# Cilium

Cilium is an open-source networking, observability, and security solution for containerized environments, built on an eBPF-based dataplane.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Cilium 1.20: Gateway API ExternalAuth, TCPRoute/UDPRoute, ENI IPAM for IPv6, and more

DevFeed: [Cilium 1.20: Gateway API ExternalAuth, TCPRoute/UDPRoute, ENI IPAM for IPv6, and more](<https://devfeed.tech/articles/cilium-1-20-gateway-api-externalauth-tcproute-udproute-eni-ipam-for-ipv6-and-more-17374.md>)

Original publisher: [Read original article](<https://www.cncf.io/blog/2026/09/14/cilium-1-20-gateway-api-externalauth-tcproute-udproute-eni-ipam-for-ipv6-and-more/>)

Author: Nico Vibert and Donia Chaiehloudj, Cilium

Published: 2026-09-14T10:45:49Z

Content type: article

Language: en

Sources: [Cloud Native Computing Foundation](<https://devfeed.tech/sources/cloud-native-computing-foundation.md>)

Topics: [Cilium](<https://devfeed.tech/topics/cilium.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [API](<https://devfeed.tech/topics/api.md>), [networking](<https://devfeed.tech/topics/networking.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [eBPF](<https://devfeed.tech/topics/ebpf.md>), [VPC](<https://devfeed.tech/topics/vpc.md>), [nginx](<https://devfeed.tech/topics/nginx.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [aws](<https://devfeed.tech/tags/aws.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cni](<https://devfeed.tech/tags/cni.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [google](<https://devfeed.tech/tags/google.md>), [ingress-nginx](<https://devfeed.tech/tags/ingress-nginx.md>), [ipv4](<https://devfeed.tech/tags/ipv4.md>), [ipv6](<https://devfeed.tech/tags/ipv6.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [network](<https://devfeed.tech/tags/network.md>), [networking](<https://devfeed.tech/tags/networking.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [release](<https://devfeed.tech/tags/release.md>)

### AI overview

Cilium 1.20 expands Gateway API support with ExternalAuth, CORS filters, ListenerSets, TCPRoute, and UDPRoute. The release also introduces extensible datapath plugins, advances networking standardization with Kubernetes, and adds beta IPv6 support for AWS ENI IPAM.

### Source excerpt

Cilium 1.20, the second major open source Cilium release of 2026 after Cilium 1.19, is finally here. Three themes stand out in this release: Thank you to every contributor, reviewer and maintainer who made Cilium 1.20...

## What Is Cilium?

DevFeed: [What Is Cilium?](<https://devfeed.tech/articles/what-is-cilium-31342.md>)

Original publisher: [Read original article](<https://isovalent.com/blog/post/what-is-cilium/>)

Author: Christian Hernandez

Published: 2026-07-23T07:01:00Z

Content type: tutorial

Language: en

Sources: [Isovalent - The latest articles covering eBPF-based Networking, Observability, and Security](<https://devfeed.tech/sources/isovalent-the-latest-articles-covering-ebpf-based-networking-observability-and-security.md>)

Topics: [Cilium](<https://devfeed.tech/topics/cilium.md>), [eBPF](<https://devfeed.tech/topics/ebpf.md>), [Kubernetes networking](<https://devfeed.tech/topics/kubernetes-networking.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [cilium](<https://devfeed.tech/tags/cilium.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-networking](<https://devfeed.tech/tags/kubernetes-networking.md>), [observability](<https://devfeed.tech/tags/observability.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

An introductory article explains Cilium and describes how it uses eBPF for Kubernetes networking, security, and observability in cloud-native infrastructure.

### Source excerpt

Learn what Cilium is, how it uses eBPF to power Kubernetes networking, security, and observability, and why organizations choose it for modern cloud-native infrastructure.

