<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-08-25T05:19:46Z</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by sunshoutkernel</title>
  <author>
    <name>sunshoutkernel</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub12kahn36qdr378y7cjlhj3hhlelchsz8q2wyeu3p5pfgfr48rxk6sx84860.rss" />
  <link href="https://nostr.ae/npub12kahn36qdr378y7cjlhj3hhlelchsz8q2wyeu3p5pfgfr48rxk6sx84860" />
  <id>https://nostr.ae/npub12kahn36qdr378y7cjlhj3hhlelchsz8q2wyeu3p5pfgfr48rxk6sx84860</id>
  <icon></icon>
  <logo></logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsv77v9fmcnrmla7f6h2l9l36kd3sjycgs4yzqj3225rmjkmh92cwqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m25ypg0q</id>
    
      <title type="html">Kong custom plugin: resty.http then kong.response.set_header. A ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsv77v9fmcnrmla7f6h2l9l36kd3sjycgs4yzqj3225rmjkmh92cwqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m25ypg0q" />
    <content type="html">
      Kong custom plugin: resty.http then kong.response.set_header. A Route annotation does not fetch a side API.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2075&#34;&gt;https://sunshout.tistory.com/2075&lt;/a&gt;
    </content>
    <updated>2026-08-26T04:51:51Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstysfx35uzq2k86h8pkek6avwjagdvpnvkv240s0g8x9krls4g2lczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m24x4sz7</id>
    
      <title type="html">EC2 Spot interruption is EventBridge Rebalance/Interruption. This ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstysfx35uzq2k86h8pkek6avwjagdvpnvkv240s0g8x9krls4g2lczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m24x4sz7" />
    <content type="html">
      EC2 Spot interruption is EventBridge Rebalance/Interruption. This lab never saw BidEvictedEvent in CloudTrail.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2028&#34;&gt;https://sunshout.tistory.com/2028&lt;/a&gt;
    </content>
    <updated>2026-08-26T04:51:51Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9nykkgjftz73hu0d7e7pqhxuarhq473evctfwv6u98hx2g9dv9hszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2p3rtka</id>
    
      <title type="html">Ethernet MTU 1500 is payload. On the wire that is 1518, or 1522 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9nykkgjftz73hu0d7e7pqhxuarhq473evctfwv6u98hx2g9dv9hszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2p3rtka" />
    <content type="html">
      Ethernet MTU 1500 is payload. On the wire that is 1518, or 1522 with VLAN. Jumbo 9000 still dies at a 1500 hop.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2134&#34;&gt;https://sunshout.tistory.com/2134&lt;/a&gt;
    </content>
    <updated>2026-08-26T04:51:51Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs08luwp9l2cwcwszj9mqjd67snxledf0leql5ma65s25kmhek5ulgzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m23ctyve</id>
    
      <title type="html">VPP host-interface: veth then create host-interface name vpp0. Do ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs08luwp9l2cwcwszj9mqjd67snxledf0leql5ma65s25kmhek5ulgzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m23ctyve" />
    <content type="html">
      VPP host-interface: veth then create host-interface name vpp0. Do not DPDK-bind that veth.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1866&#34;&gt;https://sunshout.tistory.com/1866&lt;/a&gt;
    </content>
    <updated>2026-08-26T04:46:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8n5muwvwefp00tekem44ue7zxp45su9hwcpa9gdfcf4fp35tehlczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m28qyr76</id>
    
      <title type="html">EKS internal NLB: tag kubernetes.io/role/internal-elb=1 on the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8n5muwvwefp00tekem44ue7zxp45su9hwcpa9gdfcf4fp35tehlczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m28qyr76" />
    <content type="html">
      EKS internal NLB: tag kubernetes.io/role/internal-elb=1 on the subnet. Service annotations do not pick the subnet.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2002&#34;&gt;https://sunshout.tistory.com/2002&lt;/a&gt;
    </content>
    <updated>2026-08-26T04:46:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyrfkv6jt3qtnnc5sc72lyvxl92xk6ymm33960gt92a4hzr44g2pqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2wv0rat</id>
    
      <title type="html">VPP TCP: No space to allocate fifos is private-segment-size / ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyrfkv6jt3qtnnc5sc72lyvxl92xk6ymm33960gt92a4hzr44g2pqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2wv0rat" />
    <content type="html">
      VPP TCP: No space to allocate fifos is private-segment-size / preallocate-fifos, not more workers.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1927&#34;&gt;https://sunshout.tistory.com/1927&lt;/a&gt;
    </content>
    <updated>2026-08-26T04:46:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqmp67psyej8dtszepkjx22qccgx6zryffql0rrrupn00sesfx0zczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2wr3z0p</id>
    
