Cilium: Two Kernel Developers, One eBPF Bet, and the Dataplane Every Cloud Chose
Started in December 2015 by Linux kernel networking developers Thomas Graf and Daniel Borkmann, Cilium moved Kubernetes networking, security, and observability into the kernel with eBPF — and became the first networking project the CNCF ever graduated.
Sources
- cilium/cilium repository (Apache-2.0, 25.5k stars)
- Initial commit 7fa3c60eb7 — Thomas Graf (2015-12-16)
- Cilium 1.0: Bringing the BPF Revolution to Kubernetes (2018-04-24)
- a16z: Investing in Isovalent — Martin Casado (2020-11-10)
- TechCrunch: Isovalent launches with $29M Series A (2020-11-10)
- Isovalent $40M Series B announcement (2022-09-07)
- Cisco blog: Cisco announces intent to acquire Isovalent — Tom Gillis (2023-12-21)
- Isovalent: Cisco acquires Isovalent
- CNCF project page — Cilium (incubating 2021-10-13, graduated 2023-10-11)
- CNCF announcement: Cilium graduation (2023-10-11)
- Cilium graduates CNCF — Liz Rice, Isovalent (2023-10-11)
- CNCF TOC PR #952 — Cilium graduation proposal by Thomas Graf
- Google Cloud: Cilium and eBPF are the new networking dataplane for GKE (2020-08)
- Tetragon announcement — eBPF-based security observability and runtime enforcement (2022-05-16)
- eBPF Foundation launch under the Linux Foundation (2021-08)
- Cilium 1.19.0 release notes (ZTunnel transparent encryption, multi-pool IPAM stable)
- Cilium 1.20.0 release notes (Gateway API v1.6.1, extensible datapath)
- AWS EKS user guide — Cilium is the AWS-supported CNI for EKS Hybrid Nodes
- Microsoft Learn — Azure CNI powered by Cilium (AKS)
- cilium/cilium USERS.md — 100+ adopting organizations
- Linux kernel MAINTAINERS — BPF core: Starovoitov & Borkmann
- HN 2016 thread: Cilium — Fast in-kernel networking and security policy enforcement
Most open-source infrastructure stories are about companies dumping software on a community and hoping it sticks. Cilium is the inversion: two Linux kernel networking developers started writing a container network stack in December 2015, spent four years unpaid building not just the project but the entire eBPF category around it, and only then raised a dollar. By the time Isovalent — the company they founded a year after the first commit — announced its $29M Series A in November 2020, Google had already shipped Cilium as the dataplane of GKE. Microsoft followed for AKS, AWS for EKS Anywhere and EKS Hybrid Nodes, the CNCF graduated it ahead of every other networking project it hosts, and Cisco bought the whole company. Along the way, one CNI quietly absorbed the jobs of kube-proxy, ingress controllers, service-mesh sidecars, network-policy engines, and a runtime-security agent — which is exactly the part buyers should think hardest about.
The Origin: Kernel Insiders With a Userspace Problem
December 2015: a 226-line commit from a kernel networking veteran
The initial
commit landed on 2015-12-16, authored by
Thomas Graf — at that point one of the best-known Linux kernel networking
developers, who had spent years on the Open vSwitch kernel dataplane. The repo was initially named
cilium-net ("Initial cilium-net docker plugin", December 18, 2015), was
renamed to plain cilium in February 2017 ("Rename cilium-net-daemon
service to cilium"), and its first pull request
(#1, January 12, 2016)
was a lint cleanup — every project's true origin story. The early branch names carry an imprint of the
project's pre-Isovalent home: PRs like #56 "from noironetworks/cni-test" reference the
noironetworks GitHub organization, a year before
Isovalent the company
existed. André Martins — today the project's top contributor by commit count — shows up within days.
The founding insight, visible from the first month of commits, was architectural: container networking in 2015 was userspace glue — iptables rules, veth pairs, proxy processes — wrapped around a kernel that had no idea what a container, a label, or an HTTP request was. Graf's co-founder Daniel Borkmann was (and remains, per the kernel's own MAINTAINERS file) a co-maintainer of BPF [CORE] in the mainline kernel alongside Alexei Starovoitov. That detail matters more than any funding round: the people writing Cilium were the same people merging the eBPF features it depended on. When Andreessen Horowitz later wrote its Series A announcement, it was blunt: Thomas was "the original creator of Cilium," and Borkmann "was foundational in turning eBPF into an industry-wide movement."
