Cilium is now considered the de facto cloud native networking platform for Kubernetes, connecting, securing, and monitoring millions of applications across thousands of clusters. With such versatility and feature-richness, Cilium can be daunting to learn. This comprehensive guide breaks Cilium down, making it broadly accessible to the increasing number of users who'll encounter the platform in their careers. Nico Vibert, Filip Nikolic, and James Laverack, all from Isovalent (creators of eBPF and Cilium), take you through how Cilium works, the problems it can solve, and how to run it in production. If you're an experienced platform engineer or network architect who wants to get on top of the next big thing in cloud networking, this book is for you. Learn about Kubernetes networking and the role of Cilium Dive into the various use cases Cilium addresses Understand Cilium's architecture and how it moves packets around Secure workloads through the use of network policies Connect multiple clusters for service load balancing and discovery Observe application networking performance for troubleshooting and forensics Leverage Cilium's built-in service mesh and networking capabilities for complex traffic engineering
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
Tip the Site
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat Pay
Alipay
Open WeChat or Alipay and scan. No login required.
AI guide
【One-Line Pitch】
A hands-on guide to Cilium, the eBPF-powered cloud native networking platform for Kubernetes, covering how it works, what problems it solves, and how to run it in production. Best for platform engineers and network architects who already know Kubernetes and want to master its networking, security, and observability.
【Book Arc】
- **Opening (~0%–10%)**: Frames "Why Cilium?" — its origins, evolution, and core use cases within Kubernetes, plus a high-level map of the whole book and its companion labs.
- **Early (~10%–30%)**: Introduces Cilium's architecture and major components (agent, operator, eBPF programs/maps, Envoy, Hubble, Cluster Mesh API server), then walks through installing, monitoring, and applying a first network policy.
- **Middle (~30%–55%)**: Dives into the networking core — IP address management modes, the datapath (intranode vs. internode, native routing vs. encapsulation), Kubernetes service networking, and Ingress/Gateway API.
- **Late (~55%–85%)**: Extends outward to performance features, multicluster communication, external client access, outbound traffic, and security — network policy fundamentals, advanced policy, and encryption.
- **Ending (~85%–100%)**: Closes with observability via Hubble and the operational concerns of running Cilium day-to-day in production.
【Key Takeaways】
- **Cilium is the de facto cloud native networking platform for Kubernetes** (Opening): it connects, secures, and monitors applications at scale, and the book positions it as a platform engineers will increasingly encounter. (Opening)
- **eBPF is the engine under the hood** (Early): Cilium's datapath is built from eBPF programs and maps that handle connection tracking, NAT, load balancing, and policy enforcement, with maps storing shared state. (Early)
- **Cilium extends Kubernetes NetworkPolicy beyond L3/L4** (Early): the CiliumNetworkPolicy resource adds application-level rules (DNS names, HTTP methods) and operates on Kubernetes labels and identities rather than raw IPs. (Early)
- **IPAM is a first-class design decision** (Middle): cluster-pool, multi-pool, and CRD-backed modes trade off flexibility, routing responsibility, and address-exhaustion risk — excerpts show multi-pool allocating additional CIDRs when demand grows. (Middle)
- **The datapath has two main connectivity models** (Middle): native routing works when the underlay can carry PodCIDRs (or via static routes/BGP), while encapsulation (VXLAN/Geneve) tunnels pod traffic when you can't influence the underlay. (Middle)
- **Cilium reaches beyond a single cluster** (Late): Cluster Mesh shares service and endpoint metadata so clusters can route to remote services as if local, and built-in BGP extends the cluster into the enterprise fabric for hybrid deployments. (Late)
- **Security is layered** (Late): core network policy concepts lead into advanced policy capabilities and encryption, all enforced through eBPF. (Late)
- **Observability and operations are built in** (Ending): Hubble (per-node server, Relay, CLI, UI) provides visibility for troubleshooting and forensics, while the final chapter addresses operating Cilium in production. (Ending)
【Reading Tips】
- **Follow the chapter sequence for the networking core** (Chapters 4–9): IPAM, datapath, services, and Ingress/Gateway API build on each other; skimming here will make later security and multicluster chapters harder.
- **Run the examples as you go**: the book ships manifests on GitHub and most features work on kind at no cost, so hands-on practice is the fastest way to internalize the datapath and policy behavior.
- **Deep-read the datapath chapter if you troubleshoot networking**: the packet-path walkthroughs (veth, cilium_host, encapsulation) are the mental model you'll reuse constantly.
- **Skim the preface and TOC early** to plan your route, then treat IPAM and policy chapters as reference you'll return to.
- **Use the companion Isovalent lab** when a feature can't run in nested network namespaces like kind.
【Coverage Limits】
The excerpts cover the book's structure, architecture, IPAM, datapath, and policy fundamentals well, but the security, observability, and operations chapters are only summarized — specific configurations and advanced details there are not covered here.
Excerpt 1
al sales department: 800-998-9938 or corporate@oreilly.com. Acquisitions Editor: Megan Laddusaw Indexer: Judith McConville Development Editor: Gary O’Brien C...
to temporarily disable Hubble using cilium hubble disable. This is necessary because the Hubble UI cannot be enabled when Hubble is already running. Once you...
As you’ll see here, Cilium’s kube-proxy replacement imple‐ ments all of these features, so users can rely on the same semantics that kube-proxy has while als...
and HTTP redirects. Finally, we saw how Gateway API can be used to manage east–west traffic through GAMMA. The examples in this chapter showed how the same r...
erface sits in the pod network namespace and is paired with a peer in the host network namespace. This arrangement allows pods to reach other pods and extern...
service—only services that can communicate with each other across the mesh—the settings that affect routing behavior are local to the cluster using that serv...
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.
Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat PayAlipay
Open WeChat or Alipay and scan. No login required.
Add Tag
Enter tag name (max 50 characters)
Share E-Book
Cilium Up and Running (Nico Vibert, Filip Nikolic, James Laverack)(Z-Library)
Scan QR code with your phone to access
Copy the link or scan the QR code to access this e-book on your phone
Share E-Book via Email
Please enter email address
Donation Statistics
¥.00
Total Donations
0
Donation Count
Cilium Up and Running (Nico Vibert, Filip Nikolic, James Laverack)(Z-Library)
Find Your Favorite Books
Only registered users can comment after logging in. Comments need to be reviewed by administrators before being displayed
Loading comments...
Reply to Comment
Edit Comment