World Congress 2026 Europe Jul 10, 2026 Session details

Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves

Jan Mensch

How do you stop one noisy customer from crashing your entire shared infrastructure? Learn to combine eBPF and Istio for dual-layered rate limiting that ruthlessly drops runaway connections.

Pause
Mute Enter Fullscreen
#1 about 2 min

Introduction to ClickHouse cloud database architecture

An overview of ClickHouse as an analytical database and its cloud offering.

#2 about 2 min

SaaS network architecture and proxy routing challenges

How shared proxy routing handles client-to-database connections through a network load balancer.

#3 about 1 min

Exploring real-world customer infrastructure overload incidents

Examples of customers accidentally overwhelming shared infrastructure through load testing and misconfigurations.

#4 about 3 min

Defining goals for multi-tenant rate limiting

Why global rate limiters fail in shared proxy setups and the need for rapid connection resets.

#5 about 3 min

Injecting eBPF programs into the proxy network stack

Attaching eBPF programs directly to the proxy pod container network stack to avoid Cilium conflicts.

#6 about 2 min

Token bucket rate limiting logic in eBPF

Tracking and resetting excessive downstream requests dynamically to conserve server processing utilization.

#7 about 3 min

Live demonstration of packet capture interrupt handling

Running a minimal eBPF tool inside a container to capture incoming TCP handshake interactions.

#8 about 3 min

Identifying upstream connections using the proxy protocol

Utilizing proxy protocol encoding to preserve original client connection IPs behind cloud load balancers.

#9 about 3 min

Inferring disrupted targets via active network sampling

Correlating sampled traffic arrays to identify specific customer spammers without decrypting complete SNI headers.

#10 about 2 min

Limitations of relying on client-level eBPF limits

Why simultaneous flood bursts across thousands of client IP sources bypass downstream-level connection limits.

#11 about 2 min

Transitioning to Layer 7 rate limiting safeguards

Accepting TLS handshakes at layer seven to establish granular, multi-tenant application-aware traffic safeguards.

#12 about 3 min

Configuring dynamic proxy updates with Istio Pilot

Leveraging the Istio service mesh control plane to push Envoy rule updates immediately.

#13 about 3 min

Filtering upstream traffic with Envoy local limits

Deploying connection limit filters to arrest connection accumulation while capping sudden volume traffic bursts.

#14 about 2 min

Integrating eBPF limiters alongside Layer 7 proxies

Combining IP-focused eBPF mitigation with flexible Layer 7 structural limiters to shield downstream domains.

#15 about 3 min

Handling multi-connection metrics and gRPC integration

Addressing gRPC protocol constraints and interpreting complex memory map metrics within eBPF systems.

Matching moments

12:17 min

Managing edge cases and load balancing SSE

Rainer Stropek Rainer Stropek · LIVE

6:25 min

Platform security fundamentals using Istio service mesh

Thomas Südbröcker · LIVE

1:33 min

Practical use cases covering networking and performance profiling

Mohammed Aboullaite Mohammed Aboullaite · World Congress 2024

9:56 min

Final code walk-through and audience Q&A session

Germán Álvarez · LIVE

2:48 min

Working around API rate limits and model outages

Yan Cui Yan Cui · World Congress 2025

3:15 min

Addressing scaling limitations of proxies and service meshes

Duan Lightfoot Duan Lightfoot · World Congress 2023

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 09:00–09:30

Stage 3

Your Thread Pool Is Lying to You — Sizing Concurrency from Rate Limits and Latency, Not Guesswork

Ratul Ghosh, Sesha Chennupati

Ratul Ghosh
Sesha Chennupati
Open session

World Congress 2026 North America

September 24, 2026 · 14:10–14:40

Stage 3

Real-Time Data Platforms at Trillion-Event Scale

Diptamay Sanyal

Principal Engineer | Data, AI & Cybersecurity Platforms

Diptamay Sanyal
Open session

World Congress 2026 North America

September 25, 2026 · 12:20–12:50

Stage 9

Designing APIs That Survive AI Agents at Scale

Phani Pendurthi

Mastercard, Principal Software Engineer

Phani Pendurthi
Open session

World Congress 2026 North America

September 24, 2026 · 17:30–18:00

Stage 4

Boring Failover: Predictable Region Recovery Across 5,000 Microservices

Garvit Kataria, Sahil Sabharwal

Garvit Kataria
Sahil Sabharwal
Open session

World Congress 2026 North America

September 24, 2026 · 14:10–14:40

Stage 7

Designing High-Performance AI APIs: Lessons from Serving Millions of Real-Time Requests

Wayne Liu

Chief Growth Officer and Americas President of Perfect Corp.

Wayne Liu
Open session

World Congress 2026 North America

September 25, 2026 · 09:00–09:30

Stage 1

Test Before Release, Enforce at Runtime: Governance for Tool-Using AI Agents

Sachin Gupta

Member of Technical Staff 2 at eBay

Sachin Gupta