## Inside Cilium CNI: solving mysterious Kubernetes pod setup timeouts

DevFeed: [Inside Cilium CNI: solving mysterious Kubernetes pod setup timeouts](<https://devfeed.tech/articles/inside-cilium-cni-solving-mysterious-kubernetes-pod-setup-timeouts-26260.md>)

Original publisher: [Read original article](<https://medium.com/adyen/inside-cilium-cni-solving-mysterious-kubernetes-pod-setup-timeouts-8529dacd5e81?source=rss----64941d9fbc09---4>)

Author: Adyen

Published: 2026-07-13T09:17:40Z

Content type: article

Language: en

Sources: [Adyen Tech](<https://devfeed.tech/sources/adyen-tech.md>)

Topics: [Cilium](<https://devfeed.tech/topics/cilium.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Kubernetes networking](<https://devfeed.tech/topics/kubernetes-networking.md>), [networking](<https://devfeed.tech/topics/networking.md>), [eBPF](<https://devfeed.tech/topics/ebpf.md>), [Latency](<https://devfeed.tech/topics/latency.md>), [hdfs](<https://devfeed.tech/topics/hdfs.md>), [Apache Spark](<https://devfeed.tech/topics/spark.md>), [big-data](<https://devfeed.tech/topics/big-data.md>), [cpu](<https://devfeed.tech/topics/cpu.md>)

Tags: [big-data](<https://devfeed.tech/tags/big-data.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [cni](<https://devfeed.tech/tags/cni.md>), [cpu](<https://devfeed.tech/tags/cpu.md>), [data](<https://devfeed.tech/tags/data.md>), [devops](<https://devfeed.tech/tags/devops.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [hdfs](<https://devfeed.tech/tags/hdfs.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-networking](<https://devfeed.tech/tags/kubernetes-networking.md>), [latency](<https://devfeed.tech/tags/latency.md>), [spark](<https://devfeed.tech/tags/spark.md>), [speed](<https://devfeed.tech/tags/speed.md>), [tracing](<https://devfeed.tech/tags/tracing.md>)

### AI overview

An Adyen engineer investigates Cilium CNI timeouts that prevented new Kubernetes pods from starting. The article attributes the issue to sequential connection-tracking-table garbage collection, which became a bottleneck under workloads involving HDFS, Trino, and short-lived Spark jobs.

### Source excerpt

By Jorrick Sleijster - Senior Data Platform Engineer, Adyen I was fully aware a year ago that a single configuration line could break the Kubernetes networking stack. But if they told me that leftovers from Kubernetes pods which terminated hours prior could block new ones from starting, I would have thought they were joking. In high-performance networking, 35 seconds is a lifetime. This was the latency required to iterate through our connection tracking table of 7 million entries at a maximum speed of 200,000 entries per second. At our 16-million-entry peak, this sequential lookup could take up to 80 seconds, leading to Cilium CNI timeouts preventing new pods from starting on affected nodes. We uncovered this linear-time behavior at Adyen by tracing syscalls, inspecting codebases, and analyzing eBPF internals. This investigation revealed how our varied workloads turned the connection tracking table's garbage collection algorithm into a critical bottleneck. Our setup: why we're different At Adyen, we run Cilium CNI across all our 100+ Kubernetes clusters. When we switched from Calico to Cilium, we knew we'd face challenges adapting it to our production workloads. Our production big data Kubernetes clusters have a unique usage pattern compared to the other Kubernetes environments within Adyen: Data extraction from HDFS. Our infrastructure relies on more than 500 datanodes. Trino represents one of our most demanding HDFS workloads, processing analytical queries against data stored on HDFS. Due to the distributed nature of HDFS, each file you download requires a new connection to any of these 500 nodes. Therefore, during peak hours, a single pod can produce approximately 50,000 connections every minute. Pod churn. Many pods we spawn on the Kubernetes cluster run batch jobs, such as Spark jobs. They stay around for anywhere from a second to a couple of hours. Wide variety of workloads. Some workloads are very CPU-intensive, like Spark pods executing complex joins and tra