The bet: identity-aware policy in the kernel, not bolted on top
Cilium's pitch — first shown publicly on Hacker News in August 2016 ("Fast in-kernel networking and security policy enforcement for containers"), then formally at DockerCon 2017 — was that the kernel itself could enforce policy on identities (Kubernetes labels) and protocols (HTTP, gRPC, Kafka) instead of on IP addresses, and that eBPF was the safe, programmable way to get that logic into the datapath without writing kernel modules or forking the kernel:
2016: the world Cilium entered 2018+: the world Cilium proposed
┌────────────────────────────────────┐ ┌────────────────────────────────────┐
│ userspace │ │ userspace │
│ iptables kube-proxy sidecars │ │ cilium-agent (control plane) │
│ per-app proxies, flow loggers │ │ Hubble (flow visibility) │
├────────────────────────────────────┤ ├────────────────────────────────────┤
│ kernel │ │ kernel │
│ dumb L3/L4 forwarding │ │ eBPF: identity-aware policy, │
│ knows IPs, ports — nothing else │ │ L7 parsing, LB, encryption, │
│ │ │ socket-level visibility │
└────────────────────────────────────┘ └────────────────────────────────────┘
The canonical example is still the identity-aware L7 policy — no CIDR math, no sidecar, one custom resource consumed by the dataplane:
apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy
metadata:
name: checkout-to-payment
spec:
endpointSelector:
matchLabels:
app: payment
ingress:
- fromEndpoints:
- matchLabels:
app: checkout
toPorts:
- ports:
- port: "8080"
protocol: TCP
rules:
http:
- method: "GET"
path: "/api/v1/charge.*"
In 2016 this was a radical dependency: eBPF was still shaking out, and the kernels that ran it comfortably were far newer than what most enterprises deployed. The project's answer to "will this ever be mainstream?" arrived from an unexpected direction in April 2018, in its own 1.0 announcement: "possibly the strongest signal on the success of BPF has been the decisions of the Linux kernel community to replace the in-kernel implementation of iptables with BPF."
The Timeline: From cilium-net to the Only Graduated Network
- 2015-12-16 — Commit
7fa3c60eb7, "Initial commit", 226 lines, Thomas Graf. The repo is named cilium-net; Daniel Borkmann and André Martins commit within weeks. First PR merges January 12, 2016. - 2016-08-20 — First public debut on Hacker News: "Cilium: Fast in-kernel networking and security policy enforcement for containers." The pitch is already the full stack — networking, security, visibility — not just a CNI.
- 2017 — Isovalent is founded by Thomas Graf and Dan Wendlandt "a year after starting the project," per the founders' own later account. Wendlandt is a Nicira/VMware veteran — the software-defined networking lineage is now complete at the top: kernel dataplane (Graf, Borkmann) plus SDN product (Wendlandt).
- 2017-02/05 — Rename to cilium; public announcement at DockerCon 2017. An HN thread from May 25, 2017 describes "Linux Native, HTTP Aware Networking and Security for Containers" — the project's identity is stable from here on.
- 2018-04-24 — Cilium 1.0: first stable API with upgrade/downgrade guarantees, LTS releases, a defined security process. The project commits to being production infrastructure, not a kernel experiment.
- 2019-02/08 — v1.4: multi-cluster "global services" (beta) and IPsec transparent encryption (beta). v1.5 (April): 5,000-node/100,000-pod scale targets. v1.6 (August): KVStore-free operation, socket-based load balancing, and the headline feature that redefines the project — 100% kube-proxy replacement.
- 2019-06 — The eBPF gold rush produces friction: a public license-change and attribution dispute over Cilium eBPF code appearing in the Calico project surfaces on Hacker News. The episode is minor in size, but it marks the moment eBPF stops being Cilium's private moat and becomes contested territory.
- 2019-11-19 — Hubble is spun out as its own repository: the observability layer (L3-L7 flow visibility) gets its own release cycle. Cilium is now formally a family of projects.
- 2020 — The validation year. June: v1.8 ships XDP load balancing with 2,162 commits from 72 developers. August: the team launches ebpf.io as the technology's community hub, and Google announces Cilium and eBPF as the new networking dataplane for GKE. A hyperscaler has now absorbed the kernel gamble for everyone else.
