Cilium: Two Kernel Developers, One eBPF Bet, and the Dataplane Every Cloud Chose

Started in December 2015 by Linux kernel networking developers Thomas Graf and Daniel Borkmann, Cilium moved Kubernetes networking, security, and observability into the kernel with eBPF — and became the first networking project the CNCF ever graduated.

Sources

Most open-source infrastructure stories are about companies dumping software on a community and hoping it sticks. Cilium is the inversion: two Linux kernel networking developers started writing a container network stack in December 2015, spent four years unpaid building not just the project but the entire eBPF category around it, and only then raised a dollar. By the time Isovalent — the company they founded a year after the first commit — announced its $29M Series A in November 2020, Google had already shipped Cilium as the dataplane of GKE. Microsoft followed for AKS, AWS for EKS Anywhere and EKS Hybrid Nodes, the CNCF graduated it ahead of every other networking project it hosts, and Cisco bought the whole company. Along the way, one CNI quietly absorbed the jobs of kube-proxy, ingress controllers, service-mesh sidecars, network-policy engines, and a runtime-security agent — which is exactly the part buyers should think hardest about.

The Origin: Kernel Insiders With a Userspace Problem

December 2015: a 226-line commit from a kernel networking veteran

The initial commit landed on 2015-12-16, authored by Thomas Graf — at that point one of the best-known Linux kernel networking developers, who had spent years on the Open vSwitch kernel dataplane. The repo was initially named cilium-net ("Initial cilium-net docker plugin", December 18, 2015), was renamed to plain cilium in February 2017 ("Rename cilium-net-daemon service to cilium"), and its first pull request (#1, January 12, 2016) was a lint cleanup — every project's true origin story. The early branch names carry an imprint of the project's pre-Isovalent home: PRs like #56 "from noironetworks/cni-test" reference the noironetworks GitHub organization, a year before Isovalent the company existed. André Martins — today the project's top contributor by commit count — shows up within days.

The founding insight, visible from the first month of commits, was architectural: container networking in 2015 was userspace glue — iptables rules, veth pairs, proxy processes — wrapped around a kernel that had no idea what a container, a label, or an HTTP request was. Graf's co-founder Daniel Borkmann was (and remains, per the kernel's own MAINTAINERS file) a co-maintainer of BPF [CORE] in the mainline kernel alongside Alexei Starovoitov. That detail matters more than any funding round: the people writing Cilium were the same people merging the eBPF features it depended on. When Andreessen Horowitz later wrote its Series A announcement, it was blunt: Thomas was "the original creator of Cilium," and Borkmann "was foundational in turning eBPF into an industry-wide movement."

The bet: identity-aware policy in the kernel, not bolted on top

Cilium's pitch — first shown publicly on Hacker News in August 2016 ("Fast in-kernel networking and security policy enforcement for containers"), then formally at DockerCon 2017 — was that the kernel itself could enforce policy on identities (Kubernetes labels) and protocols (HTTP, gRPC, Kafka) instead of on IP addresses, and that eBPF was the safe, programmable way to get that logic into the datapath without writing kernel modules or forking the kernel:

        2016: the world Cilium entered              2018+: the world Cilium proposed
  ┌────────────────────────────────────┐    ┌────────────────────────────────────┐
  │ userspace                          │    │ userspace                         │
  │  iptables  kube-proxy  sidecars    │    │  cilium-agent (control plane)     │
  │  per-app proxies, flow loggers     │    │  Hubble (flow visibility)          │
  ├────────────────────────────────────┤    ├────────────────────────────────────┤
  │ kernel                             │    │ kernel                             │
  │  dumb L3/L4 forwarding             │    │  eBPF: identity-aware policy,     │
  │  knows IPs, ports — nothing else    │    │  L7 parsing, LB, encryption,      │
  │                                    │    │  socket-level visibility          │
  └────────────────────────────────────┘    └────────────────────────────────────┘

