Cilium and eBPF — Kubernetes networking, security and observability
Cilium has moved Kubernetes networking into the kernel: eBPF replaces the service proxy, carries identity-based policies, load balancing and encryption, and feeds an observability that classic network interfaces cannot produce. This course covers the data path, application exposure, network security and operations.
Training objectives
- Understand the Cilium architecture and the role of eBPF programs.
- Master the data path: native routing, encapsulation and addressing.
- Replace the service proxy and optimize traffic distribution.
- Expose applications through the ingress controller and gateway interface.
- Write identity-based, application-layer and DNS-based policies.
- Encrypt communications and use flow observability.
Target audience
- Platform engineers and Kubernetes administrators.
- Network and security engineers working on clusters.
- Cloud native architects.
Prerequisites
- Kubernetes administration course or equivalent practice.
- Sound networking, routing and filtering knowledge.
Detailed program
Day 1 — Architecture and addressing
- Cilium positioning, use cases and agent components
- eBPF programs and maps, application and DNS proxies
- Address management: allocation modes, IPv6 and dual stack
Day 2 — Data path and exposure
- Intra-node and inter-node connectivity: native routing and encapsulation
- Service proxy replacement, session affinity and traffic policies
- Ingress controller, gateway interface and application-layer routing
Day 3 — Security, encryption and operations
- Network policies: identities, reserved entities and deny rules
- Application-layer and DNS-based policies, TLS interception
- Transparent encryption, flow observability and routine operations
Certification
At the end of this training, you will receive a certificate of participation issued by squint.
Other training courses that might interest you
Kubernetes — administering and running applications
Présentiel et distancielKubernetes has become the foundation of modern application platforms, and its adoption shifts the difficulty from deployment to operations. This …
Advanced Kubernetes — high availability, resilience and secrets
Présentiel et distancielA single-control-node cluster has no place in production, and a cluster database backup that has never been restored is not …
OpenShift 4 — bare metal deployment with provisioned installation
Présentiel et distancielInstalling OpenShift on bare metal is not a console operation: automated provisioning, hardware management controllers, infrastructure services, addressing plan and …
Ready to develop your skills?
Join hundreds of professionals who have trusted squint for their skills.
View all our training courses