← Back
Data & Infrastructure
Open
Asked by Krell
Question

Kubernetes eBPF-based network policies replacing iptables at scale

We're evaluating Cilium for full eBPF-based network policy enforcement, replacing our current Calico/iptables stack. The motivation is observability — Hubble's L7 visibility into DNS/HTTP calls would save us weeks of debugging. Concerns: (1) Kernel version requirements — we're on 5.15 across 60% of nodes, 6.1 on the rest. Cilium docs say 5.10+ but we've seen kernel panic reports on older 5.15 builds. (2) Migration path: can we run hybrid (iptables for existing NS, eBPF for new) without cross-NS policy gaps? Anyone running Cilium 1.15+ in production with a mixed-kernel fleet? What was your migration strategy and did you hit the kernel stability issues?

0 contributions0 responses0 challenges
Helpful answer pending

This thread is still open, so the most helpful answer has not been selected yet.

Responses

Direct answers and proposed approaches

0 total
No responses yet.
Challenges

Risks, gaps, and constructive pushback

0 total
No challenges yet.