Skip to content

Cilium

Summary

Cilium is an eBPF-based CNI for Kubernetes. It provides pod networking, identity-based L3-L7 network policy, eBPF kube-proxy replacement, Gateway API and a sidecar-free service mesh, transparent encryption, multi-cluster networking (Cluster Mesh), and flow observability through Hubble. Its sub-project Tetragon adds kernel-level runtime security. Cilium is a CNCF Graduated project (2023-10-11). The current stable release is 1.20.2 (2026-09-15). Commercial support and the enterprise edition come from Isovalent, which Cisco acquired in 2024.

Overview

Cilium replaces iptables-based pod networking with eBPF programs that the Cilium agent loads into the Linux kernel. Services, policies and routing state live in BPF hash maps, so lookup cost does not grow with the number of rules. Policy is enforced on label-derived security identities, not IP addresses. The same datapath hooks produce the flow events behind Hubble. GKE Dataplane V2 and AKS "Azure CNI Powered by Cilium" both use Cilium, and EKS supports it through Helm.

Recent direction (1.18 to 1.20): Gateway API went from v1.3 to v1.6.1, IPv6 underlay and IPv6-only support grew, ztunnel-based mTLS encryption arrived (beta), the netkit datapath gained auto-detection (beta), extension points opened up (datapath plugins, beta), and older features were removed (Kafka L7 policy, proxylib, docker libnetwork). Mutual authentication was deprecated.

Key Facts

Attribute Detail
Latest Version 1.20.2 (2026-09-15). 1.20.0 released 2026-07-29
Supported branches 1.20, 1.19 (1.19.8), 1.18 (1.18.14). 1.17 is EOL. 1.21 in pre-release (1.21.0-pre.2, 2026-09-09)
Release cadence Feature release about every 6 months. Three stable branches maintained. Monthly patch releases
Repository github.com/cilium/cilium (stars ~22k+, as of 2026-07)
Language Go (control plane), C (eBPF programs)
License Apache 2.0 (userspace). eBPF code dual-licensed GPL-2.0 / BSD-2-Clause
Governance CNCF Graduated (accepted/incubating 2021-10-13, graduated 2023-10-11)
Commercial vendor Isovalent (part of Cisco): Isovalent Enterprise for Cilium
Kernel requirement Linux >= 5.10 (or RHEL 8.10's 4.18) since 1.18. netkit needs >= 6.8
Platforms Linux nodes only (no Windows node support). External (non-Kubernetes) workloads were removed in 1.18
Kubernetes (1.20) Tested on 1.33 - 1.36
Gateway API v1.6.1 (Cilium 1.20)
Tetragon 1.7.1 (2026-08-25)
Install Helm https://helm.cilium.io/ or oci://quay.io/cilium/charts/cilium, or cilium install

Architecture at a Glance

The Cilium agent on each node turns Kubernetes state into eBPF programs and maps. The operator handles cluster-wide IPAM and controllers, Envoy handles L7, and Hubble Relay aggregates flows. The full component diagram is in Explanation.

flowchart TB
    KAPI["kube-apiserver"]
    OPER["cilium-operator<br/>IPAM, Gateway API controller"]
    subgraph Node["Each node"]
        AGENT["cilium-agent + Hubble server"]
        subgraph Kernel["Linux kernel"]
            eBPF["eBPF programs<br/>(TC/tcx, XDP, socket)"]
            Maps["BPF maps<br/>(ipcache, policy, LB, CT)"]
        end
        ENVOY["cilium-envoy (L7)"]
    end
    RELAY["Hubble Relay + UI"]
    TETRA["Tetragon (optional,<br/>separate DaemonSet)"]

    KAPI -->|"watch"| AGENT
    KAPI -->|"watch"| OPER
    AGENT -->|"loads"| eBPF
    AGENT -->|"updates"| Maps
    eBPF -->|"L7 redirect"| ENVOY
    AGENT -->|"flows"| RELAY
    TETRA -.->|"kprobes, LSM"| Kernel

    style Kernel fill:#f9a825,color:#000

Key Features

Feature Detail Maturity (1.20)
eBPF data plane Hash-map lookups replace linear iptables chains. veth by default, netkit optional Stable (netkit beta)
kube-proxy replacement ClusterIP/NodePort/LB/ExternalIP/HostPort in eBPF, socket-level LB, Maglev, DSR, XDP acceleration Stable
Network Policy K8s NetworkPolicy, CNP/CCNP, ClusterNetworkPolicy (1.20). L3/L4 + L7 (HTTP, gRPC, DNS/FQDN). Kafka L7 removed in 1.20 Stable
Hubble Flow logs, service map, DNS/HTTP visibility, Prometheus metrics, flow export Stable
Tetragon Runtime security: process, file, network events, in-kernel enforcement Separate project, 1.7.x
Gateway API / Ingress Gateway API v1.6.1 incl. TCPRoute, UDPRoute, ListenerSet, ExternalAuth. GAMMA Stable (new routes in 1.20)
Service mesh Sidecar-free: eBPF + per-node Envoy Stable
Cluster Mesh Multi-cluster pod connectivity, global services, MCS-API (stable in 1.20), up to 255/511 clusters Stable
Encryption WireGuard or IPsec (with strict mode), ztunnel mTLS WireGuard/IPsec stable, ztunnel beta
BGP / L2 announcements BGP control plane (v2 CRDs), LB-IPAM, ARP/NDP announcements (IPv6 since 1.19) Stable
Egress gateway Static egress IPs, multiple gateways and IPv6 (1.18) Stable
Bandwidth manager EDT-based egress rate limiting, BBR, ingress token bucket (1.18) Stable
Mutual authentication SPIFFE/SPIRE-based auth Beta, deprecated in 1.20

Full maturity and deprecation tables are in Reference.

