Even though Cisco acquires them, I believe this is not going to be a "RIP" story — Cilium is a graduated CNCF project, adopted by all major cloud providers, used by many fortune 100 companies, and have a rich/diverse contributors community. Plus the team at Isovalent is super strong, and eBPF powerhouse, they are going to continue working on Cilium, Tetragon, and other eBPF projects. And they've build a strong and vibrant OSS community. Cisco did a really smart and strategic move to lead a modernization of networking and security.
Yes, YAML editor functionality is there, just disabled as it needs a little bit more work.
Now you can upload existing policies if you created them manually.
Cilium 1.8 brings with it a trove of exciting new features:
- XDP Load Balancing Support: eXpress Data Path (XDP) is the fast-lane for networking in the Linux kernel, built on eBPF. We've extended our existing eBPF kube-proxy replacement to accelerate service forwarding by 5x in our tests while dramatically reducing CPU consumption at the same time.
- Cluster-wide Flow API: Hubble Relay builds on the solid core of Hubble and Cilium to provide deep observability across the entire cluster via a centralized API with minimal overhead.
- Better policy visibility and control: ClusterwideNetworkPolicy now supports matching hosts in the cluster to implement Host network security protection, and all policy types gain named ports support. New community contributors have built eBPF notifications for Policy Verdicts and a Policy Audit mode to incrementally deploy network policies in your cluster.
- Performance optimizations across the board: We've improved the performance and resource usage in almost every dimension in this release, from improving CRD scalability and optimizing the Cilium agent's memory footprint to various performance enhancements in our eBPF data path and size reduction of the Cilium container image. Hubble has been optimized to minimize resource usage by embedding the core functionality into the Cilium agent.
- Making more functionality iptables-free: We've worked hard on improving Cilium's service implementations to further reduce the dependence on external tools based on iptables. Several features are now implemented natively in eBPF, ranging from Session Affinity and HostPort to IP masquerade agent and IP fragmentation support. (More details)
Many more features: Native Azure IPAM provides better integration for Azure Cloud via a new IPAM plugin, datapath load balancing support was extended to support environments with multiple native devices, and initial support for ARM64 has been added with docker image snapshots.
Here you go, startup idea: emergency logistics. Company that can quickly ship and verify good quality approved medical equipment and supplies to the epidemic area.
Downsides could be
- more risk for founders raising rounds, since its unconventional
- increase of tax complexity for both employees and employer
- more complex cap tables and/or processes around converting stocks, since employees are usually owning common stocks, while investors are looking to get new preferred stocks issued for round
But I think big vc orgs and especially YC could pioneer / help with new approaches
i think vc/founders need to innovate on this topic to: provide better effort/reward incentives, and reduce risk for employees, giving that they have less voting control over equity.
Could be something like:
- companies keep lower number of employees, higher grants, but demand founder-like effort for early years
- early employees get substantial equity grants 5-10%, that must be sold to VCs on secondary offering at next rounds. In that case, employees could directly benefit from startup grows, while reducing risk compared to FAANg, and founder can keep their equity size. Yes, upside is limited, tax/legal work, but could be covered by new refreshment grants from employee pool
- YC creates/funds employee union-like organization, that funds/organize activities/benefits for early stage startups
- help legally with paying/hiring employees remote with equity package
also joining startup and buying out $$$$$ worth of stock options that could turn to 0 is a downside compared to stock grants from FAANg.
Disclaimer: worked only in startups as early-stage engineer.
I feel like early stage startups are getting closed to be toast, at least in bay area, from different angels conglomerates are better at non-compensation factors as well. And in current environment, when startups stay private longer, any engineer has a better chances to go to mid or late stage startup, wait till IPO and repeat. It is better from money, career, networking.
If put aside equity, as a decision factor, I think, early engineers can go to a startup because it's a faster growing environment with more freedom. Faster for career, business skills, networking, engineering skills... But founders are focused on growing a startup (or stock price) at all cost, short term, from round to round. And people personal goals are usually longer term and founders don't have time/will for that.
More thoughts on non-compensation factors that startups could get right if they want:
1. Advance in career faster.
Some go to startups because they feel they can progress faster in career ladder. In reality early engineers do not have enough experience for management/lead positions, and there is not enough experience to gain in early days (not enough people, tasks). Founders usually end up bringing ex-big corp/cool startup management, because "they worked at scale".
For management career development working at big corps are usually better, since there is a clear path you can take to grow, and you can estimate how much it will take you to do it.
Founders could be upfront about they goals and as part of offer could promise people a chance at management, some management coaching. Organizations like YC could offer early engineers management/leads coaching programs to their portfolio companies.
2. Grow as engineers
Startups usually don't have enough scale and tech is not perfect. More like a different peaces "glued" together in a hurry, and always constant change.
Anyone working at startups as early engineer and trying to go to big-corp for money will hear "yeah cool, but we are looking for tech experience at our scale of usage"
Startups can compete in this area (if they don't have scale) by allowing people to develop as public figures, encouraging blogging, talking at conferences.
3. Unlimited vacations. Flexible time.
Early engineers are always on, and harder to take long vacation, or completely disconnect. Compare to big corps, there are some where you can take several months sabbatical.
4. Full business transparency
Founders can be fully transparent in terms of business, funding in front of employees. This can go long way in developing loyalty and trust. Compare it to big corps, where there are layers of management.
5. Remote-first
More startups allow people to travel and work from whatever hours, location they want - more employees/engineers they will attract.
Founders could be upfront about it: we pay 80% of market comp, but we don't care where you work from, as long as you available from some reasonable time online.
6. Networking
I feel like startups suck at this. It's expensive to send people to conferences, startup team is small. Working at FAANg you have better networking opportunities.
YC/VCs could have a networking events not only for founders, but for engineers as well. From YC perspective it's better if engineer leaves for another YC company and stay in ecosystem, than to leave to FAANg.
7. Family friendly
I feel like big corps are more family friendly: insurance, time off, activities. Startups figuring out how to make it or compensate for luck of it — could help.
first stuck in vim 13 years ago. No internet, no GUI, could not speak english, 1 book on unix/linux. So I had to reboot (hard reboot) computer, three times, then re-install OS, since something broke because of hard-forced reboot.