Ten Years of Cilium: Community Scale and Adoption

▶ Watch (0:02)

Cilium’s first commit landed a decade ago, before Kubernetes was stable and before AI workloads existed. Today the project counts over 1,000 individual contributors and nearly 50,000 GitHub stars. In the latest State of Kubernetes Networking report, Cilium captured two-thirds of CNI votes. The same survey shows users planning Gateway API, multicluster connectivity, and eBPF-based capabilities next, all features already shipping in Cilium 1.19 alongside BGP improvements, multi-pool IPAM, and DNS host firewall.

Celonis: Migrating 160 Clusters from AWS CNI to Cilium

▶ Watch (5:00)

Celonis runs 160 clusters across AWS, Azure, and GCP, processing 3.5 terabytes of data daily and serving 360 million requests per day. Before Cilium, each cluster brought its own CNI and separate MTLS implementation. The team ran multiple CNI flavors including Karpenter, Kops, and OpenShift. That fragmentation consumed engineering capacity just keeping systems running. Marcelo Mello’s team needed a single solution that worked consistently across every environment without reinstalling clusters.

The Zero-Downtime EKS Migration Strategy

▶ Watch (8:03)

Starting in 2024, Celonis installed Cilium in hybrid mode alongside AWS CNI on existing EKS clusters. They labeled AWS CNI DaemonSets and nodes, then cordoned workloads off legacy nodes. The autoscaler forced new pods onto Cilium-managed nodes during rollouts. Draining took hours or days depending on cluster load. Once workloads moved, the team flipped each cluster to exclusive mode, removing AWS CNI and kube-proxy entirely. The result: full eBPF mode with kube-proxy replacement and near-zero downtime. Key lesson: monitor BPF maps closely, or they cause production problems.

Tetragon: Runtime Security Built on eBPF

▶ Watch (11:19)

Tetragon became GA in 2023 and tracks four signals: process execution, network observability, file access, and layer 7 network identity. It sits in the kernel via eBPF and ties every observation back to a Kubernetes identity. Since GA, the team shipped Kubernetes identity-aware policies, redaction filters that strip passwords from logs using regex, persistent enforcement that keeps policies active even if the Tetragon agent dies, event throttling to prevent overload, and support for both containerd and CRI-O runtimes.

Microsoft: Multicluster Scale and Cilium MTLS with Z Tunnel

▶ Watch (16:09)

Microsoft ships two multicluster improvements upstream. Hybrid routing mode lets a cluster use native routing locally while encapsulating cross-cluster traffic, avoiding a forced choice between all-native and all-overlay. Identity filtering in cluster mesh lets operators share only relevant service identities across the up-to-250-cluster mesh, reducing pressure on each Cilium agent. For security, Microsoft and Isovalent jointly integrated Z tunnel into Cilium. Z tunnel is a CNCF-graduated Rust proxy. The Cilium agent acts as its control plane and redirects namespace-annotated pod traffic through an encrypted mutual TLS tunnel authenticated by Spire.

Cilium MTLS in AKS: No Sidecars, No Certificate Management

▶ Watch (24:01)

The demo showed an AKS cluster with Cilium MTLS enabled. Before labeling a namespace, port 80 traffic appeared in plaintext in tcpdump. After adding a single namespace label, all traffic moved to Z tunnel on port 15008. Port 80 showed nothing. Z tunnel logs confirmed encrypted, mutually authenticated connections between client and server. Spire registered service account identities automatically on enrollment. No sidecars deployed. No certificate work required from developers. No application code changed.

Notable Quotes

the top result uh with two-thirds of the votes was selium and isalent. I think that’s a really good testament to how is really becoming the standard for cloudnative security observability um and networking. Bill Mulligan · ▶ 01:40

really monitor your BPF maps because this will lead to problems and you know make sure that you have this stack you know integrated on your receivability um as well. Marcelo Mello · ▶ 10:43

Security isn’t a feature you guys we bolt in. It is a foundation you build in. Neha Aggarwal · ▶ 20:04

we do not need to have very heavy service mesh running. We do not need to maintain two control planes. We are bringing the foundational security building blocks into the platform CNI which is the Celium CNI Neha Aggarwal · ▶ 27:04

Key Takeaways

  • Cilium holds two-thirds of CNI adoption and nearly 50,000 GitHub stars after ten years.
  • Celonis migrated 160 multi-cloud clusters to Cilium with near-zero downtime using a hybrid-then-exclusive CNI strategy.
  • Cilium MTLS on AKS delivers pod-level encryption via Z tunnel and Spire without sidecars or developer certificate work.

About the Speaker(s)

Bill Mulligan is a cloud native community builder and Cilium maintainer at Isovalent at Cisco. He restarted the Kubernetes Community Day program while at CNCF and writes and speaks broadly on cloud native topics.

Neha Aggarwal leads the Azure Networking team for cloud native workloads at Microsoft, owning AKS CNI integrations including Azure CNI and Cilium, network policies, and network observability. Her team holds SIG chair and maintainer roles in upstream Cilium.

Paul Arah is a security-focused community builder at Isovalent, the company behind Cilium and Tetragon. He speaks at open source conferences and is active across multiple open source communities.

Marcelo Mello is a Senior Platform Engineer at Celonis, where he builds Kubernetes networking infrastructure at scale across a 160-cluster multi-cloud fleet.