What is Cilium? Cilium is an open-source CNI (Container Network Interface) for Kubernetes. It uses Linux eBPF technology to provide high-performance networking, security, load balancing, and observability.
Where is it used? Cilium is commonly used in Kubernetes environments for Pod-to-Pod networking, NetworkPolicy enforcement, Service load balancing, multi-cluster connectivity, and network monitoring. It is especially useful in large-scale cloud-native environments where performance, security, and visibility are important.
Key features: eBPF-based networking, L3/L4/L7 security policies, kube-proxy replacement, encryption with WireGuard/IPsec, and network observability through Hubble.
Alternatives:Calico is a popular feature-rich CNI with strong network-policy capabilities; Flannel is a simpler option mainly focused on Pod networking; Antrea is a Kubernetes-native networking and security solution based on Open vSwitch; and Kube-router provides networking and policy with a relatively lightweight architecture.
In short: Cilium = Kubernetes networking + security + observability, powered by eBPF.
Based on the LFS258 topics, here is a 12-week Sunday Kubernetes Fundamentals learning plan. I’ve arranged it so each week builds on the previous one and includes theory, commands, a diagram topic, and a practical lab.
Week
Main Topic
Key Things to Learn
Commands / Lab Focus
1
Kubernetes Foundations
Containers vs Kubernetes, cluster concepts, control plane vs worker nodes
kubectl version, kubectl cluster-info, kubectl get nodes
2
Kubernetes Architecture
API Server, Scheduler, Controller Manager, etcd, kubelet, kube-proxy
kubectl get nodes
kubectl get pods -A
kubectl get svc
kubectl get ingress
kubectl get pv,pvc
kubectl get roles,rolebindings
Finish with a practical challenge: deploy an application with Deployment → Service → Ingress → PVC, intentionally introduce two faults, then troubleshoot them.
Recommended Sunday session structure
Since you already have a regular Kubernetes & Cloud Native learning session, a compact format can work well:
10 min — Concept → 5 min — Architecture diagram → 10 min — commands/demo → 5 min — troubleshooting/question
For deeper personal study, spend another 60–90 minutes during the week reproducing the lab yourself. The biggest improvement will come from typing the commands rather than only reading them.
After these 12 weeks, the natural next step is CKA-focused practice, especially timed exercises around troubleshooting, networking, storage, scheduling, RBAC, cluster maintenance, and kubectl speed.
Ceph is not an acronym, so there is no official expansion like “C.E.P.H.”
The name Ceph comes from “cephalopod”—animals such as an octopus or squid. The idea fits Ceph because it can spread and manage data across many storage nodes, somewhat like many arms working together.
Kubernetes handles container orchestration, scheduling, networking, and application lifecycle management, while Ceph provides the storage layer. Ceph MON, MGR, and OSD components work together to maintain cluster health, manage the storage environment, replicate data, and provide resilient persistent storage to Kubernetes applications.
Ceph combines multiple storage servers into one distributed storage platform. It can provide RBD block storage for virtual machines and Kubernetes, CephFS for shared file storage, and RGW for S3-compatible object storage. Because data is distributed and replicated across multiple OSDs, Ceph can automatically recover from disk or server failures while keeping applications running.
Kubernetes and Ceph provide a scalable, highly available, cloud-native platform for running stateful applications such as databases, monitoring systems, logging platforms, and other enterprise workloads.
This diagram provides a high-level overview of the 5G System (5GS) architecture and its key interfaces. It shows how the User Equipment (UE), NG-RAN, 5G Core control-plane functions, user-plane functions, and external data networks communicate with each other.
The main interfaces include N1/N2 for UE and RAN signaling, N3/N4/N6 for user-plane traffic, and service-based interfaces such as N5, N7, N8, N10, N11, N22, N27, and N33 between 5G Core network functions. It also highlights 4G EPC interworking, roaming/inter-PLMN connectivity, and access to external application and data networks.
Install the utility “iperf” or “iperf3” on both servers. Below here an example of install/using it on Alma9 linux server. On other distros it could be the same –
SD-WAN (Software-Defined Wide Area Network) is a modern approach to managing and optimizing wide area networks (WANs), allowing businesses to securely and efficiently connect remote offices, data centers, and cloud resources over the internet. Unlike traditional WANs, which rely on expensive, static MPLS (Multiprotocol Label Switching) circuits or leased lines, SD-WAN uses software to dynamically manage the traffic across multiple types of network connections, such as broadband internet, 4G/5G, MPLS, and other network types.
