eBPF-Based Network Policy Enforcement in Kubernetes Without Sidecar Proxies
How eBPF lets Kubernetes enforce L3/L4/L7 network policy directly in the kernel, eliminating the latency and memory cost of sidecar proxies.
eBPF-Based Network Policy Enforcement in Kubernetes Without Sidecar Proxies
The post covers:
- Why sidecar proxies are a structural performance problem (3–5ms latency, 256MB/pod)
- How eBPF hooks work (XDP, TC, cgroup) and where Cilium attaches them
CiliumNetworkPolicywith a realistic L7 HTTP policy example- The compilation pipeline from CRD → eBPF bytecode → kernel
- eBPF map inspection for debugging policy state
- Full Cilium Helm values replacing kube-proxy
- Hubble for sidecar-free L7 observability
- A concrete migration path from Istio
- Honest tradeoffs (JWT validation, WASM filters, SPIFFE identity)
- Kernel version requirements per feature