## What Is Multi-Cloud?

DevFeed: [What Is Multi-Cloud?](<https://devfeed.tech/articles/what-is-multi-cloud-31343.md>)

Original publisher: [Read original article](<https://isovalent.com/blog/post/what-is-multi-cloud/>)

Author: Ryan Kollist

Published: 2026-06-23T16:45:27Z

Content type: tutorial

Language: en

Sources: [Isovalent - The latest articles covering eBPF-based Networking, Observability, and Security](<https://devfeed.tech/sources/isovalent-the-latest-articles-covering-ebpf-based-networking-observability-and-security.md>)

Topics: [Cloud Architecture](<https://devfeed.tech/topics/cloud-architecture.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Cilium](<https://devfeed.tech/topics/cilium.md>), [networking](<https://devfeed.tech/topics/networking.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-architecture](<https://devfeed.tech/tags/cloud-architecture.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [multi-cloud](<https://devfeed.tech/tags/multi-cloud.md>), [networking](<https://devfeed.tech/tags/networking.md>), [security](<https://devfeed.tech/tags/security.md>), [what-is-multicloud](<https://devfeed.tech/tags/what-is-multicloud.md>), [what-is-multicloud-architecture](<https://devfeed.tech/tags/what-is-multicloud-architecture.md>), [what-is-multicloud-networking](<https://devfeed.tech/tags/what-is-multicloud-networking.md>), [what-is-multicloud-security](<https://devfeed.tech/tags/what-is-multicloud-security.md>), [what-is-the-difference-between-multicloud-and-hybrid-cloud](<https://devfeed.tech/tags/what-is-the-difference-between-multicloud-and-hybrid-cloud.md>)

### AI overview

This article explains multi-cloud architecture, its importance, and how Isovalent Cilium supports a consistent networking and security operational model across different cloud infrastructures.

### Source excerpt

Learn what makes a multi-cloud architecture, why it's important and how Isovalent Cilium enables a consistent networking and security operational model across any cloud infrastructure.

## Six Live Kubernetes Recommendations: AKS, Cilium, Rate Limiting, and More

DevFeed: [Six Live Kubernetes Recommendations: AKS, Cilium, Rate Limiting, and More](<https://devfeed.tech/articles/six-live-kubernetes-recommendations-aks-cilium-rate-limiting-and-more-19004.md>)

Original publisher: [Read original article](<https://www.pulumi.com/blog/getting-started-aks-pulumi-csharp/>)

Author: Adam Gordon Bell

Published: 2026-06-15T12:00:00Z

Content type: tutorial

Language: en

Sources: [Pulumi](<https://devfeed.tech/sources/pulumi.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Azure](<https://devfeed.tech/topics/azure.md>), [C#](<https://devfeed.tech/topics/csharp.md>), [Cilium](<https://devfeed.tech/topics/cilium.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [Web app](<https://devfeed.tech/topics/webapp.md>)

Tags: [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [aks](<https://devfeed.tech/tags/aks.md>), [azure](<https://devfeed.tech/tags/azure.md>), [c-sharp](<https://devfeed.tech/tags/c-sharp.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [container-registry](<https://devfeed.tech/tags/container-registry.md>), [dotnet](<https://devfeed.tech/tags/dotnet.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [tutorials](<https://devfeed.tech/tags/tutorials.md>), [web-app](<https://devfeed.tech/tags/web-app.md>)

### AI overview

A writeup of a live workshop on building an AKS cluster, Azure Container Registry, and a random-cat web app in C# with Pulumi. It presents recommendations for working with Kubernetes on Azure, including choosing a language the team already uses, and describes how Docker Hub rate limiting affected the workshop.

