Istio brings a myriad of options to provide routing rules, encryption, and monitoring for microservices, typically in container environments. Cilium provides accelerated network security using a modern kernel technology called BPF. Put the two together and what do you get? A distributed security solution enabling microservices traffic management, security, and monitoring while enforcing policy as close to the microservices as possible.
Cynthia Thomas and Romain Lenglet discuss the architectural and performance benefits of using Cilium with Istio and provide a demo of this BPF-based, Linux kernel technology. Cilium provides an API-aware security solution that can make a decision on every single microservice flow, with the ability to enforce protocols such as HTTP, Kafka, and gRPC. By addressing security policy at the API layer, you can enforce policy efficiently with kernel capabilities while reducing the attack surface in a microservices deployment.
Cynthia Thomas is a technology evangelist at Isovalent. Her background includes 10 years spent working with open source cloud and networking solutions in data center, telecommunications, and campus deployments. Cynthia is an advocate of open source technologies. Since 2015, she has been working on Docker and Kubernetes with CNI plugins, currently through the open source project Cilium. She is a frequent speaker at conferences, including ContainerCon, DevOpsDays, DockerCon, Kubernetes meetups, and OpenStack Summits and meetups.
Romain Lenglet is a chief architect at Covalent and a core developer of the Cilium open source project, where he focuses on integration with the Istio service mesh via Envoy proxy. His past work focused on the intersection of distributed systems and networking, architecting large-systems for YouTube at Google, Oracle Cloud at Oracle, and Nicira (acquired by VMware, now VMware NSX). Romain holds a PhD in computer science from the Institut polytechnique de Grenoble and an MBA from Santa Clara University.
Comments on this page are now closed.
©2018, O'Reilly Media, Inc. • (800) 889-8969 or (707) 827-7019 • Monday-Friday 7:30am-5pm PT • All trademarks and registered trademarks appearing on oreilly.com are the property of their respective owners. • email@example.com