🤔 Oh, you're using #Squid 🦑 to control #Kubernetes egress? How delightfully retro! I'm sure your cluster will appreciate the walk down memory lane as it figures out what it's gossiping about behind your back. Just remember, it's not a real party until the #NetworkPolicy shows up and ruins the fun! 🎉
https://interlaye.red/kubernetes_002degress_002dsquid.html #Egress #RetroTech #CloudComputing #HackerNews #ngated
Kubernetes Egress Control with Squid proxy (interlaye.red)

Kubernetes Egress Control with Squid proxy (interlaye.red)

Kubernetes Egress Control with Squid proxy (interlaye.red)

Kubernetes Egress Control with Squid proxy (interlaye.red)

There are problems with having a tight egress policy on a residential network. Many of the SmartTV apps include a preconfigured DNS client. The apps ignore the device DNS settings. The latest challenge is Netflix entering a fail loop every time it attempts to play an ad. The only way to clear it is to force close the app. #firewall #egress #enshittification
🎉 Wow, someone discovered that #XDP can handle #egress traffic! 🚀 Meanwhile, the rest of us are just trying to figure out why we should care about packet processing speeds when our network is already down. 😂 #KubeConBooth1752
https://loopholelabs.io/blog/xdp-for-egress-traffic #traffic #packetprocessing #KubeCon #networkperformance #technews #HackerNews #ngated
Using XDP for Egress Traffic

XDP only works for ingress. We found a loophole that lets it work for egress. Here's how we did the impossible.

Welcome to the team Lucas Pye! Lucas is joining us as an intern until mid-September and is researching what telemetry is gathered from developer machines by various popular agentic coding tools. When he's not intercepting #egress traffic you can find him climbing in the Peak District or his local gym.

(screenshot of MitMed Cursor)

Spaaaaaaaaace! (EVA on ISS egress)

https://makertube.net/w/sknoJEYuMYvw3euCfVVkfj

Spaaaaaaaaace! (EVA on ISS egress)

PeerTube

Coincidentally, I discussed some options in a recent article I wrote: https://colan.pro/blog/comparison-of-managed-kubernetes-providers-without-egress-fees/

#k8s #Kubernetes #egress

A Comparison of Managed Kubernetes Providers Without Egress Fees

Compares the different providers, focusing on costs, features, and regional availability to help you find the best alternative to major hyperscalers.

Colan Schwartz on Cloud Architecture, Automation, Security & Privacy

We make it easier for you to enable an outbound network traffic firewall in full allowlist enforcement mode -- with discovery, dry run and micro-segmentation.

Available on AWS and GCP. Search for DiscrimiNAT Firewall in your cloud web console.

#egress #filtering

Wildcards were a game-changer in GCP for this👇customer in reducing #egress management overhead.

✅Monitoring / Dry-Run mode
✅SNI spoofing proof tech
✅Public Suffix List / Effective TLD checks
✅Terraform

Deploy now or get a demo from engineering: https://chasersystems.com/

👇

Chaser Systems

Chaser Systems are a cybersecurity innovator building defensive components that operate on Cloud and IoT platforms ergonomically and with native integrations.

"Nobody ever got fired for buying ~~IBM~~ cloud."

I just do not understand #cloud based #siem for any organization over 1000 employees. #Ingress / #egress costs are ridiculous compared to the #engineers and #onprem system. Managers who are blinded by a drive to only look at cloud are short sighted.