Skip to content

Phase 6: Service Mesh & eBPF Security

πŸ“– Deep-Dive Index

1. Mesh Fundamentals

  • Traffic Management: Traffic splitting (Canary/Blue-Green), Circuit breaking, Retries, Timeouts.
  • Security: Mutual TLS (mTLS) for pod-to-pod encryption, transparent proxying.

2. eBPF & Cilium

  • eBPF (Extended Berkeley Packet Filter): Running sandboxed programs in the Linux kernel without changing kernel source code. Replacing IPTables.
  • Cilium Architecture: Sidecarless mesh, CiliumNetworkPolicies (L3/L4/L7), Hubble for observability and service map visualization.

πŸ› οΈ Job-Essential Exercises

  1. The Zero-Trust Network Policy:
  2. Deploy Cilium. Deploy three pods: Frontend, Backend, and Hacker. Write a CiliumNetworkPolicy that completely locks down the namespace, explicitly allowing only Frontend to communicate with Backend on TCP port 8080.
  3. Proving Zero-Trust:
  4. kubectl exec into Hacker and attempt to curl the Backend. It must timeout.
  5. Hubble Observability:
  6. Enable Hubble. Generate traffic between your pods. View the Hubble UI or CLI to see a live visual graph of the network flows and blocked packets.