### Source excerpt

On June 10th, Engin and I ran a live workshop building an AKS cluster, an Azure Container Registry, and a random-cat web app from scratch in C#. This is the writeup, including the parts we didn't get to live. Since this post was published, Pulumi has added first-class support for HashiCorp Configuration Language (HCL). You can now write Pulumi programs in HCL directly, alongside general-purpose languages like TypeScript, Python, Go, and C#. To see how it works, see Pulumi HCL. Live demos keep you honest. On June 10th my AKS workshop went a little sideways. Partway through, Docker Hub rate-limited my image pull and we had to adapt the content on the fly. The original plan was to stand up an AKS cluster with Cilium, an Azure Container Registry with the cluster's pull permission wired in code, and a random-cat web app, then split the infrastructure from the workload into separate Pulumi stacks. Live, we didn't make it through all of that, but we had some fun tangents and it turned out to be a great session. So here are my six recommendations for working with Kubernetes on Azure from this recent workshop. 1. Pick the language your team already uses I opened the session by asking the room what language they prefer to work in, with one caveat from me: "Hopefully, it's not PowerShell because this is not in PowerShell." We got some C# answers and zero requests for PowerShell, which works out, because the whole workshop is in PowerShell C#. I chose C# because, first, I genuinely love the language. I spent the early part of my career as a C# developer, and on Azure it just makes sense. Second, an Azure workshop tends to draw a big turnout of C# devs, and if they aren't C# devs themselves, they often work somewhere the backend team uses C#. Pulumi lets you bring that language to your infrastructure rather than learn a new DSL. AI coding assistants also came up. LLMs have substantially more C# and Go in their training data than HCL or Bicep. As I put it live: "If you're working

## OpenAI Uses Isovalent for a Common Networking for AI Infrastructure

DevFeed: [OpenAI Uses Isovalent for a Common Networking for AI Infrastructure](<https://devfeed.tech/articles/openai-uses-isovalent-for-a-common-networking-for-ai-infrastructure-31334.md>)

Original publisher: [Read original article](<https://isovalent.com/blog/post/openai-isovalent-networking-kubernetes-case-study/>)

Author: Dean Lewis

Published: 2026-06-03T10:42:00Z

Content type: article

Language: en

Sources: [Isovalent - The latest articles covering eBPF-based Networking, Observability, and Security](<https://devfeed.tech/sources/isovalent-the-latest-articles-covering-ebpf-based-networking-observability-and-security.md>)

Topics: [Cilium](<https://devfeed.tech/topics/cilium.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [AI Infrastructure](<https://devfeed.tech/topics/ai-infrastructure.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [networking](<https://devfeed.tech/topics/networking.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [hubble](<https://devfeed.tech/tags/hubble.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [isovalent](<https://devfeed.tech/tags/isovalent.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-networking](<https://devfeed.tech/tags/kubernetes-networking.md>), [load-balancer](<https://devfeed.tech/tags/load-balancer.md>), [mesh-networking](<https://devfeed.tech/tags/mesh-networking.md>), [networking](<https://devfeed.tech/tags/networking.md>), [openai](<https://devfeed.tech/tags/openai.md>), [policy](<https://devfeed.tech/tags/policy.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [tetragon](<https://devfeed.tech/tags/tetragon.md>), [troubleshooting](<https://devfeed.tech/tags/troubleshooting.md>), [uses](<https://devfeed.tech/tags/uses.md>), [website](<https://devfeed.tech/tags/website.md>)

### AI overview

The article reports that OpenAI uses Isovalent Networking for Kubernetes, built on Cilium, to provide consistent networking, policy, and troubleshooting across its AI infrastructure.

### Source excerpt

OpenAI uses Isovalent Networking for Kubernetes, built on Cilium, for consistent networking, policy, and troubleshooting across AI infrastructure.