- 2020-11-10 — Isovalent formally launches, announcing a $29M Series A led by Andreessen Horowitz and Google — and Cilium v1.9 ships the same day (deny policies, Maglev consistent hashing, bandwidth manager). Nearly five years passed between first commit and first priced round.
- 2021-05 — v1.10: WireGuard transparent encryption, standalone load-balancer mode (
--datapath-mode=lb), an Alibaba Cloud operator. The "we replace your dataplane" scope is now explicit. - 2021-08 — The eBPF Foundation launches under the Linux Foundation with Facebook, Google, Isovalent, Microsoft, and Netflix. The technology under Cilium gets neutral governance a full year before the project itself.
- 2021-10-13 — Cilium is accepted into the CNCF at the Incubating maturity level. The donation completes the Isovalent strategy: company owns the commercial distribution, foundation owns the project.
- 2021-12 — v1.11 ships OpenTelemetry export from Hubble, and days later the team publishes "eBPF will help solve service mesh by getting rid of sidecars." The service-mesh establishment (sidecar-per-pod proxies) is told its architecture is unnecessary overhead. Cilium 1.12 (July 2022) follows through: integrated Gateway API Ingress, sidecar-free service mesh, stable Egress Gateway, AWS ENI prefix delegation.
- 2022-05-16 — Tetragon is open-sourced: eBPF-based security observability and real-time runtime enforcement. Cilium now competes with runtime-security agents, not just CNIs.
- 2022-09-07 — $40M Series B, with Microsoft and Grafana Labs among the investors — both Cilium adopters at their own scale. The round's pitch: all three major cloud providers have now singled out Cilium; customers include Adobe, Capital One, IKEA, and Sky.
- 2023-10-11 — CNCF Graduation — the first networking project ever to reach it, joining Kubernetes, Prometheus, and Envoy. Thomas Graf's graduation proposal PR collected roughly 800 positive emoji reactions; vote and due diligence closed in his favor. The acquisition was announced just eleven weeks later.
- 2023-12-21 — Cisco announces its intent to acquire Isovalent — the second-largest networking company on earth buying the eBPF startup. The community question is immediate: what happens to the project? The acquisition completes in April 2024, per the update note on Cisco's own announcement.
- 2024-07-24 — First post-acquisition major release: v1.16 ships NetKit (container-network throughput at host-network speed) and BGPv2, from 2,969 commits by 750+ developers. Whatever buyers feared, engineering cadence did not slow: 1.17 (February 2025) adds pod-level network QoS and the Multi-Cluster Services API.
- 2025-07-29 — v1.18: the service load-balancing control plane is redesigned (3,298 commits, 955+ developers, 22,000 stars). NetKit gets framed as the container networking paradigm "for the AI era" — the workload story shifts to GPU fleets and AI clusters.
- 2026-02-04 — v1.19: ZTunnel-based transparent encryption (mTLS without sidecars, converging with Istio's ambient architecture), multi-pool IPAM to stable, multi-level DNS policy matching. 1,010+ contributors in cycle; 23,600 stars.
- 2026-07-29 — v1.20: Gateway API v1.6.1 with ExternalAuth (GEP-1494), TCPRoute/UDPRoute, and — the strategically loudest feature — extensible datapath plugins, letting cloud providers extend Cilium's eBPF dataplane "without maintaining a Cilium fork." 2,660 commits, 1,100+ contributors, 24,800 stars. v1.20.2 is the current stable (September 16, 2026); v1.21.0 is in prerelease.
Crisis Points & Architectural Pivots
1. The kernel-fork gamble (2015–2018, structural)
Cilium's origin risk was not market competition — it was whether mainline Linux would carry the eBPF features the project needed. Building your network stack on programmable kernel hooks in 2015 meant betting on unreleased kernel work, and the bet only paid off because the bettors controlled the odds: Graf and Borkmann were kernel maintainers, and the kernel community's eventual decision to move iptables handling toward BPF ratified the whole approach. The lesson for platform teams evaluating any kernel-adjacent tool: check who the maintainers are inside the upstream project. Cilium's credibility was BPF [CORE] maintainership, not marketing. The same check applied to a startup without kernel committers would have failed.
