
How we Serve Encrypted Video at 70+ Gbps Per Server With go and kTLS
This story was originally published on HackerNoon at: https://hackernoon.com/how-we-serve-encrypted-video-at-70-gbps-per-server-with-go-and-ktls. A deep dive into scaling Go TLS to 100 Gbps per server: how kTLS and zero-copy cut CPU overhead when delivering encrypted video at scale. Check more stories related to media at: https://hackernoon.com/c/media. You can also check exclusive content about #video, #golang, #video-streaming, #video-streaming-platform, #high-load-systems, #linux, #ktls, #hackernoon-top-story, and more. This story was written by: @alex_pavlychev. Learn more about this writer by checking @alex_pavlychev's about page, and for more stories, please visit hackernoon.com. Serving encrypted video, our bottleneck turned out to be memory-copy bandwidth rather than the network: TLS has to encrypt in user space, which breaks zero-copy and pins the CPU. We moved TLS encryption into the kernel (kTLS) so sendfile and splice could work through the stack, switched our Let's Encrypt certificates from RSA to ECDSA, and synchronized one TLS session-ticket key across servers. Together those changes get us 70+ Gbps of encrypted video per 1U server, with the edge process nearly idle.










