedContainer: false allowedCapabilities: null defaultAddCapabilities: null requiredDropCapabilities: null groups: null EOF Deploy the connectivity test You can deploy the “connectivity-check”0 码力 | 1124 页 | 21.33 MB | 1 年前3
Cilium v1.6 Documentationempire-announce >>[2018-04-10 23:50:34,638] ERROR Error when sending message to topic empire-announce with key: null, value: 27 bytes with error: (org.apache.kafka.clients.producer.internals.ErrorLoggingCallback) org ys\":\"$((($KEYID+1))) "rfc4106\(gcm\ (aes\)\)" $(echo $(dd if=/dev/urandom count=20 bs=1 2> /dev/null| xxd - p -c 64)) 128\"}}") kubectl patch secret -n cilium cilium-ipsec-keys -p="${data}" -v=1 Then test message [2017-12-07 02:13:47,020] ERROR Error when sending message to topic authaudit with key: null, value: 12 bytes with error: (org.apache.kafka.clients.producer.internals.ErrorLoggingCallback) org0 码力 | 734 页 | 11.45 MB | 1 年前3
Cilium v1.7 Documentationempire-announce >>[2018-04-10 23:50:34,638] ERROR Error when sending message to topic empire-announce with key: null, value: 27 bytes with error: (org.apache.kafka.clients.producer.internals.ErrorLoggingCallback) org ys\":\"$((($KEYID+1))) "rfc4106\(gcm\ (aes\)\)" $(echo $(dd if=/dev/urandom count=20 bs=1 2> /dev/null| xxd - p -c 64)) 128\"}}") kubectl patch secret -n kube-system cilium-ipsec-keys -p="${data}" -v=1 test message [2017-12-07 02:13:47,020] ERROR Error when sending message to topic authaudit with key: null, value: 12 bytes with error: (org.apache.kafka.clients.producer.internals.ErrorLoggingCallback) org0 码力 | 885 页 | 12.41 MB | 1 年前3
Cilium v1.5 Documentationcert-file: '/var/lib/etcd-secrets/etcd-client.crt' kind: ConfigMap metadata: creationTimestamp: null name: cilium-config selfLink: /api/v1/namespaces/kube-system/configmaps/cilium-config In the cert-file: '/var/lib/etcd-secrets/etcd-client.crt' kind: ConfigMap metadata: creationTimestamp: null name: cilium-config selfLink: /api/v1/namespaces/kube-system/configmaps/cilium-config Apply following: Host runtime HostName 127.0.0.1 User vagrant Port 2222 UserKnownHostsFile /dev/null StrictHostKeyChecking no PasswordAuthentication no IdentityFile /home/eloy/.go/src/github0 码力 | 740 页 | 12.52 MB | 1 年前3
共 8 条
- 1