The canonical example is still the identity-aware L7 policy — no CIDR math, no sidecar, one custom resource consumed by the dataplane:

apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy
metadata:
  name: checkout-to-payment
spec:
  endpointSelector:
    matchLabels:
      app: payment
  ingress:
    - fromEndpoints:
        - matchLabels:
            app: checkout
      toPorts:
        - ports:
            - port: "8080"
              protocol: TCP
          rules:
            http:
              - method: "GET"
                path: "/api/v1/charge.*"

In 2016 this was a radical dependency: eBPF was still shaking out, and the kernels that ran it comfortably were far newer than what most enterprises deployed. The project's answer to "will this ever be mainstream?" arrived from an unexpected direction in April 2018, in its own 1.0 announcement: "possibly the strongest signal on the success of BPF has been the decisions of the Linux kernel community to replace the in-kernel implementation of iptables with BPF."

The Timeline: From cilium-net to the Only Graduated Network

Crisis Points & Architectural Pivots

1. The kernel-fork gamble (2015–2018, structural)

Cilium's origin risk was not market competition — it was whether mainline Linux would carry the eBPF features the project needed. Building your network stack on programmable kernel hooks in 2015 meant betting on unreleased kernel work, and the bet only paid off because the bettors controlled the odds: Graf and Borkmann were kernel maintainers, and the kernel community's eventual decision to move iptables handling toward BPF ratified the whole approach. The lesson for platform teams evaluating any kernel-adjacent tool: check who the maintainers are inside the upstream project. Cilium's credibility was BPF [CORE] maintainership, not marketing. The same check applied to a startup without kernel committers would have failed.

2. Four unpaid years, then a hyperscaler validates (2015–2020, financial)

The monetization timeline is the tale's most instructive chart. First commit: December 2015. Public launch: 2017. Priced round: November 2020. In between, the team's output was deliberately ecosystem-shaped rather than product-shaped: ebpf.io (August 2020), the eBPF Foundation (August 2021, with Facebook, Google, Microsoft, and Netflix), the eBPF documentary, CNI benchmarks, O'Reilly books. Then Google shipped Cilium inside GKE's Dataplane V2 — and the Series A closed within three months, led by Andreessen Horowitz and Google itself. The sequencing is the playbook: neutral foundation → hyperscaler adoption → capital. Compare that with projects that raise first and search for a moat later; Cilium's moat was the kernel.

3. Scope creep: one daemon to replace them all (2019–2026, architectural)

Each release absorbed another product category's job. This is the single most decision-relevant fact about adopting Cilium in 2026 — what you are evaluating is no longer a CNI:

FunctionBefore Cilium absorbed itCilium implementationSince
Service load balancingkube-proxy (iptables/IPVS)eBPF kube-proxy replacement + Maglevv1.6 (2019), Maglev v1.9
Ingress / Gateway APIPer-cluster ingress controllersIntegrated Gateway API implementation (ExternalAuth, TCP/UDPRoute)v1.12 (2022), expanded v1.20
Service mesh mTLSSidecar proxies per podSidecar-free eBPF mesh; ZTunnel transparent encryptionv1.11–1.12 (2021–22), ZTunnel v1.19
Network policyiptables plugins, IP/CIDR rulesIdentity-based L3–L7 policy (labels, HTTP/gRPC/Kafka)v1.0 (2018), deny v1.9
EncryptionOverlay/IPsec appliancesIPsec, WireGuard, ZTunnel mTLSv1.4 / v1.10 / v1.19
Runtime securitySeparate agentsTetragon (eBPF enforcement)2022
ObservabilityFlow loggers, packet captureHubble + OpenTelemetry export2019, OTel v1.11
Load balancing (standalone)Hardware/virtual LBsDedicated LB dataplane modev1.10 (2021)
BGP routingMetalLB-class toolsBGP CRDs (v2 API)v1.11, BGPv2 v1.16

The skeptical reading: every absorbed function widens the blast radius. The upgrade guides for v1.19 and v1.20 both open with "you may need to take action" warnings — legacy mutual authentication, Envoy Go extensions, Kafka-aware policies, CiliumNodeConfig, BGP, LoadBalancer IPAM are all upgrade hazards now. A CNI's core promise was being invisible plumbing you never think about; a platform's reality is that every minor upgrade is a change-review meeting. Cilium crossed from the first to the second somewhere around v1.12. Plan operational ownership accordingly.

