Five years ago, when Google chose Cilium as the networking data plane for GKE, it was a massive milestone for the community. Google lays out all of the features that Cilium enabled in their 10 year networking review, but it can be simply summed up as Cilium "represented a significant leap in GKE's CNI capabilities." Since then Cilium has become the standard for Kubernetes networking and security.
View in browser
echo-newsletter-92 (1)

eCHO news is your bi-weekly wrap up of all things eBPF and Cilium. If you want to keep up on the latest in cloud native networking, observability, and security this is your quelle

7th October 2025

 

Five years ago, when Google chose Cilium as the networking data plane for GKE, it was a massive milestone for the community. Google lays out all of the features that Cilium enabled in their 10 year networking review, but it can be simply summed up as Cilium "represented a significant leap in GKE's CNI capabilities." Since then Cilium has become the standard for Kubernetes networking and security.

 

Don't believe me? Just look at the adopters page. And more recently, driven by customer demand, OVH chose Cilium as the default for their managed Kubernetes service and Isovalent's Cilium distribution became the first and only CNI certified across the entire Red Hat ecosystem (Network Conformance, OpenShift Virtualization, OpenShift Service Mesh, and OpenShift Hosted Control Planes). Cloud native has gone from “how do we get pods talking?” to “how do we orchestrate distributed AI pipelines across thousands of GPUs with microsecond latency?” No matter where enterprises need Kubernetes, Cilium is the default networking layer that they can rely upon.

 

I need to go ask more people to fill out the Cilium User Survey so let’s 🐝 -gin.

The Technical

Cilium Network Policies, from first principles to production

Explanation first and code second with annotated YAML

 

Linux Kernel Fundamentals for Effectively Writing Tetragon Tracing Policies

Start your journey to becoming a kernel hacker

 

A Tour of eBPF in the Linux Kernel: Observability, Security and Networking

Introduction and a small taste

 

Accelerating Pub-Sub Systems using eBPF

"XDP is obviously the most efficient of all, staying under 55% CPU usage even at the peak rate of 1.48 MReq/s"

 

What is 'Packet, where are you?' - Meet pwru!

"Auch…that would have saved me (more than) a few hours debugging tricky issues"

 

The Rabbit Hole of Building a Filesystem Watcher

Overcoming the issues of fanotify with eBPF

 

clang: avoid uninitialized variables in eBPF

"For now, make sure all stack variables are initialized!"

 

trndcenter/bpfmeter

Performance monitoring agent for eBPF programs

 

eunomia-bpf/schedcp

MCP Server for Linux Scheduler Management and Auto optimization

 

twisted-pear/ipx_wrap

A joke IPX implementation for Linux using eBPF

🐝

 

The Ecosystem

eBPF Summit 2025: This Year, it’s a Hackathon!

Time to build and showcase your ideas to the community

 

Cilium User Survey

Fill it out before it closes on the 23rd!

 

GKE network interface at 10: From core connectivity to the AI backbone

"Google Cloud embraced Cilium, a leading open-source CNI project built on eBPF, which represented a significant leap in GKE's CNI capabilities"

 

Scaling Cloudera’s development environment: Leveraging Amazon EKS, Karpenter, Bottlerocket, and Cilium for hybrid cloud

"Cilium allowed Cloudera to scale beyond 10,000 workloads without encountering IP exhaustion issues, all while offering clear visibility into pod-level networking"

 

eBPF Tech Talks at P99 CONF 2025

Any guesses which talk I'm looking forward to the most?

 

KubeCon + CloudNativeCon North America 2025 Co-Located Event Deep Dive: CiliumCon

Find out where to find me each morning in Atlanta

 

Networking’s Open Source Era Is Just Getting Started

Standards in bodies or in code?

 

Why L4 eBPF 🐝 Network Metrics Really Matter in Production

Find the bottlenecks in the network layer

 

How eBPF and Splunk Are Quietly Rewriting the Rules of Runtime Cloud Security

"CVE Scanners Tell You What. eBPF Tells You So What"

🐝

 

The How To

 Test Verifier Changes on Cilium's BPF Programs
 Cilium's large eBPF programs are good verifier complexity proving grounds
 

Azure CNI with Cilium: Beyond the Basics - Unlocking Enterprise eBPF Security

How to install full Cilium OSS on AKS

 

Getting started with pwru

From tracing your first flow to digesting and debugging the flow

🐝

 

The Video

APIM Hotrod S2E04 - Azure Kubernetes Service with Richard Hooper

"If anyone is running Calico, I would look at ways to migrate to Cilium"

 

Hijacking DNS Port 53 with eBPF & XDP for Remote K8s Access

Learn to let multiple DNS resolvers share the default DNS port 53

🐝

 

The Events

CiliumCon NA

November 10th in Atlanta. Schedule out now

 

eBPF Summit 2025: Hackathon Edition

Submissions open Oct 13–Nov 30

 

Container & Kubernetes Defense feat. eBPF

Training course in Zurich December 9-11

 

CiliumCon EU

CfP now open for Amsterdam. Deadline November 2nd

🐝 

The Livestreams

eCHO Episode 195: Clang-free: runtime config for Cilium & eBPF

 

eCHO Episode 195: Clang-free: runtime config for Cilium & eBPF

  

Upcoming (Oct. 17) - eCHO Episode 196: Exploring Tetragon on Linux Servers

eCHO Episode 196: Exploring Tetragon on Linux Servers

The Post of the Week

As always, if you’ve seen a blog post, a tool, or anything else eBPF or Cilium related that you think the rest of the community should hear about, send them my way. You can either hit reply or join the #echo-news channel on Cilium Slack. You can also find all of the past episodes on the website.

🐝

To make sure you keep getting these emails, please add bill@isovalent.com to your address book or otherwise mark me as a permitted sender.

 

Know a friend that needs to be in the know? Forward this to them

Was this forwarded to you? Sign up today!

Written and sent by Bill Mulligan. Any feedback is welcome!

KC+CNC_NA_Headshot_241114_William_Mulligan_8154 (1)

I work for Isovalent at Cisco which is leading the eBPF-Powered Revolution in Cloud Native Networking, Observability, and Security with Cilium and Tetragon

logo-wordmark-isovalent-vertical-dark@2x
LinkedIn
X

Cisco/Isovalent, LLC, 755 Sycamore Drive, Milipitas, CA 95035, United States

Unsubscribe Manage preferences