We Put an L7 Firewall in the Kernel

·Hacker News··

Application-layer firewall decisions at XDP, before a socket buffer exists. We built a firewall that decides on HTTP/2 headers in the kernel with eBPF and lets you write the policy as a JavaScript app. The decision lands in the nanoseconds, changing a rule takes no rebuild or restart, and it's already running in front of real enterprise traffic. Here's how it works.

Read full article →

Related Articles

Tell HN: PayPal Blocks GrapheneOS
leumon · Hacker News · 7h ago
Asahi Linux Progress Report: Linux 7.2
pizzaiolo · Hacker News · 18h ago
Worst-case glacial lake flood scenarios in a transboundary Himalayan basin 2022
totetsu · Hacker News · 18h ago
An ongoing 3D-printer AGPL violation
Velocifyer · Hacker News · 23h ago
MIT's Ad Hoc Committee on AI Use in Teaching, Learning, and Research Training
pbui · Hacker News · 3h ago