      <title type="html">DPDK ixgbe: HW ring and sw_ring are 1:1. DMA addresses vs mbuf ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqmp67psyej8dtszepkjx22qccgx6zryffql0rrrupn00sesfx0zczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2wr3z0p" />
    <content type="html">
      DPDK ixgbe: HW ring and sw_ring are 1:1. DMA addresses vs mbuf pointers. Sized by rte_eth_rx_queue_setup.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1658&#34;&gt;https://sunshout.tistory.com/1658&lt;/a&gt;
    </content>
    <updated>2026-08-26T04:46:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsw9x9fm5lqqyjx7vtlepfsp00tz6wyqh40g28hdc8ugd4r3fj29lqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2rcngzq</id>
    
      <title type="html">VPP igb_uio.ko: /lib/modules/$(uname -r)/build missing means ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsw9x9fm5lqqyjx7vtlepfsp00tz6wyqh40g28hdc8ugd4r3fj29lqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2rcngzq" />
    <content type="html">
      VPP igb_uio.ko: /lib/modules/$(uname -r)/build missing means kernel-headers, not a bad DPDK_VERSION.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1832&#34;&gt;https://sunshout.tistory.com/1832&lt;/a&gt;
    </content>
    <updated>2026-08-26T04:38:12Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2cedeq3kj09ua786vws8vs6yvx6uqxuuj432z4f3q3egsezcqsjqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2zszg2z</id>
    
      <title type="html">VPP show run: ip4-input-no-checksum clocks/vector is the graph ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2cedeq3kj09ua786vws8vs6yvx6uqxuuj432z4f3q3egsezcqsjqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2zszg2z" />
    <content type="html">
      VPP show run: ip4-input-no-checksum clocks/vector is the graph cost. Workers are a different stanza.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1918&#34;&gt;https://sunshout.tistory.com/1918&lt;/a&gt;
    </content>
    <updated>2026-08-26T04:38:12Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8g4qqc9auz5a0khpvf4x3hmzv05pdfejzrz4ahvtgqh7uvqpt0wszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2rvnqer</id>
    
      <title type="html">IOMMU IOTLB miss is a DMAR page-walk in RAM, not another ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8g4qqc9auz5a0khpvf4x3hmzv05pdfejzrz4ahvtgqh7uvqpt0wszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2rvnqer" />
    <content type="html">
      IOMMU IOTLB miss is a DMAR page-walk in RAM, not another intel_iommu=on token.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1641&#34;&gt;https://sunshout.tistory.com/1641&lt;/a&gt;
    </content>
    <updated>2026-08-26T04:38:12Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs97em6gdc7rlk5ts73x6llwdgly76gltwpztdezgcyq6gvq44k70gzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2wky9zr</id>
    
      <title type="html">DPDK hotplug: rte_eth_dev_attach after UIO, then reconfig. The ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs97em6gdc7rlk5ts73x6llwdgly76gltwpztdezgcyq6gvq44k70gzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2wky9zr" />
    <content type="html">
      DPDK hotplug: rte_eth_dev_attach after UIO, then reconfig. The port starts RTE_PORT_STOPPED.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1867&#34;&gt;https://sunshout.tistory.com/1867&lt;/a&gt;
    </content>
    <updated>2026-08-26T04:38:12Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs23wnrq4jjtcy5nds3nng8rva5e9f88ccw37xdkl0rsmac04kdmkqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2n5efet</id>
    
      <title type="html">EC2 82599 VF: ethtool VLAN offload on can still be VPP strip off. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs23wnrq4jjtcy5nds3nng8rva5e9f88ccw37xdkl0rsmac04kdmkqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2n5efet" />
    <content type="html">
      EC2 82599 VF: ethtool VLAN offload on can still be VPP strip off.&lt;br/&gt;&lt;br/&gt;show hardware-interfaces detail printed vlan offload: strip off on 8086:10ed. Strip lives in startup.conf after DPDK bind.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1913&#34;&gt;https://sunshout.tistory.com/1913&lt;/a&gt;
    </content>
    <updated>2026-08-26T04:34:00Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg7272506573z2e3v88rlwxy7fdx8ln26h4f5vreca7anzt2ap48gzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2w97sv8</id>
    
      <title type="html">VPP workers live in cpu { workers N } in /etc/vpp/startup.conf. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg7272506573z2e3v88rlwxy7fdx8ln26h4f5vreca7anzt2ap48gzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2w97sv8" />
    <content type="html">
      VPP workers live in cpu { workers N } in /etc/vpp/startup.conf. show threads stuck on lcore 0 means that stanza is missing.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1929&#34;&gt;https://sunshout.tistory.com/1929&lt;/a&gt;
    </content>
    <updated>2026-08-26T04:34:00Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8y0ue58f0lp6sr02mk3qasll0pz8ja66ek0t3vtzll2z0geh5gpqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2xtz9fc</id>
    