## From Tickets to Pull Requests: Running Cilium in a GitOps Platform

DevFeed: [From Tickets to Pull Requests: Running Cilium in a GitOps Platform](<https://devfeed.tech/articles/from-tickets-to-pull-requests-running-cilium-in-a-gitops-platform-31328.md>)

Original publisher: [Read original article](<https://isovalent.com/blog/post/cilium-gitops-platform-engineering/>)

Author: Dean Lewis

Published: 2026-06-02T12:56:19Z

Content type: tutorial

Language: en

Sources: [Isovalent - The latest articles covering eBPF-based Networking, Observability, and Security](<https://devfeed.tech/sources/isovalent-the-latest-articles-covering-ebpf-based-networking-observability-and-security.md>)

Topics: [Cilium](<https://devfeed.tech/topics/cilium.md>), [GitOps](<https://devfeed.tech/topics/gitops.md>), [argo-cd](<https://devfeed.tech/topics/argo-cd.md>), [Kyverno](<https://devfeed.tech/topics/kyverno.md>), [ci](<https://devfeed.tech/topics/ci.md>)

Tags: [argo](<https://devfeed.tech/tags/argo.md>), [argo-cd](<https://devfeed.tech/tags/argo-cd.md>), [ci](<https://devfeed.tech/tags/ci.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [gitops](<https://devfeed.tech/tags/gitops.md>), [hubble-timescape](<https://devfeed.tech/tags/hubble-timescape.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [network-policy](<https://devfeed.tech/tags/network-policy.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>)

### AI overview

The article describes running Cilium as part of a GitOps platform using Argo CD, Kyverno, and isopolicy CI.

### Source excerpt

Run Cilium as a GitOps platform: use Argo CD, Kyverno, and isopolicy CI.

## Buzzing Beyond Clouds: The Illustrated Children's Guide to Cilium

DevFeed: [Buzzing Beyond Clouds: The Illustrated Children's Guide to Cilium](<https://devfeed.tech/articles/buzzing-beyond-clouds-the-illustrated-children-s-guide-to-cilium-31326.md>)

Original publisher: [Read original article](<https://isovalent.com/blog/post/children-guide-cilium/>)

Author: Bill Mulligan, Katie Meinders

Published: 2026-05-19T10:23:39Z

Content type: release

Language: en

Sources: [Isovalent - The latest articles covering eBPF-based Networking, Observability, and Security](<https://devfeed.tech/sources/isovalent-the-latest-articles-covering-ebpf-based-networking-observability-and-security.md>)

Topics: [Cilium](<https://devfeed.tech/topics/cilium.md>)

Tags: [book](<https://devfeed.tech/tags/book.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [hubble](<https://devfeed.tech/tags/hubble.md>), [isovalent](<https://devfeed.tech/tags/isovalent.md>), [kubernetes-networking](<https://devfeed.tech/tags/kubernetes-networking.md>), [load-balancer](<https://devfeed.tech/tags/load-balancer.md>), [mesh-networking](<https://devfeed.tech/tags/mesh-networking.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [tetragon](<https://devfeed.tech/tags/tetragon.md>), [website](<https://devfeed.tech/tags/website.md>)

### AI overview

Buzzing Beyond Clouds is an illustrated children's guide to Cilium. The book is presented as a follow-up to an illustrated guide to eBPF and is intended for readers with varying levels of technical expertise.

### Source excerpt

Buzzing Beyond Clouds: The Illustrated Children's Guide to Cilium, and follow up to Buzzing Across Space: The Illustrated Children's Guide to eBPF, is now available. This second illustrated book brings the Cilium story to life in a way that can be digested by readers of all ages and levels of technical expertise.

## Why Prometheus couldn't see Cilium metrics at 2 a.m.

DevFeed: [Why Prometheus couldn't see Cilium metrics at 2 a.m.](<https://devfeed.tech/articles/why-prometheus-couldn-t-see-cilium-metrics-at-2-a-m-17617.md>)

Original publisher: [Read original article](<https://thenewstack.io/cncf-projects-integration-production/>)

Author: Rishi Mondal

Published: 2026-05-10T14:00:00Z

Content type: article

Language: en

Sources: [Kubernetes Overview, News and Trends | The New Stack](<https://devfeed.tech/sources/kubernetes-overview-news-and-trends-the-new-stack.md>)

