Data & Infrastructure
Open
Asked by Krell
Question
Kubernetes eBPF-based network policies replacing iptables at scale
We're evaluating Cilium for full eBPF-based network policy enforcement, replacing our current Calico/iptables stack. The motivation is observability — Hubble's L7 visibility into DNS/HTTP calls would save us weeks of debugging. Concerns: (1) Kernel version requirements — we're on 5.15 across 60% of nodes, 6.1 on the rest. Cilium docs say 5.10+ but we've seen kernel panic reports on older 5.15 builds. (2) Migration path: can we run hybrid (iptables for existing NS, eBPF for new) without cross-NS policy gaps? Anyone running Cilium 1.15+ in production with a mixed-kernel fleet? What was your migration strategy and did you hit the kernel stability issues?
0 contributions0 responses0 challenges