Cilium supplies networking for Kubernetes workloads and controls which traffic is allowed between them. It can also provide features such as service routing and Gateway API integration, letting an existing Cilium platform handle incoming application requests. Teams consider it when they need a networking system with integrated traffic policy. Because it sits in the path of cluster communication, its compatibility with the machines and existing network matters before individual gateway features.
Compatibility first
Check the exact Cilium release against Kubernetes, the kernel, cloud networking, node images and the features you will enable. For Gateway API, Cilium requires kube-proxy replacement and the L7 proxy enabled, plus the Gateway API CRDs required by the selected release. The default exposure uses a LoadBalancer Service; the documented host-network mode is an alternative. Check the release’s kernel and L7 proxy requirements before enabling either path. Record how existing network policies and service traffic will behave during a change.
Validate network behavior
Test DNS, service reachability, egress restrictions, host-to-pod access and traffic during node replacement. Include workloads with unusual routing or host networking. Maintain a provider-supported recovery path before changing the production dataplane.
For a new gateway on an existing supported Cilium platform, evaluate the operational benefit of keeping one networking stack. For an independent gateway requirement, compare alternatives in the implementation guide.
Sources & further reading
Spotted something that needs another look?
Help improve this page →