Cilium¶
Summary
Cilium is an eBPF-based CNI for Kubernetes. It provides pod networking, identity-based L3-L7 network policy, eBPF kube-proxy replacement, Gateway API and a sidecar-free service mesh, transparent encryption, multi-cluster networking (Cluster Mesh), and flow observability through Hubble. Its sub-project Tetragon adds kernel-level runtime security. Cilium is a CNCF Graduated project (2023-10-11). The current stable release is 1.20.2 (2026-09-15). Commercial support and the enterprise edition come from Isovalent, which Cisco acquired in 2024.
Overview¶
Cilium replaces iptables-based pod networking with eBPF programs that the Cilium agent loads into the Linux kernel. Services, policies and routing state live in BPF hash maps, so lookup cost does not grow with the number of rules. Policy is enforced on label-derived security identities, not IP addresses. The same datapath hooks produce the flow events behind Hubble. GKE Dataplane V2 and AKS "Azure CNI Powered by Cilium" both use Cilium, and EKS supports it through Helm.
Recent direction (1.18 to 1.20): Gateway API went from v1.3 to v1.6.1, IPv6 underlay and IPv6-only support grew, ztunnel-based mTLS encryption arrived (beta), the netkit datapath gained auto-detection (beta), extension points opened up (datapath plugins, beta), and older features were removed (Kafka L7 policy, proxylib, docker libnetwork). Mutual authentication was deprecated.
Key Facts¶
| Attribute | Detail |
|---|---|
| Latest Version | 1.20.2 (2026-09-15). 1.20.0 released 2026-07-29 |
| Supported branches | 1.20, 1.19 (1.19.8), 1.18 (1.18.14). 1.17 is EOL. 1.21 in pre-release (1.21.0-pre.2, 2026-09-09) |
| Release cadence | Feature release about every 6 months. Three stable branches maintained. Monthly patch releases |
| Repository | github.com/cilium/cilium (stars ~22k+, as of 2026-07) |
| Language | Go (control plane), C (eBPF programs) |
| License | Apache 2.0 (userspace). eBPF code dual-licensed GPL-2.0 / BSD-2-Clause |
| Governance | CNCF Graduated (accepted/incubating 2021-10-13, graduated 2023-10-11) |
| Commercial vendor | Isovalent (part of Cisco): Isovalent Enterprise for Cilium |
| Kernel requirement | Linux >= 5.10 (or RHEL 8.10's 4.18) since 1.18. netkit needs >= 6.8 |
| Platforms | Linux nodes only (no Windows node support). External (non-Kubernetes) workloads were removed in 1.18 |
| Kubernetes (1.20) | Tested on 1.33 - 1.36 |
| Gateway API | v1.6.1 (Cilium 1.20) |
| Tetragon | 1.7.1 (2026-08-25) |
| Install | Helm https://helm.cilium.io/ or oci://quay.io/cilium/charts/cilium, or cilium install |
Architecture at a Glance¶
The Cilium agent on each node turns Kubernetes state into eBPF programs and maps. The operator handles cluster-wide IPAM and controllers, Envoy handles L7, and Hubble Relay aggregates flows. The full component diagram is in Explanation.