2. Four unpaid years, then a hyperscaler validates (2015–2020, financial)
The monetization timeline is the tale's most instructive chart. First commit: December 2015. Public launch: 2017. Priced round: November 2020. In between, the team's output was deliberately ecosystem-shaped rather than product-shaped: ebpf.io (August 2020), the eBPF Foundation (August 2021, with Facebook, Google, Microsoft, and Netflix), the eBPF documentary, CNI benchmarks, O'Reilly books. Then Google shipped Cilium inside GKE's Dataplane V2 — and the Series A closed within three months, led by Andreessen Horowitz and Google itself. The sequencing is the playbook: neutral foundation → hyperscaler adoption → capital. Compare that with projects that raise first and search for a moat later; Cilium's moat was the kernel.
3. Scope creep: one daemon to replace them all (2019–2026, architectural)
Each release absorbed another product category's job. This is the single most decision-relevant fact about adopting Cilium in 2026 — what you are evaluating is no longer a CNI:
| Function | Before Cilium absorbed it | Cilium implementation | Since |
|---|---|---|---|
| Service load balancing | kube-proxy (iptables/IPVS) | eBPF kube-proxy replacement + Maglev | v1.6 (2019), Maglev v1.9 |
| Ingress / Gateway API | Per-cluster ingress controllers | Integrated Gateway API implementation (ExternalAuth, TCP/UDPRoute) | v1.12 (2022), expanded v1.20 |
| Service mesh mTLS | Sidecar proxies per pod | Sidecar-free eBPF mesh; ZTunnel transparent encryption | v1.11–1.12 (2021–22), ZTunnel v1.19 |
| Network policy | iptables plugins, IP/CIDR rules | Identity-based L3–L7 policy (labels, HTTP/gRPC/Kafka) | v1.0 (2018), deny v1.9 |
| Encryption | Overlay/IPsec appliances | IPsec, WireGuard, ZTunnel mTLS | v1.4 / v1.10 / v1.19 |
| Runtime security | Separate agents | Tetragon (eBPF enforcement) | 2022 |
| Observability | Flow loggers, packet capture | Hubble + OpenTelemetry export | 2019, OTel v1.11 |
| Load balancing (standalone) | Hardware/virtual LBs | Dedicated LB dataplane mode | v1.10 (2021) |
| BGP routing | MetalLB-class tools | BGP CRDs (v2 API) | v1.11, BGPv2 v1.16 |
The skeptical reading: every absorbed function widens the blast radius. The upgrade guides for v1.19 and v1.20 both open with "you may need to take action" warnings — legacy mutual authentication, Envoy Go extensions, Kafka-aware policies, CiliumNodeConfig, BGP, LoadBalancer IPAM are all upgrade hazards now. A CNI's core promise was being invisible plumbing you never think about; a platform's reality is that every minor upgrade is a change-review meeting. Cilium crossed from the first to the second somewhere around v1.12. Plan operational ownership accordingly.
4. Graduation first, acquisition second (2023, governance)
The Cisco acquisition is the crisis that wasn't, and the reason is sequencing. The graduation PR opened in late 2022, the TOC vote and due diligence completed October 11, 2023, and the acquisition was announced December 21 — the project was under neutral CNCF governance, Apache-2.0, before the acquirer showed up. Cisco bought Isovalent's engineers, its enterprise distribution, and its Tetragon customers (GitHub, G-Research, and Nationwide are named by the founders); it did not buy the project, because the project is not the founders' to sell. Compare the ecosystem's cautionary tale: Terraform stayed under single-company ownership until 2023, changed its license, and forced a community fork. The Cilium sequence — donate, graduate, then exit — is now the template every VC-backed infrastructure startup will be measured against. Whether Isovalent planned it that way or the timing was luck, the result is the same: no BUSF-style crisis is possible here, and that should be priced into the risk analysis of any Cilium-standardized fleet.
Community Engine & Corporate Influence: Who Actually Built It
The commit archaeology is unambiguous about the center of gravity. André Martins (aanm) leads all contributors at ~3,900 commits, with Thomas Graf (tgraf) at ~2,750 and the long tail of maintainers behind them — the top ten accounts for roughly two-thirds of a decade of merged work:
login commits role (verified where known)
aanm 3902 André Martins — lead maintainer, Isovalent-era
tgraf 2754 Thomas Graf — creator, Isovalent co-founder/CTO
joestringer 2481 long-time maintainer
tklauser 1950 kernel-side contributor
jrajahalme 1607
pchaigno 1522
julianwiedmann 1492
brb 1288 load-balancing subsystem lead
giorio94 1227
borkmann 1131 Daniel Borkmann — kernel BPF co-maintainer
But the corporate pattern is the healthier half of the story. Isovalent employees built the core, and — per the project's own graduation account — engineers from Google, Microsoft, Datadog and "many more" companies now work on it alongside them. Every major adopter had a structural reason to contribute: Google needed GKE's dataplane hardened, Microsoft needed Azure CNI powered by Cilium to work at AKS scale, and AWS made Cilium the default CNI of EKS Anywhere and the AWS-supported CNI for EKS Hybrid Nodes. When your cloud vendor's managed offering runs the project, the maintenance bill is distributed — the exact opposite of the one-volunteer bus-factor failure that killed Ingress NGINX.