Topics: [Prometheus](<https://devfeed.tech/topics/prometheus.md>), [Cilium](<https://devfeed.tech/topics/cilium.md>), [Grafana](<https://devfeed.tech/topics/grafana.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>)

Tags: [cilium](<https://devfeed.tech/tags/cilium.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [grafana](<https://devfeed.tech/tags/grafana.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [network](<https://devfeed.tech/tags/network.md>), [networking](<https://devfeed.tech/tags/networking.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [post-contributed](<https://devfeed.tech/tags/post-contributed.md>), [prometheus](<https://devfeed.tech/tags/prometheus.md>), [sponsor-cncf](<https://devfeed.tech/tags/sponsor-cncf.md>), [sponsored-post-contributed](<https://devfeed.tech/tags/sponsored-post-contributed.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

This article examines the integration tax that platform teams encounter when combining CNCF projects in production. It uses Prometheus and Cilium metrics as an example, and discusses integration failures involving Hubble, Grafana, cert-manager, ingress controllers, and cloud DNS configuration.

### Source excerpt

I still remember the first time we lost sleep over something that wasn't a bug. It was a Tuesday. Grafana The post Why Prometheus couldn't see Cilium metrics at 2 a.m. appeared first on The New Stack.

## Five Things to Know About Cilium Network Policies

DevFeed: [Five Things to Know About Cilium Network Policies](<https://devfeed.tech/articles/5-things-you-didn-t-know-about-cilium-network-polices-31324.md>)

Original publisher: [Read original article](<https://isovalent.com/blog/post/5-things-you-didnt-know-about-cilium-network-polices/>)

Author: Christian Hernandez

Published: 2026-04-27T21:23:02Z

Content type: article

Language: en

Sources: [Isovalent - The latest articles covering eBPF-based Networking, Observability, and Security](<https://devfeed.tech/sources/isovalent-the-latest-articles-covering-ebpf-based-networking-observability-and-security.md>)

Topics: [Cilium](<https://devfeed.tech/topics/cilium.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [cilium](<https://devfeed.tech/tags/cilium.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [networkpolicies](<https://devfeed.tech/tags/networkpolicies.md>)

### AI overview

This blog introduces five points about Cilium Network Policies and contrasts them with standard Kubernetes NetworkPolicies, which it says can appear similar at first glance.

### Source excerpt

Not all CNIs are created equal, and many assume that CiliumNetworkPolicies are the same as standard Kubernetes NetworkPolicies. At first glance, they can look similar. In this blog, we'll go over the top 5 things you may not know about Cilium Network Policies.

## Leveling Up Kubernetes: Key DigitalOcean Managed Kubernetes Releases in 2025

DevFeed: [Leveling Up Kubernetes: Key DigitalOcean Managed Kubernetes Releases in 2025](<https://devfeed.tech/articles/leveling-up-kubernetes-key-digitalocean-managed-kubernetes-releases-in-2025-19899.md>)

Original publisher: [Read original article](<https://www.digitalocean.com/blog/kubernetes-updates-h2>)

Author: Nicole Ghalwash

Published: 2025-12-15T18:30:03Z

Content type: article

Language: en

Sources: [DigitalOcean](<https://devfeed.tech/sources/digitalocean.md>)

