"For the next 10 years, eBPF is going to be the strategic platform of choice for infrastructure developers." That is the line that really stuck with me from Daniel Borkmann's keynote at Open Source Summit. For the past 10 years, the community has been putting all of the pieces in place to make eBPF the default choice when looking to add new functionality in the kernel. Now comes the fun part, pushing beyond early adopters into mainstream systems engineering. The building blocks are all there with a stable ISA, mature verifier, growing ecosystem, and real-world deployments at massive scale. The conversation is shifting from “can eBPF do this?” to “how do we best use it?” If the first decade was about proving the technology, the next one is about using it to reshape how we build and operate systems from the inside out. I have to put the finishing touches on the CiliumCon schedule which is coming out tomorrow so let’s 🐝 -gin.
View in browser
echo-newsletter-88

eCHO news is your bi-weekly wrap up of all things eBPF and Cilium. If you want to keep up on the latest in cloud native networking, observability, and security this is your quelle

12th August 2025

 

"For the next 10 years, eBPF is going to be the strategic platform of choice for infrastructure developers." That is the line that really stuck with me from Daniel Borkmann's keynote at Open Source Summit. For the past 10 years, the community has been putting all of the pieces in place to make eBPF the default choice when looking to add new functionality in the kernel.

 

Now comes the fun part, pushing beyond early adopters into mainstream systems engineering. The building blocks are all there with a stable ISA, mature verifier, growing ecosystem, and real-world deployments at massive scale. The conversation is shifting from “can eBPF do this?” to “how do we best use it?”

 

If the first decade was about proving the technology, the next one is about using it to reshape how we build and operate systems from the inside out. I have to put the finishing touches on the CiliumCon schedule which is coming out tomorrow so let’s 🐝 -gin.

The Technical

Cilium 1.18 - Expanded IPv6 Support, Encrypted Overlay, Ingress Bandwidth Controls, Policy Performance Improvements, and More!
Release blog! Latency down 40%, CPU usage down 43%, 30% smaller arm images
 
Mastering Enterprise-Grade Networking in Kubernetes with Cilium’s Latest Features
 
Improving Network Performance with Custom eBPF-based Schedulers
Enabling 5G network slicing and QoS with eBPF and sched-ext
 
When TCP Window Scaling Broke Our API — and How I Solve It with eBPF
See how eBPF filled an observability gap in the kernel networking stack
 
Practical Guide to Cilium Network Policy using iximiuz Labs - CKS Edition
Learn to ace the CKS exam with a hands on lab
 
BGP Integration: Cilium and UniFi Cloud Gateway Max
Removing MetalLB and HAProxy was a "really easy and a smooth operation"
 
Bouncing on trampolines to run eBPF programs
Thanks to the fundings from the eBPF foundation, this work is now integrated!
 
Cilium Network Deep Dive: Routing, Masquerading, and DNS
"When you combine these features you get a network that’s both fast and flexible"
 
Two‑Phase eBPF Program Signing: Bridging Compilation and Load‑Time Integrity
Trying to strike the balance between flexibility and security
 
Detecting io_uring activity with eBPF
" io_uring is not a big problem for EDRs that use ebpf"
 
Understanding Cilium’s Network Routing Modes — Native Routing and Encapsulation
Ensuring pod traffic can traverse network boundaries with performance
 
Cilium Network Policies
Advantages of Cilium over standard K8s network policies and examples
 
appsec-jedi/pipeline-sentinel

A lightweight, eBPF-powered security monitor for CI/CD build pipelines

 

SRodi/ebpf-server

Data Backend server using eBPF to monitor network connections and provide real-time network analytics

 

bombinisecurity/bombini

eBPF security monitoring agent based on Aya

🐝

 

The Ecosystem

Stop Using the Wrong CNI in 2025: Flannel vs Calico vs Cilium
"Cilium: The Upgrade Your Cluster Actually Needs"
 

Explore Our New eCHO Playlist Library

Catch up on the episodes you missed or deep dive into a topic

 

Can we move Service Mesh to the kernel?

"Cilium essentially turns the Linux kernel into your new service mesh proxy"

 

AI Clouds Are Flying Blind: The Illusion of Runtime Protection

"[eBPF] became the undisputed industry standard for runtime security"

🐝

 

The How To

eBPF Uprobes: Tracing gRPC Headers by Unpacking Go Function Internals
From understanding Go's register-based calling convention to successfully extracting gRPC headers from running applications using eBPF uprobes
 
Installing Cilium and Multus on Talos OS for Advanced Kubernetes Networking
Disable Flannel and kube-proxy, bring on multiple interfaces

🐝

 

The Video

The Illustrated Children's Guide to eBPF

Cisco DevNet had me on to talk about the book and the eBPF ecosystem in general

 

Keynote - eBPF: Unlocking Innovation in the Linux Kernel

"For the next 10 years, eBPF is going to be the strategic platform of choice for infrastructure developers"

 

hello-ebpf: Writing eBPF Programs Directly in Java

With a little bit of sched-ext sprinkled in

🐝

 

The Events

Isovalent Enterprise Load Balancer: Traffic Management for your Datacenter

September 4th, online webinar

 

SIGCOMM 2025 eBPF Workshop

September 8-11th in Coimbra

 

Stop Hoarding Networking Tools: Declutter Your Cluster with the Isovalent Platform

September 14th, online webinar

 

CiliumCon

November 10th in Atlanta

🐝 

The Livestreams

eCHO Episode 190: Enigma Machine in eBPF

eCHO Episode 190: Enigma Machine in eBPF

  

eCHO Episode 191: Exploring New Features in Cilium 1.18

eCHO Episode 191: Exploring New Features in Cilium 1.18

Upcoming Stream

eCHO Episode 192: TBD

The Post of the Week

The list of papers accepted at the 3rd hashtag#eBPF workshop has been published!

As always, if you’ve seen a blog post, a tool, or anything else eBPF or Cilium related that you think the rest of the community should hear about, send them my way. You can either hit reply or join the #echo-news channel on Cilium Slack. You can also find all of the past episodes on the website.

🐝

To make sure you keep getting these emails, please add bill@isovalent.com to your address book or otherwise mark me as a permitted sender.

 

Know a friend that needs to be in the know? Forward this to them

Was this forwarded to you? Sign up today!

Written and sent by Bill Mulligan. Any feedback is welcome!

KC+CNC_NA_Headshot_241114_William_Mulligan_8154 (1)

I work for Isovalent at Cisco which is leading the eBPF-Powered Revolution in Cloud Native Networking, Observability, and Security with Cilium and Tetragon

logo-wordmark-isovalent-vertical-dark@2x
LinkedIn
X

Cisco/Isovalent, LLC, 755 Sycamore Drive, Milipitas, CA 95035, United States

Unsubscribe Manage preferences