The Tale of Smokey and the Crypto Bandits## The Tale of Smokey and the Crypto Bandits How Okteto uses Falco to keep users happy and our platform healthy eBPF Summit Ramiro Berrelleza ## Hey everyone! • Co-founder of Okteto ● Former architect com> Hi Ramiro, Open Source to the rescue! ## X Falco Attempt #1 - We were young and naive • Installed Falco in the clusters - Configured it with the default rules plus our own jpg) ## Attempt #1 - The Postmortem - The default falco rules are not well suited for a dev platform • The processing overhead is non-trivial - Falco's eBPF module + ContainerOS was not very performant0 码力 | 14 页 | 926.57 KB | 1 年前3
2020 中国开源年度报告
所有的例外情况(包括拒绝)均由 TOC 来处理。目前该阶段的项目有 Argo、Buildpacks、CloudEvents、CNI、Contour、Cortex、CRI-O、Dragonfly、Falco、gRPC、KubeEdge、Linkerd、NATS、Notary、Open Policy Agent、OpenTracing、Operator Framework、SPIFFE、SPIRE、Thanos 9|316|3041|236|489|549| |22|projectcontour/contour|Go|833.89|182|3608|437|684|2113| |23|falcosecurity/falco|C++|744.34|253|4132|229|276|425| |24|spiffe/spire|Go|568.48|73|1139|222|450|1697| |25|fluent/fluentd|Ruby|5350 码力 | 46 页 | 4.09 MB | 2 年前3
Buzzing Across Spacebetter level of control than traditional solutions. Projects using eBPF for security purposes include Falco, Tetragon, or Tracee. Alas! During the fight a thruster was damaged. Once at the space garage, Captain0 码力 | 32 页 | 32.98 MB | 1 年前3
So You Think You Can Hash## A Unified Proposal for Composable Hashing Document number: N3980 Howard E. Hinnant Vinnie Falco John Bytheway 2014-05-24 ## Types Don't Know # N. Josuttis: P0814R2: hash_combine() Again0 码力 | 119 页 | 6.54 MB | 1 年前3
Falcon v1.4.0 Documentationtype to use as the value for the Content-Type header on responses (default ‘application/json’). The falco module provides a number of constants for common media types, such as falcon.MEDIA_MSGPACK, falcon0 码力 | 230 页 | 271.65 KB | 2 年前3
Falcon v1.4.1 Documentationtype to use as the value for the Content-Type header on responses (default ‘application/json’). The falco module provides a number of constants for common media types, such as falcon.MEDIA_MSGPACK, falcon0 码力 | 231 页 | 272.52 KB | 2 年前3
Falcon v1.4.1-post-1 Documentationtype to use as the value for the Content-Type header on responses (default ‘application/json’). The falco module provides a number of constants for common media types, such as falcon.MEDIA_MSGPACK, falcon0 码力 | 229 页 | 273.39 KB | 2 年前3
Falcon v2.0.0 Documentationtype to use as the value for the Content-Type header on responses (default ‘application/json’). The falco module provides a number of constants for common media types, such as falcon.MEDIA_MSGPACK, falcon0 码力 | 265 页 | 299.57 KB | 2 年前3
2022年美团技术年货 合辑在网络编排领域,表现尤为亮眼,逐步代替 iptables 等产品,大有一统江山的趋势。而在监控、观测等领域也有很多产品。尤其是运行时安全(Runtime Security)领域,Datadog、Falco、Google 等公司也都推出了相应的产品。感兴趣的同学,可以参考相关产品源码分析(Cilium eBPF 实现机制源码分析、Datadog 的 eBPF 安全检测机制分析)的分享。 我们回顾一下 的开发者也写了一篇文章,讲解不同场景的处理方案 bpF-core-reference-guide。 ## 大型项目 在国外,云原生领域产品发展较快,涌现出一批批基于 eBPF 的产品,包括 Cilium、Datadog、Falco、Katran 等,应用在网络编排、网络防火墙、跟踪定位、运行时安全等各个领域,可以借鉴这些大型项目的研发经验,来加快产品建设,包括多系统兼容、框架设计、项目质量、监控体系建设等。本篇以检测防御为0 码力 | 1356 页 | 45.90 MB | 2 年前3
共 9 条
- 1