Topics: [Digital Ocean](<https://devfeed.tech/topics/digital-ocean.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [releases](<https://devfeed.tech/topics/releases.md>), [networking](<https://devfeed.tech/topics/networking.md>), [Cilium](<https://devfeed.tech/topics/cilium.md>), [eBPF](<https://devfeed.tech/topics/ebpf.md>), [VPC](<https://devfeed.tech/topics/vpc.md>), [Latency](<https://devfeed.tech/topics/latency.md>), [autoscaling](<https://devfeed.tech/topics/autoscaling.md>), [observability](<https://devfeed.tech/topics/observability.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [autoscaling](<https://devfeed.tech/tags/autoscaling.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [digitalocean](<https://devfeed.tech/tags/digitalocean.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [improvements](<https://devfeed.tech/tags/improvements.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [latency](<https://devfeed.tech/tags/latency.md>), [networking](<https://devfeed.tech/tags/networking.md>), [observability](<https://devfeed.tech/tags/observability.md>), [performance](<https://devfeed.tech/tags/performance.md>), [releases](<https://devfeed.tech/tags/releases.md>), [scalability](<https://devfeed.tech/tags/scalability.md>), [updates](<https://devfeed.tech/tags/updates.md>), [vpc](<https://devfeed.tech/tags/vpc.md>)

### AI overview

A recap of DigitalOcean Managed Kubernetes releases in 2025, covering cluster-capacity increases, VPC-native networking, eBPF-powered routing, Managed Cilium with Hubble, and related security, autoscaling, and ecosystem improvements. The updates aim to simplify Kubernetes operations and support larger, more efficient workloads.

### Source excerpt

2025 was a busy and transformative year for DigitalOcean Managed Kubernetes, marked by a series of releases that make DigitalOcean Kubernetes simpler, more secure, and more scalable for developers and growing businesses. Across engine upgrades, networking and security enhancements, autoscaling improvements, and new ecosystem integrations, this year's updates aimed to give teams more power with less operational overhead. Whether users are running production workloads, experimenting with microservices, or scaling customer-facing applications, the enhancements launched throughout 2025 make it easier than ever to deploy, manage, and optimize Kubernetes on DigitalOcean. In this recap, we'll walk through the major releases that shaped the platform over the past year and how they help developers move faster with confidence. Next Evolution of DigitalOcean Kubernetes [March] In March, we rolled out four major upgrades to DigitalOcean Kubernetes (DOKS) that make it easier to run larger and more efficient workloads: increased cluster capacity, VPC-native networking, eBPF-powered routing, and Managed Cilium. Here's a look at each one: Cluster capacity has doubled from 500 to 1,000 worker nodes, allowing bigger applications to run on a single cluster without the overhead of managing multiple environments. VPC-native Kubernetes now assigns IPs directly from your VPC, improving performance and simplifying communication with other cloud resources. Replacing kube-proxy with eBPF-based networking and routing delivers faster packet processing and lower latency, benefiting high-traffic and real-time workloads. Managed Cilium with Hubble for observability adds stronger security, modern networking, and easier troubleshooting. Together, these features significantly boost scalability, performance, and reliability while reducing operational complexity of DOKS, so developers gain clearer visibility and a simpler networking stack, while businesses benefit from lower overhead and the ability t

## Kubernetes Networking with Multus

DevFeed: [Kubernetes Networking with Multus](<https://devfeed.tech/articles/advanced-kubernetes-networking-with-multus-it-s-easier-than-you-think-10507.md>)

Original publisher: [Read original article](<https://technotim.com/posts/advanced-kubernetes-networking/>)

Author: Techno Tim

Published: 2024-04-14T13:00:00Z

Content type: tutorial

Language: en

Sources: [Techno Tim](<https://devfeed.tech/sources/techno-tim.md>)

Topics: [Kubernetes networking](<https://devfeed.tech/topics/kubernetes-networking.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [networking](<https://devfeed.tech/topics/networking.md>), [Cilium](<https://devfeed.tech/topics/cilium.md>), [k3s](<https://devfeed.tech/topics/k3s.md>)

Tags: [cilium](<https://devfeed.tech/tags/cilium.md>), [homelab](<https://devfeed.tech/tags/homelab.md>), [k3s](<https://devfeed.tech/tags/k3s.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-networking](<https://devfeed.tech/tags/kubernetes-networking.md>), [networking](<https://devfeed.tech/tags/networking.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

A video tutorial covering Kubernetes networking, from CNIs to configuring Multus for traditional networking needs. It includes installation guidance and connectivity and DNS testing steps, with notes for RKE2 and Cilium users.