flowchart TB
KAPI["kube-apiserver"]
OPER["cilium-operator<br/>IPAM, Gateway API controller"]
subgraph Node["Each node"]
AGENT["cilium-agent + Hubble server"]
subgraph Kernel["Linux kernel"]
eBPF["eBPF programs<br/>(TC/tcx, XDP, socket)"]
Maps["BPF maps<br/>(ipcache, policy, LB, CT)"]
end
ENVOY["cilium-envoy (L7)"]
end
RELAY["Hubble Relay + UI"]
TETRA["Tetragon (optional,<br/>separate DaemonSet)"]
KAPI -->|"watch"| AGENT
KAPI -->|"watch"| OPER
AGENT -->|"loads"| eBPF
AGENT -->|"updates"| Maps
eBPF -->|"L7 redirect"| ENVOY
AGENT -->|"flows"| RELAY
TETRA -.->|"kprobes, LSM"| Kernel
style Kernel fill:#f9a825,color:#000
Key Features¶
| Feature | Detail | Maturity (1.20) |
|---|---|---|
| eBPF data plane | Hash-map lookups replace linear iptables chains. veth by default, netkit optional | Stable (netkit beta) |
| kube-proxy replacement | ClusterIP/NodePort/LB/ExternalIP/HostPort in eBPF, socket-level LB, Maglev, DSR, XDP acceleration | Stable |
| Network Policy | K8s NetworkPolicy, CNP/CCNP, ClusterNetworkPolicy (1.20). L3/L4 + L7 (HTTP, gRPC, DNS/FQDN). Kafka L7 removed in 1.20 | Stable |
| Hubble | Flow logs, service map, DNS/HTTP visibility, Prometheus metrics, flow export | Stable |
| Tetragon | Runtime security: process, file, network events, in-kernel enforcement | Separate project, 1.7.x |
| Gateway API / Ingress | Gateway API v1.6.1 incl. TCPRoute, UDPRoute, ListenerSet, ExternalAuth. GAMMA | Stable (new routes in 1.20) |
| Service mesh | Sidecar-free: eBPF + per-node Envoy | Stable |
| Cluster Mesh | Multi-cluster pod connectivity, global services, MCS-API (stable in 1.20), up to 255/511 clusters | Stable |
| Encryption | WireGuard or IPsec (with strict mode), ztunnel mTLS | WireGuard/IPsec stable, ztunnel beta |
| BGP / L2 announcements | BGP control plane (v2 CRDs), LB-IPAM, ARP/NDP announcements (IPv6 since 1.19) | Stable |
| Egress gateway | Static egress IPs, multiple gateways and IPv6 (1.18) | Stable |
| Bandwidth manager | EDT-based egress rate limiting, BBR, ingress token bucket (1.18) | Stable |
| Mutual authentication | SPIFFE/SPIRE-based auth | Beta, deprecated in 1.20 |
Full maturity and deprecation tables are in Reference.
Evaluation¶
| Pros | Cons |
|---|---|
| eBPF datapath scales better than iptables as services and policies grow | Needs a modern kernel (>= 5.10 since 1.18, >= 6.8 for netkit) |
| Hubble: deep network observability with no sidecars | More complex to run and debug than Flannel |
| Tetragon: kernel-level runtime security from the same ecosystem | Agent needs CAP_SYS_ADMIN / privileged host access |
| Sidecar-free service mesh and Gateway API v1.6.1 | Steeper learning curve (identities, BPF maps, many Helm knobs) |
| L3/L4/L7 identity-based network policies | BPF map memory must be sized for large clusters |
| Socket-level load balancing, DSR, Maglev, XDP | Migration from iptables-based CNIs or kube-proxy needs planning |
| CNCF Graduated, large community, used by GKE and AKS | Features are removed on a fixed schedule (for example Kafka L7 in 1.20). Read the upgrade notes every minor |
When Cilium fits
Choose Cilium for production clusters that need network policy beyond L3/L4, flow observability, kube-proxy-free service handling, multi-cluster connectivity, or Gateway API without a separate ingress stack. For tiny or edge clusters that only need pod connectivity, Flannel is simpler. Calico is the main alternative when BGP-centric designs, non-Kubernetes hosts, or older kernels dominate.
Performance claims
Percentages such as "30-40% faster than iptables" come from vendor and community posts that record no test conditions. The project's own CNI benchmark is from Cilium 1.9.6 and publishes charts, not a single speed-up figure. See Reference: Benchmarks for what the official benchmark and scalability report measured, and for the official map limits.
Licensing and Commercial Offering¶
- Open source: the full CNI, Hubble, Cluster Mesh, Gateway API, encryption and Tetragon are free under Apache 2.0 (eBPF code GPL-2.0/BSD-2-Clause).
- Isovalent Enterprise for Cilium: Isovalent (founded by Cilium's creators, acquired by Cisco on 2024-04-12) sells a supported distribution with extra enterprise features. Not published: Isovalent Enterprise for Cilium is sold through private offers and sales quotes, including on the Azure Marketplace (checked 2026-09-27).
- Managed offerings: GKE Dataplane V2 and AKS Azure CNI Powered by Cilium run Cilium under the provider's lifecycle. The provider chooses which features and versions you get.
