Since the last edition we've seen four new Cilium case studies appear, all showcasing organizations running Cilium or Tetragon at impressive scale with high demands. Preferred Networks standardized Cilium across five clusters running more than 1,500 GPUs. Celonis rolled it out to 150+ Kubernetes clusters processing 3.5TB and 360 million requests a day. Splunk replaced three separate security tools with Tetragon, cutting CPU use 67% and memory use 74%. Etraveli repalced proprietary load balancers and eliminated production downtime by consolidating on Cilium. ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
View in browser
echo-newsletter 117

eCHO news is your bi-weekly wrap up of all things eBPF and Cilium. If you want to keep up on the latest in cloud native networking, observability, and security this is your quelle

22nd September 2026

 

Since the last edition we've seen four new Cilium case studies appear, all showcasing organizations running Cilium or Tetragon at impressive scale with high demands. Preferred Networks standardized Cilium across five clusters running more than 1,500 GPUs. Celonis rolled it out to 150+ Kubernetes clusters processing 3.5TB and 360 million requests a day. Splunk replaced three separate security tools with Tetragon, cutting CPU use 67% and memory use 74%. Etraveli repalced proprietary load balancers and eliminated production downtime by consolidating on Cilium.

 

Google also shared how they use eBPF to tailor CPU scheduling and cut RPC latency, leading to ~5% QPS improvement, and double digit throughput gains.

 

There's also a sneak peak at the upcoming Certified Kubernetes Network Engineer (CKNE) certification, plus three new eBPF labs.

 

If you're still reading, we have some passes for Linux Plumbers Conference to give away courtesy of the eBPF Foundation. If you will be in Prague and would like to attend, or would like to attend virtually, make sure you are subscribed to eCHO News on LinkedIn and reply via email or comment on LinkedIn (depending on where you are reading) with the talk you are most looking forward to from the eBPF track. We will select winners this week. And on that note, lets 🐝-gin.

The Technical

Zero-Trust Developer Platforms with Cilium Network Policies

OpenChoreo auto-generates CiliumNetworkPolicies from declared endpoint visibility

 

How AWS Lambda logs every flow across thousands of microVMs per host with eBPF and Rust

Engineers replaced iptables flow logging w/ eBPF & Rust at massive microVM scale

 

How Cilium Uses eBPF Socket Hooks for Kubernetes Service Load Balancing

Cilium load-balances K8s Services w/eBPF socket hooks instead of packet rewriting

 

Service Mesh Evolution: Istio Sidecars → Cilium eBPF

Migrating a 300-node mesh from Istio sidecars to Cilium eBPF cut API latency ~5%

 

Nutanix Flow & eBPF: Redefining Cloud-Native Security & Observability for NKP

Tetragon is certified to interoperate with Nutanix's eBPF-based Flow CNI

 

AgentGuard-hq/AgentGuard

eBPF LSM that lets AgentGuard block coding agents from bypassing prompt-based security rules

 

Jaycubic/Distributed-Security-Control-Plane

Distributed security control plane for asynchronous telemetry

 

travershartstone93/weird-sensor

Root-only eBPF collector

🐝

 

The Ecosystem

Preferred Networks unifies container networking for AI clusters with Cilium

Standardized on Cilium across 5 clusters running 1,5k+ GPUs & 200+ AI accelerators

 

How Celonis Standardized Networking Across 150+ Kubernetes Clusters with Cilium

Processing 3.5TB & 360 million requests daily across a Cilium networking stack

 

How Splunk Unified Security Observability and Reduced Infrastructure Costs with Cillium’s Tetragon

Cut CPU use 67% & memory use 74% by replacing 3 security tools with Tetragon

 

Etraveli Group Replaced Proprietary Load Balancers and Eliminated Production Downtime with Cilium

Load balancing capacity scales automatically with every node added to the cluster

 

How Google Uses eBPF to Tailor CPU Scheduling and Optimize Workload Performance

Google cut RPC latency & boosted throughput with custom eBPF CPU schedulers

 

Preparing for CKNE: What I Learned From the Beta Exam

A sneak peek at the new Certified Kubernetes Network Engineer certification

🐝

 

The How To

Cilium Gateway API for vCluster Tenant Clusters on RKE2 | Shared Gateway API Resources per Tenant
Share Gateway API resources across vCluster tenants using Cilium's LoadBalancerIPPool
🐝

 

The Video

De Nederlandse Kubernetes Podcast 144: Kubernetes Doesn't Build Your Network

A convo about how eBPF maps replace iptables for faster service routing

🐝

 

The Events

ACM SOSP'26 Workshop on eBPF and Kernel Extensions

September 29th in Prague

 

Linux Plumbers Conference

October 5-7th in Prague, schedule for eBPF Track 

 

CiliumCon

November 9 in Salt Lake City, schedule now live 

 

Security Native Europe

November 26 in Zurich, headlined by Daniel Borkmann on eBPF's role in live system hardening

 

CiliumCon Europe

March 15, 2027 in Barcelona, CFP open through October 18

🐝 

The Livestreams

eCHO Episode 215: Tetragon in GitHub Actions 

eCHO Episode 215: Exploring Tetragon in GitHub Actions

  

eCHO Episode 216: eBPF Lab Preview

eCHO 216: eBPF Labs sneak peek

The Post of the Week

Screenshot 2026-09-22 at 14.57.28

As always, if you’ve seen a blog post, a tool, or anything else eBPF or Cilium related that you think the rest of the community should hear about, send them my way. You can either hit reply or join the #echo-news channel on Cilium Slack. You can also find all of the past episodes on the website.

🐝

To make sure you keep getting these emails, please add kaoconno@cisco.com to your address book or otherwise mark me as a permitted sender.

 

Know a friend that needs to be in the know? Forward this to them

Was this forwarded to you? Sign up today!

Written and sent by Katie Meinders. Any feedback is welcome!

1755685839473

I work for Isovalent at Cisco which is leading the eBPF-Powered Revolution in Cloud Native Networking, Observability, and Security with Cilium and Tetragon

logo-wordmark-isovalent-vertical-dark@2x
LinkedIn
Bluesky_Logo.svg

Cisco/Isovalent, LLC, 755 Sycamore Drive, Milpitas, CA 95035, United States

Unsubscribe Manage preferences