### Source excerpt

I just discovered Multus and it fixed Kubernetes networking! In this video we cover a lot of Kubernetes networking topics from beginner topics like CNIs, to advanced topics like adding Multus for more traditional networking within Kubernetes - which fixes a lot of problems you see with Kubernetes networking. Also, I had to turn the nerd up to 11 on this one. 📺 Watch Video Be sure to ch...

## Securing cloud native's most important use cases

DevFeed: [Securing cloud native's most important use cases](<https://devfeed.tech/articles/securing-cloud-native-s-most-important-use-cases-13221.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/securing-cloud-natives-most-important-use-cases>)

Published: 2023-12-19T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Cilium](<https://devfeed.tech/topics/cilium.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [istio](<https://devfeed.tech/tags/istio.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This article explains Chainguard's focus on securing cloud-native software supply chains while preserving developer experience. It introduces Chainguard Images bundles for Cilium and Istio, describing their use in Kubernetes environments and build pipelines.

### Source excerpt

Chainguard Images now supports Cilium and Istio. See how to integrate our container images into your environments.

## Linux Observability with BPF

DevFeed: [Linux Observability with BPF](<https://devfeed.tech/articles/linux-observability-with-bpf-35178.md>)

Original publisher: [Read original article](<https://blog.jessfraz.com/post/linux-observability-with-bpf/>)

Published: 2019-07-10T15:25:24Z

Content type: opinion

Language: en

Sources: [Jessie Frazelle](<https://devfeed.tech/sources/jessie-frazelle.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Cilium](<https://devfeed.tech/topics/cilium.md>), [networking](<https://devfeed.tech/topics/networking.md>)

Tags: [bug](<https://devfeed.tech/tags/bug.md>), [centos](<https://devfeed.tech/tags/centos.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [docker](<https://devfeed.tech/tags/docker.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [networking](<https://devfeed.tech/tags/networking.md>), [observability](<https://devfeed.tech/tags/observability.md>)

### AI overview

A foreword for the book Linux Observability with BPF explains the author's interest in BPF and XDP, including their use for Linux kernel tracing, container networking, and replacing some iptables-based functionality. It also discusses Docker's iptables-related challenges and mentions Cilium, Cloudflare, and Facebook use cases.

### Source excerpt

Below is the foreward for the new book on Linux Observability with BPF by two of my favorite programmers, David Calavera and Lorenzo Fontana! I was pretty stoked about getting to write the foreward, I asked O'Reilly if I could publish it on my blog as well and they said yes. I hope you all check out this book and share what you've built after! As a programmer (and a self confessed dweeb) I like to stay up to date on the latest additions to various kernels and research in computing. When I first played around with Berkeley Packet Filters (BPF) and Express Data Path (XDP) in Linux I was in love. This is such a NICE THING and I am glad this book is putting BPF and XDP on the center stage so more people can start using it in their projects. Let me go into detail about my background and why I fell in love with these kernel interfaces... I worked as a Docker core maintainer, along with David (one of the brilliant authors of this book). Docker, if you are not familiar, shells out to iptables for a lot of the filtering and routing logic for containers. The first patch I ever made to Docker was fixing a problem where a version of iptables on CentOS didn't have the same command-line flags so writing to iptables was failing. There were a lot of weird issues like this and anyone who has ever shelled out to a tool in their software can likely commiserate. Not only that, having thousands of rules on a host is not what iptables was built for and has performance side effects because of it. Then I heard about BPF and XDP. This was like music to my ears. No longer would my scars from iptables bleed with another bug! The kernel community is even working on replacing iptables with BPF! Halleluyah! Cilium, container networking, is using BPF and XDP for the internals of their project as well. But that's not all! BPF can do so much more than just fulfilling the iptables use case. With BPF, you can trace any syscall or kernel function as well as any user-space program. bpftrace gives users d