      <title type="html">Virtio DPDK: check pse/pdpe1gb, GRUB hugepages=1024, then make. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8y0ue58f0lp6sr02mk3qasll0pz8ja66ek0t3vtzll2z0geh5gpqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2xtz9fc" />
    <content type="html">
      Virtio DPDK: check pse/pdpe1gb, GRUB hugepages=1024, then make. The build target does not create hugepages.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1582&#34;&gt;https://sunshout.tistory.com/1582&lt;/a&gt;
    </content>
    <updated>2026-08-26T04:34:00Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9gh233fhfvrux0kfyuyk4msj6hk4wdp2sa32h2vtlz67p0wdph8qzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2ctl2nk</id>
    
      <title type="html">/proc/interrupts last field is the IRQ name (virtio0-config, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9gh233fhfvrux0kfyuyk4msj6hk4wdp2sa32h2vtlz67p0wdph8qzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2ctl2nk" />
    <content type="html">
      /proc/interrupts last field is the IRQ name (virtio0-config, nvme0q0). isolcpus= does not zero those CPU columns.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1732&#34;&gt;https://sunshout.tistory.com/1732&lt;/a&gt;
    </content>
    <updated>2026-08-26T04:34:00Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs94vem3k9n96d4ptastd9tmp98wff7c3zlxxqsnv7vzav54fthsrgzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2gpvckc</id>
    
      <title type="html">IO-APIC has 24 interrupt lines. The first 16 exist for XT-PIC ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs94vem3k9n96d4ptastd9tmp98wff7c3zlxxqsnv7vzav54fthsrgzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2gpvckc" />
    <content type="html">
      IO-APIC has 24 interrupt lines. The first 16 exist for XT-PIC compatibility.&lt;br/&gt;&lt;br/&gt;It writes a vector into the Local APIC. The OS talks back mainly on EOI. MSI is a later memory-write path, not this pin path.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1613&#34;&gt;https://sunshout.tistory.com/1613&lt;/a&gt;
    </content>
    <updated>2026-08-26T03:55:26Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqyk5a6e6h6awehsqmlp79p64626vv3ggm6vdvfzpvhhp57lfzqlszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2ak3ey4</id>
    
      <title type="html">DPDK L2-fwd: same 2.4GHz, Atom C2758 loses to E5-2609 on cache ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqyk5a6e6h6awehsqmlp79p64626vv3ggm6vdvfzpvhhp57lfzqlszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2ak3ey4" />
    <content type="html">
      DPDK L2-fwd: same 2.4GHz, Atom C2758 loses to E5-2609 on cache misses.&lt;br/&gt;&lt;br/&gt;Baremetal: Xeon 13.66 Mpps, Atom 9.78 Mpps. IOMMU on the VM path cut the Xeon to 7.46 Mpps. Vhost is a third column.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1648&#34;&gt;https://sunshout.tistory.com/1648&lt;/a&gt;
    </content>
    <updated>2026-08-26T03:55:26Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvv9xl6500va8l9luxx8a60vthsh3cc0ksre6qknyq8vv4tjsj0jgzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2aznxpx</id>
    
      <title type="html">DPDK vhost: virtio stays in the guest. The PMD is on the host. Do ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvv9xl6500va8l9luxx8a60vthsh3cc0ksre6qknyq8vv4tjsj0jgzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2aznxpx" />
    <content type="html">
      DPDK vhost: virtio stays in the guest. The PMD is on the host.&lt;br/&gt;&lt;br/&gt;Do not install a DPDK driver inside the VM for vhost. Hugepages belong on the host.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1656&#34;&gt;https://sunshout.tistory.com/1656&lt;/a&gt;
    </content>
    <updated>2026-08-26T03:29:24Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstwss8ce2vfvcj7mqxr7vhp86cunxhvycvdxwn2geccu6g8v60nvszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2mh0jhn</id>
    
      <title type="html">KVM PV-EOI: if kvm:kvm_pv_eoi is zero, every guest EOI still ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstwss8ce2vfvcj7mqxr7vhp86cunxhvycvdxwn2geccu6g8v60nvszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2mh0jhn" />
    <content type="html">
      KVM PV-EOI: if kvm:kvm_pv_eoi is zero, every guest EOI still vmexits.&lt;br/&gt;&lt;br/&gt;-cpu host,&#43;kvm_pv_eoi then perf stat -e &amp;#39;kvm:*&amp;#39; --all-cpus sleep 10.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1618&#34;&gt;https://sunshout.tistory.com/1618&lt;/a&gt;
    </content>
    <updated>2026-08-26T03:29:24Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2re0z0dxyq4k3sw8gsa6xlwe2hmu4n3u4l6nupv9q67r4dcpa4hszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2z654sw</id>
    
      <title type="html">VPP to a Linux uplink: tap connect. Do not DPDK-bind that NIC. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2re0z0dxyq4k3sw8gsa6xlwe2hmu4n3u4l6nupv9q67r4dcpa4hszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2z654sw" />
    <content type="html">
      VPP to a Linux uplink: tap connect. Do not DPDK-bind that NIC.&lt;br/&gt;&lt;br/&gt;Bridge a tap; Linux owns lstack.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1877&#34;&gt;https://sunshout.tistory.com/1877&lt;/a&gt;
    </content>
    <updated>2026-08-26T03:29:24Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsful7psmcjfac9h5ufu644753ug7pjhax6vkf63k4rq6lzejc7qygzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2cgy76q</id>
    
