Cilium v1.10 Documentationto use ClusterConfig [https://eksctl.io/usage/creating- and-managing-clusters/#using-config-files] file to create the cluster: apiVersion: eksctl.io/v1alpha5 kind: ClusterConfig ... managedNodeGroups: For the Cilium CLI to access the cluster in successive steps you will need to use the kubeconfig file stored at /etc/rancher/k3s/k3s.yaml by setting the KUBECONFIG environment variable: export KUBEC to use ClusterConfig [https://eksctl.io/usage/creating- and-managing-clusters/#using-config-files] file to create the cluster: apiVersion: eksctl.io/v1alpha5 kind: ClusterConfig ... managedNodeGroups:0 码力 | 1307 页 | 19.26 MB | 1 年前3
Cilium v1.11 Documentationto use ClusterConfig [https://eksctl.io/usage/creating- and-managing-clusters/#using-config-files] file to create the cluster: apiVersion: eksctl.io/v1alpha5 kind: ClusterConfig ... managedNodeGroups: For the Cilium CLI to access the cluster in successive steps you will need to use the kubeconfig file stored at /etc/rancher/k3s/k3s.yaml by setting the KUBECONFIG environment variable: export KUBEC to use ClusterConfig [https://eksctl.io/usage/creating- and-managing-clusters/#using-config-files] file to create the cluster: apiVersion: eksctl.io/v1alpha5 kind: ClusterConfig ... managedNodeGroups:0 码力 | 1373 页 | 19.37 MB | 1 年前3
Cilium v1.9 Documentationcni=cilium parameter in minikube start command. With this flag enabled, minikube will not only mount eBPF file system but also deploy quick- install.yaml automatically. However, this may not install the latest you may seek help on Slack. Tip Hubble CLI configuration can be persisted using a configuration file or environment variables. This avoids having to specify options specific to a particular environment you may seek help on Slack. Tip Hubble CLI configuration can be persisted using a configuration file or environment variables. This avoids having to specify options specific to a particular environment0 码力 | 1263 页 | 18.62 MB | 1 年前3
Cilium v1.8 Documentationnetwork-plugin=cilium parameter in minikube start command. With this flag enabled, minikube will not only mount eBPF file system but also deploy quick- install.yaml automatically. 4. Mount the eBPF filesystem minikube creation is done using a YAML configuration file. This step is necessary in order to disable the default CNI and replace it with Cilium. Create a kind-config.yaml file based on the following template. It will conflicts with your local network address range, update the networking section of the kind configuration file to specify different subnets that do not conflict or you risk having connectivity issues when deploying0 码力 | 1124 页 | 21.33 MB | 1 年前3
Cilium v1.5 Documentationgeneric -n kube-system cilium-etcd-secrets \ --from-file=etcd-client-ca.crt=ca.crt \ --from-file=etcd-client.key=client.key \ --from-file=etcd-client.crt=client.crt In case you are not using want to use TLS in etcd, uncomment the 'ca-file' line # and create a kubernetes secret by following the tutorial in # https://cilium.link/etcd-config #ca-file: '/var/lib/etcd-secrets/etcd-client-ca.crt' secret by following the tutorial in # https://cilium.link/etcd-config #key-file: '/var/lib/etcd-secrets/etcd-client.key' #cert-file: '/var/lib/etcd-secrets/etcd-client.crt' Deploy Cilium kubectl create0 码力 | 740 页 | 12.52 MB | 1 年前3
Cilium v1.6 Documentationprepare generating the deployment artifacts based on the Helm templates. Generate the required YAML file and deploy it: helm template cilium \ --namespace kube-system \ --set global.etcd.enabled=true generic -n kube-system cilium-etcd-secrets \ --from-file=etcd-client-ca.crt=ca.crt \ --from-file=etcd-client.key=client.key \ --from-file=etcd-client.crt=client.crt Adjust the helm template generation prepare generating the deployment artifacts based on the Helm templates. Generate the required YAML file and deploy it: helm template cilium \ --namespace kube-system \ --set global.cni.chainingMode=aws-cni0 码力 | 734 页 | 11.45 MB | 1 年前3
Cilium v1.7 DocumentationInstead it uses YAML configuration that is very similar to Kubernetes. Create a kind-config.yaml file based on the following template. The template will create 3 node + 1 apiserver cluster with the latest generic -n kube-system cilium-etcd-secrets \ --from-file=etcd-client-ca.crt=ca.crt \ --from-file=etcd-client.key=client.key \ --from-file=etcd-client.crt=client.crt Adjust the helm template generation Ready agent 8m26s v1.13.10 Create an AKS + Cilium CNI configuration Create a chaining.yaml file based on the following template to specify the desired CNI chaining configuration: apiVersion: v10 码力 | 885 页 | 12.41 MB | 1 年前3
Building a Secure and Maintainable PaaSpicture:Right click on image > Replace image > Select file 3 Requirements for Scaling Up TIP: To change picture:Right click on image > Replace image > Select file ❏ Secure Network Isolation ❏ Network Visibility Security and Auditing 5 Scalability and Maintainability Source: https://commons.wikimedia.org/wiki/File:Pictofigo-Scalability.png 6 Evaluating eBPF CNI Offerings 7 8 9 10 Evaluating Cilium and Hubble 11 Cilium Benefits TIP: To change picture:Right click on image > Replace image > Select file ❏ Pod network filtering uses eBPF rather than iptables ❏ More flexible network policies ❏ Tools0 码力 | 20 页 | 2.26 MB | 1 年前3
bpfbox: Simple Precise
Process Confinement
with eBPF and KRSI8 4 / 7 Our Policy Language Rules and Directives Rules specify access to system objects: ▶ fs(file, access) ▶ net(socket, access) ▶ signal(prog, sig) ▶ etc. Directives augment blocks of rules: ▶0 码力 | 8 页 | 528.12 KB | 1 年前3
Can eBPF save us from the Data Deluge?Can eBPF save us from the Data Deluge? A case for file filtering in eBPF Giulia Frascaria October 28, 2020 1 The data deluge on modern storage 2 Compute node CPU Network Storage node Flash0 码力 | 18 页 | 266.90 KB | 1 年前3
共 11 条
- 1
- 2













