Hacker News new | past | comments | ask | show | jobs | submit login

Fantastic write up - keep going (please)!

Agree more practical examples but disagree this is too abstract.

I’m thinking starting at more common scenarios then jumping to container networking. Ie - Flow of a packet on a simple node, a two interface node, then namespaces, and then quirky virtual stuff.

Another example - I’d love to see how iptables actually works. Maybe how to use ebpf to implement iptables things like source/dest NAT, Masquerade, etc.

But yeah I learned a ton here. Thanks




> I’d love to see how iptables actually works.

If you're actually interested in iptables the old packet filter how-to is great:

https://www.netfilter.org/documentation/HOWTO/packet-filteri...

But iptables is turning into just a legacy interface for nftables in modern Linux. See eg:

https://wiki.debian.org/nftables

https://wiki.nftables.org/wiki-nftables/index.php/Main_Page


I do plan on having a "flow of a packet on a simple node". Working on an ingress and egress packet flow posts. These are rather large undertakings tho that require a post of their own IMO. Stay tuned for those :)




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: