Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Nico Vibert, Filip Nikolic, James Laverack

Rating No ratings yet

Cilium is now considered the de facto cloud native networking platform for Kubernetes, connecting, securing, and monitoring millions of applications across thousands of clusters. With such versatility and feature-richness, Cilium can be daunting to learn. This comprehensive guide breaks Cilium down, making it broadly accessible to the increasing number of users who'll encounter the platform in their careers. Nico Vibert, Filip Nikolic, and James Laverack, all from Isovalent (creators of eBPF and Cilium), take you through how Cilium works, the problems it can solve, and how to run it in production. If you're an experienced platform engineer or network architect who wants to get on top of the next big thing in cloud networking, this book is for you. Learn about Kubernetes networking and the role of Cilium Dive into the various use cases Cilium addresses Understand Cilium's architecture and how it moves packets around Secure workloads through the use of network policies Connect multiple clusters for service load balancing and discovery Observe application networking performance for troubleshooting and forensics Leverage Cilium's built-in service mesh and networking capabilities for complex traffic engineering

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A hands-on guide to Cilium, the eBPF-powered cloud native networking platform for Kubernetes, covering how it works, what problems it solves, and how to run it in production. Best for platform engineers and network architects who already know Kubernetes and want to master its networking, security, and observability. 【Book Arc】 - **Opening (~0%–10%)**: Frames "Why Cilium?" — its origins, evolution, and core use cases within Kubernetes, plus a high-level map of the whole book and its companion labs. - **Early (~10%–30%)**: Introduces Cilium's architecture and major components (agent, operator, eBPF programs/maps, Envoy, Hubble, Cluster Mesh API server), then walks through installing, monitoring, and applying a first network policy. - **Middle (~30%–55%)**: Dives into the networking core — IP address management modes, the datapath (intranode vs. internode, native routing vs. encapsulation), Kubernetes service networking, and Ingress/Gateway API. - **Late (~55%–85%)**: Extends outward to performance features, multicluster communication, external client access, outbound traffic, and security — network policy fundamentals, advanced policy, and encryption. - **Ending (~85%–100%)**: Closes with observability via Hubble and the operational concerns of running Cilium day-to-day in production. 【Key Takeaways】 - **Cilium is the de facto cloud native networking platform for Kubernetes** (Opening): it connects, secures, and monitors applications at scale, and the book positions it as a platform engineers will increasingly encounter. (Opening) - **eBPF is the engine under the hood** (Early): Cilium's datapath is built from eBPF programs and maps that handle connection tracking, NAT, load balancing, and policy enforcement, with maps storing shared state. (Early) - **Cilium extends Kubernetes NetworkPolicy beyond L3/L4** (Early): the CiliumNetworkPolicy resource adds application-level rules (DNS names, HTTP methods) and operates on Kubernetes labels and identities rather than raw IPs. (Early) - **IPAM is a first-class design decision** (Middle): cluster-pool, multi-pool, and CRD-backed modes trade off flexibility, routing responsibility, and address-exhaustion risk — excerpts show multi-pool allocating additional CIDRs when demand grows. (Middle) - **The datapath has two main connectivity models** (Middle): native routing works when the underlay can carry PodCIDRs (or via static routes/BGP), while encapsulation (VXLAN/Geneve) tunnels pod traffic when you can't influence the underlay. (Middle) - **Cilium reaches beyond a single cluster** (Late): Cluster Mesh shares service and endpoint metadata so clusters can route to remote services as if local, and built-in BGP extends the cluster into the enterprise fabric for hybrid deployments. (Late) - **Security is layered** (Late): core network policy concepts lead into advanced policy capabilities and encryption, all enforced through eBPF. (Late) - **Observability and operations are built in** (Ending): Hubble (per-node server, Relay, CLI, UI) provides visibility for troubleshooting and forensics, while the final chapter addresses operating Cilium in production. (Ending) 【Reading Tips】 - **Follow the chapter sequence for the networking core** (Chapters 4–9): IPAM, datapath, services, and Ingress/Gateway API build on each other; skimming here will make later security and multicluster chapters harder. - **Run the examples as you go**: the book ships manifests on GitHub and most features work on kind at no cost, so hands-on practice is the fastest way to internalize the datapath and policy behavior. - **Deep-read the datapath chapter if you troubleshoot networking**: the packet-path walkthroughs (veth, cilium_host, encapsulation) are the mental model you'll reuse constantly. - **Skim the preface and TOC early** to plan your route, then treat IPAM and policy chapters as reference you'll return to. - **Use the companion Isovalent lab** when a feature can't run in nested network namespaces like kind. 【Coverage Limits】 The excerpts cover the book's structure, architecture, IPAM, datapath, and policy fundamentals well, but the security, observability, and operations chapters are only summarized — specific configurations and advanced details there are not covered here.
Excerpt 1
al sales department: 800-998-9938 or corporate@oreilly.com. Acquisitions Editor: Megan Laddusaw Indexer: Judith McConville Development Editor: Gary O’Brien C...
View in text
Excerpt 2
installation, configu‐ ration, and troubleshooting. Proxies Handle traffic that requires inspection beyond simple packet filtering. Envoy processes HTTP and...
View in text
Excerpt 3
to temporarily disable Hubble using cilium hubble disable. This is necessary because the Hubble UI cannot be enabled when Hubble is already running. Once you...
View in text
Excerpt 4
24) tcx/ingress cil_from_container prog_id 1668 link_id 37 lxcc5b0a1b7ddfb(26) tcx/ingress cil_from_container prog_id 1695 link_id 38 The listing shows sever...
View in text
Excerpt 5
As you’ll see here, Cilium’s kube-proxy replacement imple‐ ments all of these features, so users can rely on the same semantics that kube-proxy has while als...
View in text
Excerpt 6
and HTTP redirects. Finally, we saw how Gateway API can be used to manage east–west traffic through GAMMA. The examples in this chapter showed how the same r...
View in text
Excerpt 7
erface sits in the pod network namespace and is paired with a peer in the host network namespace. This arrangement allows pods to reach other pods and extern...
View in text
Excerpt 8
service—only services that can communicate with each other across the mesh—the settings that affect routing behavior are local to the cluster using that serv...
View in text
Tags
AI categories
Cloud NativeDevOps
ISBN: 8341622998
Publisher: O'Reilly Media
Publish Year: 2026
Language: English
Pages: 373
File Format: PDF
File Size: 9.9 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…