How SD-WAN Works:
Centralized Control Plane:
SD-WAN is built around a centralized control plane that manages the entire network’s policies and traffic routing.
This control plane is typically hosted in the cloud or on-premises, and it communicates with SD-WAN devices (also called edge devices or appliances) at branch offices, data centers, or remote sites.
The centralized control allows for real-time traffic management and decision-making, optimizing network performance across different types of connections.
Decentralized Data Plane:
The data plane is made up of SD-WAN devices located at the edge of the network, such as branch routers, and it handles actual data forwarding and traffic routing.
These edge devices are responsible for securely transmitting data between remote sites, data centers, and cloud applications, based on the policies set by the control plane.
Traffic Management and Routing:
SD-WAN uses intelligent path selection to route traffic over the most appropriate and cost-effective path in real-time. It can choose from multiple links (e.g., MPLS, broadband, LTE) based on:
Performance metrics: latency, jitter, packet loss, etc.
Application requirements: certain applications might need high bandwidth or low latency.
Policy-driven decisions: predefined rules about how specific types of traffic should be prioritized (e.g., voice or video traffic).
Application-Aware Routing:
SD-WAN can distinguish between different types of applications and automatically route traffic based on business priorities.
For example, it can prioritize VoIP or video conferencing traffic over general web browsing traffic to ensure high-quality performance for critical applications.
It can also dynamically adjust traffic routes based on network conditions to maintain application performance.
Security:
SD-WAN often includes integrated security features such as:
Encryption: All traffic between SD-WAN devices is encrypted, ensuring secure communication over potentially untrusted public networks (e.g., the internet).
Firewalling: Built-in firewall capabilities can prevent unauthorized access and attacks.
VPN (Virtual Private Network): Secure site-to-site connections can be established, leveraging IPsec or SSL VPNs.
Zero Trust Security: Many SD-WAN solutions implement Zero Trust principles, ensuring that security policies are enforced across the network regardless of location.
Cloud Integration:
SD-WAN is well-suited for cloud-first or hybrid IT environments because it allows direct and optimized access to cloud applications (e.g., SaaS, IaaS, PaaS) without routing traffic through centralized data centers.
This reduces latency, improves application performance, and enhances user experience by enabling direct internet breakout from remote sites to cloud services.
Simplified Management:
SD-WAN solutions are often managed through a centralized, web-based portal, providing administrators with visibility into the entire network.
The portal allows for easy configuration, monitoring, troubleshooting, and reporting across all remote sites and cloud applications.
Many SD-WAN platforms offer automation, allowing for the rapid deployment of new branch sites or network changes without requiring manual configuration at each site.
Key Benefits of SD-WAN:
Cost Efficiency:
By leveraging lower-cost internet connections (such as broadband or LTE) alongside or in place of expensive MPLS links, organizations can reduce their WAN costs significantly.
Improved Performance:
SD-WAN can provide better application performance by selecting the best path based on real-time network conditions, reducing bottlenecks and improving the user experience.
Scalability:
SD-WAN networks are easier to scale as businesses grow. New sites can be added quickly without the need for complex configurations or additional hardware.
Flexibility:
SD-WAN can support multiple types of connections (e.g., MPLS, broadband, LTE, 5G), making it adaptable to a wide range of network environments.
Security:
SD-WAN provides built-in encryption and secure connections, reducing the need for separate security appliances.
Cloud Optimization:
SD-WAN helps businesses securely and efficiently connect to cloud applications and services without backhauling traffic through a central data center.
Centralized Control and Visibility:
The centralized control plane gives IT teams a unified view of the network, simplifying management and troubleshooting.
Use Cases for SD-WAN:
Branch Office Connectivity: Connecting multiple branch offices securely and efficiently, with optimized performance for cloud applications.
Cloud Transformation: Ensuring seamless, secure access to cloud resources and applications for remote and branch locations.
Business Continuity: Using multiple network links to ensure high availability and failover in case of a link or site failure.
Remote Worker Access: Extending SD-WAN benefits to remote workers by securely connecting them to corporate applications via the internet.
Conclusion:
SD-WAN is revolutionizing the way organizations manage their WANs by using software to dynamically manage traffic, optimize application performance, and reduce costs. It provides a more flexible, secure, and efficient solution compared to traditional WAN architectures, making it particularly well-suited for modern cloud-driven, distributed enterprise environments.
“journalctl” – is a command-line tool in Linux used to query and view logs managed by the systemd-journald service, which is part of the systemd system and service manager. journalctl allows users to access log data from various sources in a consolidated, searchable format, covering everything from kernel and system logs to application logs for services that run on systemd.