● ○ ○ ⇒ ⇒ ● ●
● ○ ● ○ ○ ●
● ○ ○ ○ ● ○ ○
● ● ○ ○ Frontend BackendLB FE BE LB LB FE FE BE LB
● ● ○ ○ Frontend BackendLB FE BE LB LB FE FE BE LB Prod Frontend BackendLB FE BELB QA Prod QA Prodrequires requires QA QA
● ○ FE BE LB Prod QA Prod Prod FE BE LB QA QA 10 11 12 13 14 15 16 Cluster Wide Label ID Table: This ID is carried in the network packet and used to reconstruct the label context at the receiving host. Policy enforcement cost is reduced to a single hashtable lookup regardless of complexity.
● ● ● FE BE LB LB ECMP FE FE BE BE BE Small HTTP GET Ultra HD Cat Pictures/Videos
Intel Xeon 3.5Ghz Sandy Bridge, 24 cores, 1 TCP flow per core, netperf -t TCP_SENDFILE, 10’000 policies
● ● ● ● ● ● ● ● ● ● ● ● ●

Cilium - Container Networking with BPF & XDP