We Put an L7 Firewall in the Kernel

·Hacker News··

Application-layer firewall decisions at XDP, before a socket buffer exists. We built a firewall that decides on HTTP/2 headers in the kernel with eBPF and lets you write the policy as a JavaScript app. The decision lands in the nanoseconds, changing a rule takes no rebuild or restart, and it's already running in front of real enterprise traffic. Here's how it works.

Read full article →

Related Articles

Field measurements of neighborhood-scale air temperature impacts of data centers
cwwc · Hacker News · 9h ago
Linux 7.3 improves performance when running out of vRAM
flaburgan · Hacker News · 18h ago
Memory prices climb 500% in 12 months
haunter · Hacker News · 1d ago
Solo – a .so loader for static Linux binaries
zX41ZdbW · Hacker News · 2h ago
Meta Files Patent for Facial Recognition, Automatic Recording of People
DeepLogin · Hacker News · 14h ago