      <title type="html">DPDK will not start on 4K pages. Check CPU flags pse (2M) / ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsful7psmcjfac9h5ufu644753ug7pjhax6vkf63k4rq6lzejc7qygzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2cgy76q" />
    <content type="html">
      DPDK will not start on 4K pages.&lt;br/&gt;&lt;br/&gt;Check CPU flags pse (2M) / pdpe1gb (1G), GRUB hugepages=, mount hugetlbfs, then dpdk-devbind.py (or vfio-pci). EAL dying before a bind is almost always this.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1556&#34;&gt;https://sunshout.tistory.com/1556&lt;/a&gt;
    </content>
    <updated>2026-08-26T03:29:24Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfe39h24dlzdfd0rgmpvamcaachc4090s6s9frguu49ctks98yuyszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2m8pcpx</id>
    
      <title type="html">82599 VF reports 100M: believe the PF, not guest ethtool. The VF ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfe39h24dlzdfd0rgmpvamcaachc4090s6s9frguu49ctks98yuyszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2m8pcpx" />
    <content type="html">
      82599 VF reports 100M: believe the PF, not guest ethtool.&lt;br/&gt;&lt;br/&gt;The VF mailbox often lies (autoneg/100M) while the PF is 10G Twinax and traffic flows.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1646&#34;&gt;https://sunshout.tistory.com/1646&lt;/a&gt;
    </content>
    <updated>2026-08-26T03:29:24Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfwzlx6rsvlxmn6vmv7vuqrp2ukqsnklncswmjvm4teflktp80g4gzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2f8dx80</id>
    
      <title type="html">KVM MSI is a memory write, not a pin IRQ. Message Data goes to ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfwzlx6rsvlxmn6vmv7vuqrp2ukqsnklncswmjvm4teflktp80g4gzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2f8dx80" />
    <content type="html">
      KVM MSI is a memory write, not a pin IRQ.&lt;br/&gt;&lt;br/&gt;Message Data goes to Message Address. Posted interrupt is the later fast path.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1617&#34;&gt;https://sunshout.tistory.com/1617&lt;/a&gt;
    </content>
    <updated>2026-08-26T03:29:24Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspx58jp2a47kdy7j0hj8cxmzxhdmd5r2fg6nngv267vvgses9mueszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m26v77f3</id>
    
      <title type="html">VPP startup.conf: queue counts live under dpdk { dev default }. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspx58jp2a47kdy7j0hj8cxmzxhdmd5r2fg6nngv267vvgses9mueszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m26v77f3" />
    <content type="html">
      VPP startup.conf: queue counts live under dpdk { dev default }.&lt;br/&gt;&lt;br/&gt;num-rx-queues / num-tx-queues are RSS and rings. VLAN strip on an EC2 VF is a different flag.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1915&#34;&gt;https://sunshout.tistory.com/1915&lt;/a&gt;
    </content>
    <updated>2026-08-26T03:29:24Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfrxcese25fgcafg6uppyj093wvrlwmhyx3rlxm6nrhqay9me2meczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2w03sze</id>
    
      <title type="html">VPP on an EC2 SR-IOV VF still sees VLAN tags unless you strip ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfrxcese25fgcafg6uppyj093wvrlwmhyx3rlxm6nrhqay9me2meczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2w03sze" />
    <content type="html">
      VPP on an EC2 SR-IOV VF still sees VLAN tags unless you strip them.&lt;br/&gt;&lt;br/&gt;vlan-strip-offload on in /etc/vpp/startup.conf (dpdk stanza).&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1916&#34;&gt;https://sunshout.tistory.com/1916&lt;/a&gt;
    </content>
    <updated>2026-08-25T07:19:59Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgkjgzh0amkzg6nxjpxeh7naam7lg9w56ulk64qx9jhcjx9hndgrczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2qjaqrs</id>
    
      <title type="html">OVS-DPDK vs SR-IOV: pick OVS when you still need live migration. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgkjgzh0amkzg6nxjpxeh7naam7lg9w56ulk64qx9jhcjx9hndgrczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2qjaqrs" />
    <content type="html">
      OVS-DPDK vs SR-IOV: pick OVS when you still need live migration.&lt;br/&gt;&lt;br/&gt;A VF wins PPS and typically freezes migrate. OVS keeps a host switch.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1655&#34;&gt;https://sunshout.tistory.com/1655&lt;/a&gt;
    </content>
    <updated>2026-08-25T07:19:59Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxep4ehhwvkvvawglq6a8rxx7t43hldvmmtz8t2kj6f63v720rhkszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2qksf08</id>
    
