A proposed four-day workshop on Cilium investigation
Participants need basic Kubernetes and IP-networking knowledge. We adapt the networking material to the selected Cilium version and deployment mode, with runtime diagnosis as the main task.
Day 1
Workload health and network symptoms
Connect probes, ports, labels, and release changes to the request under investigation. Distinguish an unavailable application from a path that fails to reach it.
Hands-on exercises
- Compare backend health with the result of a representative client request.
- Identify which endpoints and labels changed during a release.
Day 2
Templates, agents, and observed state
Relate rendered resources to CNI configuration, endpoint state, and node agents. Establish what the available diagnostic tools can observe.
Hands-on exercises
- Inspect whether the selected workload is managed by the expected networking implementation.
- Compare node-local observations with the available relay view.
Day 3
Forwarding, identity, and policy
Trace same-node and cross-node traffic through the configured data path. Interpret policy verdicts alongside discovery, endpoint identity, and routing evidence.
Hands-on exercises
- Diagnose a controlled policy denial using the affected endpoints' evidence.
- Investigate a path that works locally but fails across nodes.
Day 4
Pressure, lifecycle, and repeatable diagnosis
Examine how workload replacement, resource pressure, and diagnostic permissions affect the investigation. Define the smallest correction and the paths needed to validate it.
Hands-on exercises
- Repeat a connectivity check after a bounded configuration or lifecycle change.
- Produce an evidence record that states collection scope and remaining uncertainty.
Your CNI deployment, connectivity questions, and node responsibilities can shape the agenda. Get in touch to tailor the workshop to your team's work.