Cilium
An eBPF-based networking, security and observability layer for cloud native and Kubernetes environments, covering container networking, policies and load balancing.
- GitHub stars
- 26k
- Last commit
- today
- Latest release
- v1.20.2
- Licence
- Apache-2.0
- Self-hosted
- Yes

Cilium is a cloud native project that uses eBPF, a technology that runs sandboxed programs inside the Linux kernel, to provide networking, security and observability for containerized workloads. It is most often deployed in Kubernetes clusters as the container network interface, replacing traditional iptables-based approaches.
Its topics show the breadth of the project: Kubernetes networking and CNI, load balancing, XDP, security, kernel-level monitoring and troubleshooting. Because policies and visibility are implemented in the kernel, it can enforce network rules and observe traffic between services with relatively low overhead. The project website describes it simply as cloud native, eBPF-based networking, observability and security.
Cilium is written in Go and Apache-2.0 licensed, and it runs on your own clusters rather than as a hosted service, though several cloud providers integrate it into managed Kubernetes. It suits platform and security teams that operate Kubernetes at scale and need fine-grained network policy plus insight into service-to-service traffic.
Key features
- eBPF-powered Kubernetes networking
- Network security policies
- Kernel-level load balancing
- Traffic observability and troubleshooting
- XDP acceleration support
- Container network interface plugin
Pricing: Free and open source under the Apache-2.0 license.