Cilium v1.6 DocumentationREADY STATUS RESTARTS AGE pod/mediabot 1/1 Running 0 14s Apply DNS Egress Policy The following Cilium network policy allows mediabot pods to only access c8493120-bf57-11e8-98e6- f1a9f45fc4d8 | e74a0300-94f3-4b3d-aee4-fea85eca5af7 | True 53ed94d0-ddac-4b14-8c2f-ba6f83a8218c | c641a150-bf57-11e8-98e6- f1a9f45fc4d8 | 104ddbb6-f2f7-4cd0-8683-cc18cccc1326 |11211/TCP 14m NAME READY STATUS RESTARTS AGE pod/a-wing-67db8d5fcc-dpwl4 1/1 Running 0 14m pod/alliance-tracker-6b6447bd69-sz5hz 0 码力 | 734 页 | 11.45 MB | 1 年前3
Cilium v1.8 Documentationmetadata: creationTimestamp: null name: cluster-1 networking: clusterNetwork: - cidr: 10.128.0.0/14 hostPrefix: 23 machineNetwork: - cidr: 10.0.0.0/16 networkType: Cilium serviceNetwork: - 172 ipam.operator.clusterPoolIPv4PodCIDR=10.128.0.0/14 \ --set global.ipam.operator.clusterPoolIPv4MaskSize=23 \ --set global.nativeRoutingCIDR=10.128.0.0/14 \ --set config.bpfMasquerade=false \ --set to empire ships only Kind: CiliumNetworkPolicy Metadata: Creation Timestamp: 2020-06-15T14:06:48Z Generation: 1 Managed Fields: API Version: cilium.io/v2 Fields Type: FieldsV10 码力 | 1124 页 | 21.33 MB | 1 年前3
Cilium v1.9 Documentationmetadata: creationTimestamp: null name: cluster-1 networking: clusterNetwork: - cidr: 10.128.0.0/14 hostPrefix: 23 machineNetwork: - cidr: 10.0.0.0/16 networkType: Cilium serviceNetwork: - 172 --set ipam.operator.clusterPoolIPv4PodCIDR=10.128.0.0/14 \ --set ipam.operator.clusterPoolIPv4MaskSize=23 \ --set nativeRoutingCIDR=10.128.0.0/14 \ --set bpf.masquerade=false \ --set endpointRoutes to empire ships only Kind: CiliumNetworkPolicy Metadata: Creation Timestamp: 2020-06-15T14:06:48Z Generation: 1 Managed Fields: API Version: cilium.io/v2 Fields Type: FieldsV10 码力 | 1263 页 | 18.62 MB | 1 年前3
Cilium v1.7 DocumentationREADY STATUS RESTARTS AGE pod/mediabot 1/1 Running 0 14s Apply DNS Egress Policy The following Cilium network policy allows mediabot pods to only access READY STATUS RESTARTS AGE pod/mediabot 1/1 Running 0 14s A Brief Overview of the TLS Certificate Model TLS is a protocol that “wraps” other protocols like c8493120-bf57-11e8-98e6- f1a9f45fc4d8 | e74a0300-94f3-4b3d-aee4-fea85eca5af7 | True 53ed94d0-ddac-4b14-8c2f-ba6f83a8218c | c641a150-bf57-11e8-98e6- f1a9f45fc4d8 | 104ddbb6-f2f7-4cd0-8683-cc18cccc1326 |0 码力 | 885 页 | 12.41 MB | 1 年前3
Cilium v1.10 Documentationmetadata: creationTimestamp: null name: cluster-1 networking: clusterNetwork: - cidr: 10.128.0.0/14 hostPrefix: 23 machineNetwork: - cidr: 10.0.0.0/16 networkType: Cilium serviceNetwork: - 172 to empire ships only Kind: CiliumNetworkPolicy Metadata: Creation Timestamp: 2020-06-15T14:06:48Z Generation: 1 Managed Fields: API Version: cilium.io/v2 Fields Type: FieldsV1 f:ingress: Manager: kubectl Operation: Update Time: 2020-06-15T14:06:48Z Resource Version: 2914 Self Link: /apis/cilium.io/v2/namespaces/default/cilium0 码力 | 1307 页 | 19.26 MB | 1 年前3
Cilium v1.5 DocumentationREADY STATUS RESTARTS AGE pod/mediabot 1/1 Running 0 14s Apply DNS Egress Policy The following Cilium network policy allows mediabot pods to only access fc4d 5b9a7990-657e-442d-a3f7-94484f06696e | c8493120-bf57-11e8-98e6-f1a9f45fc4d 53ed94d0-ddac-4b14-8c2f-ba6f83a8218c | c641a150-bf57-11e8-98e6-f1a9f45fc4d 074ad3b9-a47d-4ebc-83d3-cad75b1911ce | 9 Running 0 14m pod/alliance-tracker-6b6447bd69-sz5hz 1/1 Running 0 14m pod/memcached-server-bdbfb87cd-8tdh7 1/1 Running 0 14m pod/x-wing-fd5dfb9d9-wrtwn0 码力 | 740 页 | 12.52 MB | 1 年前3
Cilium v1.11 Documentationmetadata: creationTimestamp: null name: cluster-1 networking: clusterNetwork: - cidr: 10.128.0.0/14 hostPrefix: 23 machineNetwork: - cidr: 10.0.0.0/16 networkType: Cilium serviceNetwork: - 172 to empire ships only Kind: CiliumNetworkPolicy Metadata: Creation Timestamp: 2020-06-15T14:06:48Z Generation: 1 Managed Fields: API Version: cilium.io/v2 Fields Type: FieldsV1 f:ingress: Manager: kubectl Operation: Update Time: 2020-06-15T14:06:48Z Resource Version: 2914 Self Link: /apis/cilium.io/v2/namespaces/default/cilium0 码力 | 1373 页 | 19.37 MB | 1 年前3
Steering connections to sockets with BPF socket lookup hook{pathname="/home/vagrant/bpffs/echo_socket", …}, …) = 5 bpf(BPF_MAP_UPDATE_ELEM, {map_fd=5, key=0x7fff9c4e0b14, value=0x7fff9c4e0b08}, 120) = 0 +++ exited with 0 +++ $ bpftool map dump pinned $HOME/bpffs/echo_socket f/echo_dispatch_link", bpf_fd=5, …) = 0 # bpftool link show pinned /sys/fs/bpf/echo_dispatch_link 14: netns prog 75 netns_ino 4026531992 attach_type sk_lookup $ ls -l /proc/self/ns/net lrwxrwxrwx0 码力 | 23 页 | 441.22 KB | 1 年前3
Building a Secure and Maintainable PaaSComplexity 13 CiliumNetworkPolicies Layer 7 HTTP Filtering Outbound to DNS Name Clusterwide Policy 14 Cilium CLI commands Listing Endpoints on a Node Traffic Denied by Policy Traffic Allowed by Policy0 码力 | 20 页 | 2.26 MB | 1 年前3
Can eBPF save us from the Data Deluge?business-critical ● We can blindly drop DoS 13 But could we reduce data transfer size? eBPF filter-reduce 14 Filter Reduce input Result https://github.com/giuliafrascaria/ebpf-data-filter eBPF filter-reduce0 码力 | 18 页 | 266.90 KB | 1 年前3
共 11 条
- 1
- 2