Evaluation

Pros Cons
eBPF datapath scales better than iptables as services and policies grow Needs a modern kernel (>= 5.10 since 1.18, >= 6.8 for netkit)
Hubble: deep network observability with no sidecars More complex to run and debug than Flannel
Tetragon: kernel-level runtime security from the same ecosystem Agent needs CAP_SYS_ADMIN / privileged host access
Sidecar-free service mesh and Gateway API v1.6.1 Steeper learning curve (identities, BPF maps, many Helm knobs)
L3/L4/L7 identity-based network policies BPF map memory must be sized for large clusters
Socket-level load balancing, DSR, Maglev, XDP Migration from iptables-based CNIs or kube-proxy needs planning
CNCF Graduated, large community, used by GKE and AKS Features are removed on a fixed schedule (for example Kafka L7 in 1.20). Read the upgrade notes every minor

When Cilium fits

Choose Cilium for production clusters that need network policy beyond L3/L4, flow observability, kube-proxy-free service handling, multi-cluster connectivity, or Gateway API without a separate ingress stack. For tiny or edge clusters that only need pod connectivity, Flannel is simpler. Calico is the main alternative when BGP-centric designs, non-Kubernetes hosts, or older kernels dominate.

Performance claims

Percentages such as "30-40% faster than iptables" come from vendor and community posts that record no test conditions. The project's own CNI benchmark is from Cilium 1.9.6 and publishes charts, not a single speed-up figure. See Reference: Benchmarks for what the official benchmark and scalability report measured, and for the official map limits.

Licensing and Commercial Offering

  • Open source: the full CNI, Hubble, Cluster Mesh, Gateway API, encryption and Tetragon are free under Apache 2.0 (eBPF code GPL-2.0/BSD-2-Clause).
  • Isovalent Enterprise for Cilium: Isovalent (founded by Cilium's creators, acquired by Cisco on 2024-04-12) sells a supported distribution with extra enterprise features. Not published: Isovalent Enterprise for Cilium is sold through private offers and sales quotes, including on the Azure Marketplace (checked 2026-09-27).
  • Managed offerings: GKE Dataplane V2 and AKS Azure CNI Powered by Cilium run Cilium under the provider's lifecycle. The provider chooses which features and versions you get.

Topic Map

  • How-to Guides: install, upgrade, kube-proxy migration, policies, Gateway API, Cluster Mesh, encryption, netkit, Tetragon, troubleshooting
  • Reference: release matrix, Kubernetes/kernel requirements, ports, Helm values, map limits, feature maturity, deprecations, IPAM and routing modes, benchmarks
  • Explanation: components, eBPF datapath, How It Works, Hubble, Tetragon, Cluster Mesh, identity model, encryption, threat model
  • Commands & Recipes

Sources

Questions

Open

  • What is the real-world memory overhead of Cilium's ztunnel encryption (beta, 1.19+) compared with Istio ambient's ztunnel?
  • When will bpf.datapathMode default to auto/netkit and veth be deprecated? The docs only say "once base kernels become more ubiquitous".
  • In which release will the deprecated mutual authentication feature and the local REST policy API be removed?
  • What will Cilium 1.21 (expected around early 2027) contain? Track the 1.21 pre-releases.

Answered

  • Q: When did Cisco close the Isovalent acquisition? On 2024-04-12 (Cisco newsroom, MarketScreener).
  • Q: Does Cilium work with kernel < 5.8? No, for current releases. Cilium 1.18, 1.19 and 1.20 require Linux >= 5.10 (or 4.18 on RHEL 8.10). Cilium 1.16 and 1.17 accepted >= 5.4. Some features need more: BIG TCP IPv6 5.19, IPv4 6.3, netkit 6.8 (system requirements).
  • Q: Is Cilium a service mesh? Yes. It includes a sidecar-free mesh (eBPF for L3/L4 plus a per-node cilium-envoy for L7), Gateway API/GAMMA, and ztunnel-based mTLS (beta).
  • Q: Does Cilium still support Kafka-aware policy? No. Kafka L7 policy and proxylib were deprecated in 1.18 and removed in 1.20. Remove rules.kafka sections before upgrading.
  • Q: How does Cilium handle eBPF map memory pressure at 10,000+ pod scale? BPF maps have fixed upper limits and live in kernel memory. The CT, NAT and IP cache maps grow with connections and cluster-wide endpoints. Cilium sizes the large maps from node memory with bpf.mapDynamicSizeRatio (default 0.0025), and you can set explicit limits (bpf.ctTcpMax, bpf.ctAnyMax, bpf.natMax, bpf.policyMapMax, bpf.lbMapMax). The identity model helps: pods that share labels share one identity, which keeps policy maps small, and 1.20 wildcard entries shrink the world/cluster entity cost further. Default limits are in Reference.
  • Q: What is the migration path from kube-proxy to Cilium kube-proxy replacement? Either a maintenance-window cutover (set kubeProxyReplacement=true and k8sServiceHost/k8sServicePort, delete kube-proxy, restart Cilium) or a node-by-node migration: a CiliumNodeConfig sets kube-proxy-replacement for nodes with a migration label, kube-proxy is kept off those nodes by affinity, and each node is cordoned, labeled, has its Cilium pod restarted, is checked, and is uncordoned. The per-node flow is a pattern built from documented pieces, not an official procedure. See How-to Guides.