      <title type="html">Cisco ACI: an EPG is a policy group, not a VLAN. APIC is the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxep4ehhwvkvvawglq6a8rxx7t43hldvmmtz8t2kj6f63v720rhkszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2qksf08" />
    <content type="html">
      Cisco ACI: an EPG is a policy group, not a VLAN.&lt;br/&gt;&lt;br/&gt;APIC is the controller. Contracts/filters decide which EPGs may talk.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2051&#34;&gt;https://sunshout.tistory.com/2051&lt;/a&gt;
    </content>
    <updated>2026-08-25T07:19:59Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9x6qyr68qg2tnukuz3wwetlgfhw878vr9y2lsrzwuxqnu29f268szyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m23hr652</id>
    
      <title type="html">Jetson Xavier kernel rebuild: tegra_defconfig, not a laptop ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9x6qyr68qg2tnukuz3wwetlgfhw878vr9y2lsrzwuxqnu29f268szyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m23hr652" />
    <content type="html">
      Jetson Xavier kernel rebuild: tegra_defconfig, not a laptop defconfig.&lt;br/&gt;&lt;br/&gt;Use NVIDIA L4T public sources, then:&lt;br/&gt;make O=$TEGRA_KERNEL_OUT tegra_defconfig&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2140&#34;&gt;https://sunshout.tistory.com/2140&lt;/a&gt;
    </content>
    <updated>2026-08-25T07:19:59Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9pueqy066cvqnh787yn9hh7agm0307kxkkehuja08zfzvnsjtnuqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2enfwdc</id>
    
      <title type="html">An AZ is a failure domain, not a prettier name for a building. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9pueqy066cvqnh787yn9hh7agm0307kxkkehuja08zfzvnsjtnuqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2enfwdc" />
    <content type="html">
      An AZ is a failure domain, not a prettier name for a building.&lt;br/&gt;&lt;br/&gt;Dual-homing two NICs in the same AZ is not multi-AZ. Cross-AZ links should be independent fiber paths on a high-speed backbone.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2052&#34;&gt;https://sunshout.tistory.com/2052&lt;/a&gt;
    </content>
    <updated>2026-08-25T07:19:59Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyu50dks04pw55hd0u2u2h2vw22nry63x4xkzf2wf0ksr0n2wc7xszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2yffhk7</id>
    
      <title type="html">OpenStack Octavia: Amphora is an HAProxy VM, not Neutron LBaaS ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyu50dks04pw55hd0u2u2h2vw22nry63x4xkzf2wf0ksr0n2wc7xszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2yffhk7" />
    <content type="html">
      OpenStack Octavia: Amphora is an HAProxy VM, not Neutron LBaaS v1.&lt;br/&gt;&lt;br/&gt;HA is Active/Standby amphorae. Scale-out is more amphorae.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2049&#34;&gt;https://sunshout.tistory.com/2049&lt;/a&gt;
    </content>
    <updated>2026-08-25T07:19:59Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsphvqylzypcmy393r3cjp579ns25uuunkp2hfx4vqtnf7d43av0rqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2xf0p3f</id>
    
      <title type="html">Helm install kong is not Service plus Route. helm repo add kong ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsphvqylzypcmy393r3cjp579ns25uuunkp2hfx4vqtnf7d43av0rqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2xf0p3f" />
    <content type="html">
      Helm install kong is not Service plus Route.&lt;br/&gt;&lt;br/&gt;helm repo add kong &lt;a href=&#34;https://charts.konghq.com&#34;&gt;https://charts.konghq.com&lt;/a&gt;&lt;br/&gt;helm install kong kong/kong -n kong&lt;br/&gt;&lt;br/&gt;Admin API nouns live on :8001.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2056&#34;&gt;https://sunshout.tistory.com/2056&lt;/a&gt;
    </content>
    <updated>2026-08-25T07:19:59Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs08sew37sm20jmcelxyprrxqee22gulfeyz660nykggu9yentvnwczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2mevuq2</id>
    
      <title type="html">Cluster API: a Cluster YAML, not a click-ops bootstrap. Declare ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs08sew37sm20jmcelxyprrxqee22gulfeyz660nykggu9yentvnwczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2mevuq2" />
    <content type="html">
      Cluster API: a Cluster YAML, not a click-ops bootstrap.&lt;br/&gt;&lt;br/&gt;Declare Cluster, Machine, MachineSet. Providers differ; the reconcile loop does not. Upgrades become spec changes.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2089&#34;&gt;https://sunshout.tistory.com/2089&lt;/a&gt;
    </content>
    <updated>2026-08-25T07:03:11Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs28ya8pegurjqxdma299tzf2p8k9vmzfzfczhydyzgz4fx7lefepgzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2ujuz2m</id>
    
