Skip to content
_CORE
AI & Agentic Systems Core Information Systems Cloud & Platform Engineering Data Platform & Integration Security & Compliance QA, Testing & Observability IoT, Automation & Robotics Mobile & Digital Banking & Finance Insurance Public Administration Defense & Security Healthcare Energy & Utilities Telco & Media Manufacturing Logistics & E-commerce Retail & Loyalty
References Technologies Blog Know-how Tools
About Collaboration Careers
CS EN DE
Let's talk

eBPF and Cilium — Service Mesh Without Sidecar Proxies

15. 10. 2023 Updated: 24. 03. 2026 1 min read CORE SYSTEMSinfrastructure
This article was published in 2023. Some information may be outdated.
eBPF and Cilium — Service Mesh Without Sidecar Proxies

Istio with Envoy sidecar proxies on every pod. Great — but also overhead. Cilium takes a radically different approach: eBPF in the kernel. No sidecars. And the results are impressive.

eBPF — A Programmable Kernel

eBPF allows running sandboxed programs directly in the Linux kernel. For networking: filtering, routing, load balancing, and observability with minimal overhead.

Cilium as a Service Mesh

Sidecar-free: mTLS, traffic management, L7 policy — all without Envoy proxies. Since version 1.14, Cilium is a graduated CNCF project. Latency overhead measured in microseconds.

Hubble — Observability

Network flows, DNS queries, HTTP requests — at the kernel level. No agents, no code instrumentation.

Migration from Istio

  • P99 latency: reduced by 40%
  • Memory per pod: ~50MB saved (no Envoy sidecar)
  • Operational complexity: significantly lower
  • Observability: better (Hubble vs. Kiali)

eBPF Is the Future of Kubernetes Networking

Requires a modern kernel (5.10+). For organizations with large clusters and latency-sensitive workloads, it’s the clear choice.

ebpfciliumservice meshkubernetes
Share:

CORE SYSTEMS

We build core systems and AI agents that keep operations running. 15 years of experience with enterprise IT.

Need help with implementation?

Our experts can help with design, implementation, and operations. From architecture to production.

Contact us
Need help with implementation? Schedule a meeting