Topic Map¶
- How-to Guides: install, upgrade, kube-proxy migration, policies, Gateway API, Cluster Mesh, encryption, netkit, Tetragon, troubleshooting
- Reference: release matrix, Kubernetes/kernel requirements, ports, Helm values, map limits, feature maturity, deprecations, IPAM and routing modes, benchmarks
- Explanation: components, eBPF datapath, How It Works, Hubble, Tetragon, Cluster Mesh, identity model, encryption, threat model
- Commands & Recipes
Related Topics¶
- CNI Comparison: Cilium vs Calico vs Flannel
- Networking comparisons index
- Sibling CNIs: Calico, Flannel
- Networking domain
- Kubernetes: the platform Cilium plugs into
- Service Mesh: Istio ambient/ztunnel and sidecar meshes vs Cilium's mesh
- eBPF Developer Tutorial: eBPF fundamentals behind Cilium and Tetragon
- Coroot: another eBPF-based platform that often runs alongside Cilium
Sources¶
- Cilium documentation (stable = 1.20): official docs
- cilium/cilium repository and v1.20 CHANGELOG: release contents, removals
- Release 1.20.0 and GitHub releases
- Cilium Helm chart index (cilium/charts): release dates of all Cilium and Tetragon charts
- Cilium 1.20 release blog (Isovalent) and CNCF blog on Cilium 1.20 (2026-09-14)
- Cilium 1.19 release blog (Isovalent)
- Celebrating 10 Years of Cilium (cilium.io, 2026-03-23)
- System requirements: kernel, ports, privileges
- Upgrade guide: 1.20 upgrade notes
- eBPF & XDP reference: kernel datapath
- Hubble: observability pipeline
- Tetragon documentation: runtime security
- CNCF project page and CNCF landscape data: graduation dates (2021-10-13 incubating, 2023-10-11 graduated)
- Cilium blog: release announcements
- endoflife.date: Cilium: support windows
Questions¶
Open¶
- What is the real-world memory overhead of Cilium's ztunnel encryption (beta, 1.19+) compared with Istio ambient's ztunnel?
- When will
bpf.datapathModedefault toauto/netkit and veth be deprecated? The docs only say "once base kernels become more ubiquitous". - In which release will the deprecated mutual authentication feature and the local REST policy API be removed?
- What will Cilium 1.21 (expected around early 2027) contain? Track the 1.21 pre-releases.
Answered¶
- Q: When did Cisco close the Isovalent acquisition? On 2024-04-12 (Cisco newsroom, MarketScreener).
- Q: Does Cilium work with kernel < 5.8? No, for current releases. Cilium 1.18, 1.19 and 1.20 require Linux >= 5.10 (or 4.18 on RHEL 8.10). Cilium 1.16 and 1.17 accepted >= 5.4. Some features need more: BIG TCP IPv6 5.19, IPv4 6.3, netkit 6.8 (system requirements).
- Q: Is Cilium a service mesh? Yes. It includes a sidecar-free mesh (eBPF for L3/L4 plus a per-node
cilium-envoyfor L7), Gateway API/GAMMA, and ztunnel-based mTLS (beta). - Q: Does Cilium still support Kafka-aware policy? No. Kafka L7 policy and proxylib were deprecated in 1.18 and removed in 1.20. Remove
rules.kafkasections before upgrading. - Q: How does Cilium handle eBPF map memory pressure at 10,000+ pod scale? BPF maps have fixed upper limits and live in kernel memory. The CT, NAT and IP cache maps grow with connections and cluster-wide endpoints. Cilium sizes the large maps from node memory with
bpf.mapDynamicSizeRatio(default 0.0025), and you can set explicit limits (bpf.ctTcpMax,bpf.ctAnyMax,bpf.natMax,bpf.policyMapMax,bpf.lbMapMax). The identity model helps: pods that share labels share one identity, which keeps policy maps small, and 1.20 wildcard entries shrink theworld/clusterentity cost further. Default limits are in Reference. - Q: What is the migration path from kube-proxy to Cilium kube-proxy replacement? Either a maintenance-window cutover (set
kubeProxyReplacement=trueandk8sServiceHost/k8sServicePort, delete kube-proxy, restart Cilium) or a node-by-node migration: aCiliumNodeConfigsetskube-proxy-replacementfor nodes with a migration label, kube-proxy is kept off those nodes by affinity, and each node is cordoned, labeled, has its Cilium pod restarted, is checked, and is uncordoned. The per-node flow is a pattern built from documented pieces, not an official procedure. See How-to Guides.