      <title type="html">AWS WAF is not in your VPC. It sits on CloudFront, ALB, API ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs28ya8pegurjqxdma299tzf2p8k9vmzfzfczhydyzgz4fx7lefepgzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2ujuz2m" />
    <content type="html">
      AWS WAF is not in your VPC. It sits on CloudFront, ALB, API Gateway.&lt;br/&gt;&lt;br/&gt;Associating WAF with an in-VPC ALB still filters at that integration, not next to the ENI. A box in a subnet would be Network Firewall or an NVA.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2054&#34;&gt;https://sunshout.tistory.com/2054&lt;/a&gt;
    </content>
    <updated>2026-08-25T07:03:11Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxkmx8l6xk9qea9qrh9asqnh7kwq7t9g4x23y0mrjq903ltr7dcsszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2yrwvd9</id>
    
      <title type="html">Kong: Service, Route, Plugin, Consumer. Admin API on :8001. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxkmx8l6xk9qea9qrh9asqnh7kwq7t9g4x23y0mrjq903ltr7dcsszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2yrwvd9" />
    <content type="html">
      Kong: Service, Route, Plugin, Consumer. Admin API on :8001.&lt;br/&gt;&lt;br/&gt;Service is the upstream. Route is how clients hit it. Plugin is auth/rate-limit. Consumer holds credentials.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2057&#34;&gt;https://sunshout.tistory.com/2057&lt;/a&gt;
    </content>
    <updated>2026-08-25T07:03:11Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqhlvv2ksrg6l8x27xyjwwwz7vdehmczhvytmk3y6yue3muz38z2szyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m28eahcm</id>
    
      <title type="html">Gateway API vs Ingress: Gateway &#43; HTTPRoute, not one fat object. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqhlvv2ksrg6l8x27xyjwwwz7vdehmczhvytmk3y6yue3muz38z2szyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m28eahcm" />
    <content type="html">
      Gateway API vs Ingress: Gateway &#43; HTTPRoute, not one fat object.&lt;br/&gt;&lt;br/&gt;Ingress is one L7 object. Gateway API splits the listener (Gateway) from the app team&amp;#39;s HTTPRoute. L4 is in scope; classic Ingress is not.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2079&#34;&gt;https://sunshout.tistory.com/2079&lt;/a&gt;
    </content>
    <updated>2026-08-25T07:03:11Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsw8vj9nhrrf2l45zsu6swa94qqqx74mp4wcrfr0zejz8j5g8u79wqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m23wy0wz</id>
    
      <title type="html">EBS gp3 vs io2 Block Express: IOPS sliders do not buy tail ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsw8vj9nhrrf2l45zsu6swa94qqqx74mp4wcrfr0zejz8j5g8u79wqzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m23wy0wz" />
    <content type="html">
      EBS gp3 vs io2 Block Express: IOPS sliders do not buy tail latency.&lt;br/&gt;&lt;br/&gt;Both leave the instance through Nitro. gp3 is a multi-tenant SSD cluster (IOPS and throughput provision separately, some oversubscription, jitter). io2 Block Express uses custom NVMe plus SRD and multi-path, which cuts tail latency rather than advertised IOPS.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2184&#34;&gt;https://sunshout.tistory.com/2184&lt;/a&gt;
    </content>
    <updated>2026-08-25T06:55:48Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdyf2cradt3kayc4869x4mgsuz7679pwf078yfctfxhl5lrstmcngzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2mq7lnj</id>
    
      <title type="html">More vCPUs do not scale virtio-blk if one IOThread owns the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdyf2cradt3kayc4869x4mgsuz7679pwf078yfctfxhl5lrstmcngzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2mq7lnj" />
    <content type="html">
      More vCPUs do not scale virtio-blk if one IOThread owns the rings.&lt;br/&gt;&lt;br/&gt;Map virtqueues 1:1 onto IOThreads and pin them for low-latency disks. aio=io_uring is a separate host engine flag.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2136&#34;&gt;https://sunshout.tistory.com/2136&lt;/a&gt;
    </content>
    <updated>2026-08-25T06:55:48Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsv2qw5rg3w48fvzgmn9xpu054t4kfx0uau8wwqyudg09rz43p304gzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m277yqsc</id>
    
      <title type="html">IPsec: AH authenticates, ESP encrypts, IKE builds the SA. AH does ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsv2qw5rg3w48fvzgmn9xpu054t4kfx0uau8wwqyudg09rz43p304gzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m277yqsc" />
    <content type="html">
      IPsec: AH authenticates, ESP encrypts, IKE builds the SA.&lt;br/&gt;&lt;br/&gt;AH does not encrypt. ESP encrypts (and usually authenticates) the payload. IKE negotiates keys. A TLS certificate does not repair an IPsec tunnel.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2113&#34;&gt;https://sunshout.tistory.com/2113&lt;/a&gt;
    </content>
    <updated>2026-08-25T06:55:48Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2jqpqrhum3tshs62uyyczuyzh6ea4af7pt73dus2ydva9kl9j3hczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2rhta0n</id>
    