4. Graduation first, acquisition second (2023, governance)

The Cisco acquisition is the crisis that wasn't, and the reason is sequencing. The graduation PR opened in late 2022, the TOC vote and due diligence completed October 11, 2023, and the acquisition was announced December 21 — the project was under neutral CNCF governance, Apache-2.0, before the acquirer showed up. Cisco bought Isovalent's engineers, its enterprise distribution, and its Tetragon customers (GitHub, G-Research, and Nationwide are named by the founders); it did not buy the project, because the project is not the founders' to sell. Compare the ecosystem's cautionary tale: Terraform stayed under single-company ownership until 2023, changed its license, and forced a community fork. The Cilium sequence — donate, graduate, then exit — is now the template every VC-backed infrastructure startup will be measured against. Whether Isovalent planned it that way or the timing was luck, the result is the same: no BUSF-style crisis is possible here, and that should be priced into the risk analysis of any Cilium-standardized fleet.

Community Engine & Corporate Influence: Who Actually Built It

The commit archaeology is unambiguous about the center of gravity. André Martins (aanm) leads all contributors at ~3,900 commits, with Thomas Graf (tgraf) at ~2,750 and the long tail of maintainers behind them — the top ten accounts for roughly two-thirds of a decade of merged work:

login           commits   role (verified where known)
aanm              3902   André Martins — lead maintainer, Isovalent-era
tgraf             2754   Thomas Graf — creator, Isovalent co-founder/CTO
joestringer       2481   long-time maintainer
tklauser          1950   kernel-side contributor
jrajahalme        1607
pchaigno           1522
julianwiedmann     1492
brb                1288   load-balancing subsystem lead
giorio94           1227
borkmann           1131   Daniel Borkmann — kernel BPF co-maintainer

But the corporate pattern is the healthier half of the story. Isovalent employees built the core, and — per the project's own graduation account — engineers from Google, Microsoft, Datadog and "many more" companies now work on it alongside them. Every major adopter had a structural reason to contribute: Google needed GKE's dataplane hardened, Microsoft needed Azure CNI powered by Cilium to work at AKS scale, and AWS made Cilium the default CNI of EKS Anywhere and the AWS-supported CNI for EKS Hybrid Nodes. When your cloud vendor's managed offering runs the project, the maintenance bill is distributed — the exact opposite of the one-volunteer bus-factor failure that killed Ingress NGINX.

The influence audit still deserves skepticism on two axes. First, the Isovalent-at-Cisco commercial arm now sells an Isovalent Enterprise Platform (hardened Cilium + Tetragon, plus ACI and Nexus integrations), and the project's feature velocity visibly tracks Cisco's multicloud strategy — extensible datapath plugins in v1.20 are a cloud-provider feature, not a community ask. Second, the CNCF's own project page currently scores Cilium's health as Fair (66) with total contributors down 3% year-over-year and contributing organizations down 6% — plateau signals, not decline signals, but worth watching now that the acquisition-era momentum has burned off. Eleven thousand lifetime contributors and 2,600+ contributing organizations mean the project is not fragile; the honest read is that the exponential phase is over and the institutional phase has begun.

Current Trajectory: The Verdict

Final verdict: Cilium is the rare infrastructure tale where every phase of the arc worked: kernel expertise became a project, the project became a category, the category became a hyperscaler-validated standard, the standard was donated to a foundation before its creators sold the company, and the acquirer kept shipping. The two genuine costs are architectural honesty — it stopped being "just a CNI" years ago, and operating it as a platform is the only sane posture — and concentration risk, which the graduation structure mitigates but does not erase. In a decade of cloud-native networking, no other project converted kernel-level control into ecosystem-level leverage this completely. That is either the strongest endorsement or the strongest warning in this series, depending on which side of the upgrade review meeting you sit.

Who should skip it: teams pinned to kernels older than Cilium's minimum, non-Linux worker nodes, or shops that have standardized on another eBPF dataplane and are genuinely satisfied. Everyone else evaluating Kubernetes networking in 2026 should understand this history — because the defaults of every major managed Kubernetes offering were shaped by it.