The influence audit still deserves skepticism on two axes. First, the Isovalent-at-Cisco commercial arm now sells an Isovalent Enterprise Platform (hardened Cilium + Tetragon, plus ACI and Nexus integrations), and the project's feature velocity visibly tracks Cisco's multicloud strategy — extensible datapath plugins in v1.20 are a cloud-provider feature, not a community ask. Second, the CNCF's own project page currently scores Cilium's health as Fair (66) with total contributors down 3% year-over-year and contributing organizations down 6% — plateau signals, not decline signals, but worth watching now that the acquisition-era momentum has burned off. Eleven thousand lifetime contributors and 2,600+ contributing organizations mean the project is not fragile; the honest read is that the exponential phase is over and the institutional phase has begun.
Current Trajectory: The Verdict
- The growth line is still steep, measured by the project's own release notes. Stars at release time: 19,300 (v1.16, July 2024) → 20,800 (v1.17) → 22,000 (v1.18) → 23,600 (v1.19) → 24,800 (v1.20, July 2026), with 25,500+ on the repo today. Contributors per cycle: 750 → 880 → 955 → 1,010 → 1,100+. That is a maturing but still-compounding project, not a post-acquisition coast.
- eBPF won, and Cilium is the standard distribution of the win. The kernel community moved iptables handling toward BPF; the eBPF Foundation carries the technology; ebpf.io is the front door; GKE, AKS, EKS Anywhere, and EKS Hybrid Nodes all ship or support Cilium-based dataplanes. If you are picking a CNI in 2026 without a hard requirement that excludes it (ancient kernels, non-Linux workers, an existing Calico investment you're happy with), Cilium is the default the market already picked. Our hands-on Cilium service mesh guide covers the sidecar-free mesh architecture this history produced.
- Buy the support, not the dependency-free fantasy. The commercial path is Isovalent Enterprise at Cisco for hardened distribution, support, and the Tetragon security story; the managed paths are GKE Dataplane V2, Azure CNI powered by Cilium, and EKS Anywhere/Hybrid Nodes. Whichever door you take, the honest procurement question is what the upgrade notes make obvious: Cilium is now a platform decision with quarterly upgrade reviews, not a set-and-forget plugin. Teams that treat it as the latter accumulate upgrade hazards (legacy mutual auth, Kafka policies, BGP configs) exactly like the ingress-controller users who woke up one day to find their front door archived.
- Watch two risks: scope gravity and kernel-adjacent concentration. Every function Cilium absorbs (the table above) raises switching costs and upgrade blast radius — fine while the project is healthy, expensive if governance ever sours. And the ecosystem has concentrated its kernel-networking destiny on one project whose core still leans on one company's engineers, however large the community around them has grown. The CNCF health score says Fair; the adoption curve says winner; both are true.
Final verdict: Cilium is the rare infrastructure tale where every phase of the arc worked: kernel expertise became a project, the project became a category, the category became a hyperscaler-validated standard, the standard was donated to a foundation before its creators sold the company, and the acquirer kept shipping. The two genuine costs are architectural honesty — it stopped being "just a CNI" years ago, and operating it as a platform is the only sane posture — and concentration risk, which the graduation structure mitigates but does not erase. In a decade of cloud-native networking, no other project converted kernel-level control into ecosystem-level leverage this completely. That is either the strongest endorsement or the strongest warning in this series, depending on which side of the upgrade review meeting you sit.
Who should skip it: teams pinned to kernels older than Cilium's minimum, non-Linux worker nodes, or shops that have standardized on another eBPF dataplane and are genuinely satisfied. Everyone else evaluating Kubernetes networking in 2026 should understand this history — because the defaults of every major managed Kubernetes offering were shaped by it.