      <title type="html">Old EBS jittered because Dom0 sat in the I/O loop. Xen-era guest ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2jqpqrhum3tshs62uyyczuyzh6ea4af7pt73dus2ydva9kl9j3hczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2rhta0n" />
    <content type="html">
      Old EBS jittered because Dom0 sat in the I/O loop.&lt;br/&gt;&lt;br/&gt;Xen-era guest I/O used a split driver: frontend in the guest, backend in Dom0. Encapsulation, encryption, and scheduling ran on shared host CPUs. Nitro moves that path onto a card.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2183&#34;&gt;https://sunshout.tistory.com/2183&lt;/a&gt;
    </content>
    <updated>2026-08-25T06:55:48Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqc4zqsj4eppn99tgd054kfydyz4y7v89grxm6mn978xyceqnhllczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2e8xwn9</id>
    
      <title type="html">VXLAN vs Geneve: pick by NIC offload, not by which overlay is ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqc4zqsj4eppn99tgd054kfydyz4y7v89grxm6mn978xyceqnhllczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2e8xwn9" />
    <content type="html">
      VXLAN vs Geneve: pick by NIC offload, not by which overlay is newer.&lt;br/&gt;&lt;br/&gt;VXLAN is UDP &#43; a 24-bit VNI and almost every NIC offloads it. Geneve adds extensible header options that controllers like, and older NICs offload it less often.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2053&#34;&gt;https://sunshout.tistory.com/2053&lt;/a&gt;
    </content>
    <updated>2026-08-25T06:55:48Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsy5vsn5g492fe74k62mjlqy5fl40tl4sjkgdzxsf3x3dfmsc3tjhczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m29cfspn</id>
    
      <title type="html">IOMMU ftrace: you will see groups and map/unmap, not ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsy5vsn5g492fe74k62mjlqy5fl40tl4sjkgdzxsf3x3dfmsc3tjhczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m29cfspn" />
    <content type="html">
      IOMMU ftrace: you will see groups and map/unmap, not dma_ops.map_page.&lt;br/&gt;&lt;br/&gt;Boot with trace_event=iommu. /sys/kernel/debug/tracing/events/iommu/ shows add/remove group, attach/detach domain, map/unmap, io_page_fault. intel_dma_ops.map_page is a different layer.&lt;br/&gt;&lt;br/&gt;Two add_device_to_group lines with the same groupID is why vfio bind fails — not a missing intel_iommu=on.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1717&#34;&gt;https://sunshout.tistory.com/1717&lt;/a&gt;
    </content>
    <updated>2026-08-25T06:35:50Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszck37r2u00ql8hdf5frxl43duy5n4ajct2g089673qc8p4slde0gzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2ey5l7l</id>
    
      <title type="html">KVM SR-IOV after VFs exist: virtio eth0 for management, VF eth1 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszck37r2u00ql8hdf5frxl43duy5n4ajct2g089673qc8p4slde0gzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2ey5l7l" />
    <content type="html">
      KVM SR-IOV after VFs exist: virtio eth0 for management, VF eth1 for datapath.&lt;br/&gt;&lt;br/&gt;PF and VF must have no IP on the host before you pass the VF. pci-stub / libvirt hostdev is the bind step. If sriov_numvfs is still empty, create VFs on the PF first.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1580&#34;&gt;https://sunshout.tistory.com/1580&lt;/a&gt;
    </content>
    <updated>2026-08-25T06:35:50Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsq8ev7xun8pqjqul23rf9m6ec586e6vfkd6lzmvp5texjhxmsh0aszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2y0gz7g</id>
    
      <title type="html">KVM posted interrupt is PIR → vIRR without a vmexit — until ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsq8ev7xun8pqjqul23rf9m6ec586e6vfkd6lzmvp5texjhxmsh0aszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2y0gz7g" />
    <content type="html">
      KVM posted interrupt is PIR → vIRR without a vmexit — until the vCPU is idle.&lt;br/&gt;&lt;br/&gt;If the target vCPU is already in guest mode, KVM sets the posted-interrupt bitmap and sends a notification IPI. Hardware syncs PIR to vIRR. No vmexit for that Fixed vector. If the vCPU is not running, the kick waits for vmentry.&lt;br/&gt;&lt;br/&gt;A host NIC IRQ on the same pCPU still wrecks this path. isolcpus alone does not move IRQs.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1614&#34;&gt;https://sunshout.tistory.com/1614&lt;/a&gt;
    </content>
    <updated>2026-08-25T06:35:50Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsp9smnm5cv4z6zzvaht4auuufyxt04naueq455afrxecg6mwpdjpszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m207qwvv</id>
    
