World Congress 2026 Europe

Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves

July 10, 2026 10:20 – 10:50 · 30 min Stage 8 - powered by Red Hat

What this session covers

Do you offer a SaaS product? Is your entire infrastructure sitting behind a couple of reverse proxies that got overloaded because one customer decided to “stress test” your service? Then this talk is for you!

This presentation covers rate limiting at ClickHouse Cloud, makers of the open-source database of the same name. We’ll discuss how to cut off connections at L3 using eBPF before they overwhelm your proxies. You’ll learn how we guess which customer is the (accidental) bad actor, even though our rate limiter never parses the TLS SNI header that would tell us which customer instance is being hit. You’ll also learn why eBPF rate limiting isn’t enough on its own, and why we use Istio as well.

Related talks at this congress

Open session

World Congress 2026 Europe

July 9, 2026 · 12:10–12:40

Stage 8 - powered by Red Hat

The Hidden Costs of CPU Limits in Kubernetes

Pavel Malyarevsky

Director PCCP at Deutsche Bank

Pavel Malyarevsky
Open session

World Congress 2026 Europe

July 10, 2026 · 16:20–16:50

Stage 2

Super scaling for the Super Bowl: How to survive 30 million users hitting your backend in 30 minutes

Irina Branovic

Tech Lead at adjoe

Irina Branovic
Open session

World Congress 2026 Europe

July 10, 2026 · 13:40–14:10

Stage 10 - powered by TikTok

There Is No Such Thing as a Fair DBaaS Benchmark

Daniel Seybold

Co-Founder of benchANT

Daniel Seybold
Open session

World Congress 2026 Europe

July 9, 2026 · 16:10–16:40

Stage 12

What If We've Been Scaling Stream Processing Wrong All Along?

Hartmut Armbruster

Software Architect at StoatFlow

Hartmut Armbruster
All sessions at this congress