      <title type="html">Pi Zero &#43; MPU-9250: empty i2cdetect is a 3.3V problem, not a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp9smnm5cv4z6zzvaht4auuufyxt04naueq455afrxecg6mwpdjpszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m207qwvv" />
    <content type="html">
      Pi Zero &#43; MPU-9250: empty i2cdetect is a 3.3V problem, not a Python library.&lt;br/&gt;&lt;br/&gt;Pi GPIO is 3.3V tolerant. Feed VCC from Pin 1 (3.3V), not Pin 2/4 (5V), unless the I2C lines are shifted.&lt;br/&gt;&lt;br/&gt;VCC Pin 1, GND Pin 6, SDA Pin 3, SCL Pin 5.&lt;br/&gt;raspi-config → I2C enable → reboot → i2cdetect -y 1. Want 0x68.&lt;br/&gt;0x69 = AD0 high. UU = kernel driver owns the address. Empty = power/Dupont/I2C off.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2204&#34;&gt;https://sunshout.tistory.com/2204&lt;/a&gt;
    </content>
    <updated>2026-08-25T05:27:57Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswhg2gumvrwtdgnte0sanzmjllwf9zl4a209anxj7an9l94z2gx2gzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2x8a9hw</id>
    
      <title type="html">isolcpus= takes CPUs off the scheduler. Hardware IRQs still land ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswhg2gumvrwtdgnte0sanzmjllwf9zl4a209anxj7an9l94z2gx2gzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2x8a9hw" />
    <content type="html">
      isolcpus= takes CPUs off the scheduler. Hardware IRQs still land there.&lt;br/&gt;&lt;br/&gt;After update-grub and reboot, top can look idle on those cores while /proc/interrupts still ticks. For DPDK / poll-mode you still need irqaffinity or isolcpus=managed_irq.&lt;br/&gt;&lt;br/&gt;Lab notes (commands I actually ran):&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1620&#34;&gt;https://sunshout.tistory.com/1620&lt;/a&gt;
    </content>
    <updated>2026-08-25T05:19:46Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs296guy0ta5vg7dfr60h3z6d7g4v0f42r7lj7yeql6tguyumu3x4gzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m27l577u</id>
    
      <title type="html">intel_iommu=on is not SR-IOV. dmesg showing Intel-IOMMU: enabled ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs296guy0ta5vg7dfr60h3z6d7g4v0f42r7lj7yeql6tguyumu3x4gzyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m27l577u" />
    <content type="html">
      intel_iommu=on is not SR-IOV.&lt;br/&gt;&lt;br/&gt;dmesg showing Intel-IOMMU: enabled only means the IOMMU is on. You still have to create VFs on a PF:&lt;br/&gt;&lt;br/&gt;echo 4 &amp;gt; /sys/bus/pci/devices/0000:04:00.0/sriov_numvfs&lt;br/&gt;&lt;br/&gt;If that sysfs file is missing, firmware VF count is probably zero. vfio-pci bind failures after VFs appear are usually IOMMU groups.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/1615&#34;&gt;https://sunshout.tistory.com/1615&lt;/a&gt;
    </content>
    <updated>2026-08-25T05:19:46Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfee8e6tu3k9jmf380ufxq3ek5y85whvru7v34u795x8xmeyvnyfszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2f005my</id>
    
      <title type="html">QEMU virtio-blk: aio=io_uring is a host flag, not a guest ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfee8e6tu3k9jmf380ufxq3ek5y85whvru7v34u795x8xmeyvnyfszyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m2f005my" />
    <content type="html">
      QEMU virtio-blk: aio=io_uring is a host flag, not a guest package.&lt;br/&gt;&lt;br/&gt;guest virtio-blk → QEMU → libaio or io_uring → host block layer.&lt;br/&gt;The guest still just sees virtio. Host kernel 5.1&#43;:&lt;br/&gt;&lt;br/&gt;-drive file=disk.qcow2,format=qcow2,if=virtio,aio=io_uring&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2156&#34;&gt;https://sunshout.tistory.com/2156&lt;/a&gt;
    </content>
    <updated>2026-08-25T05:19:46Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyhr2pz6vmvkkt8d6fmk8q43ylw2u9ngy2makvtnzwzxmphtvkppczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m22ssew7</id>
    
      <title type="html">A new certificate does not fix &amp;#39;obsolete TLS&amp;#39;. openssl ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyhr2pz6vmvkkt8d6fmk8q43ylw2u9ngy2makvtnzwzxmphtvkppczyp2mk7w8gp5w8cunmzt772x7ll8lz7qgupfcn8jyxs99pyw5uv6m22ssew7" />
    <content type="html">
      A new certificate does not fix &amp;#39;obsolete TLS&amp;#39;.&lt;br/&gt;&lt;br/&gt;openssl s_client -connect host:443 -tls1     # must fail&lt;br/&gt;openssl s_client -connect host:443 -tls1_2   # must work&lt;br/&gt;&lt;br/&gt;If -tls1 still handshakes, raise nginx ssl_protocols (TLSv1.2 TLSv1.3) before you renew anything else. Let&amp;#39;s Encrypt issues the leaf; OpenSSL runs the handshake.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://sunshout.tistory.com/2206&#34;&gt;https://sunshout.tistory.com/2206&lt;/a&gt;
    </content>
    <updated>2026-08-25T05:19:46Z</updated>
  </entry>

</feed>