# cilium/cilium

eBPF-based Networking, Security, and Observability

Repository: https://github.com/cilium/cilium
Canonical: https://ross.abutalabs.com/products/cilium
Homepage: https://cilium.io
Language: Go
License: Apache-2.0
License Family: permissive
Topics: containers, bpf, security, kubernetes, kubernetes-networking, cni, kernel, loadbalancing, monitoring, troubleshooting, xdp, ebpf, k8s, observability, networking, cncf
Last push: 2026-08-26T22:59:45+00:00

## Health v2 (maintenance only)
Score: 95/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 99, release rhythm 86, longevity 100
- inputs: {"age_days": 3913, "days_push": 7, "days_rel": 15, "gap_med": 0, "n_releases_24m": 76}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 25014, forks 3993 (observed 2026-08-28T04:11:37.780563+00:00)

## What it is
Cilium is an open-source networking, security, and observability solution for Kubernetes and container workloads built on an eBPF-based dataplane. It provides L3-L7 network policy enforcement, distributed load balancing, kube-proxy replacement, and deep visibility using identity-based security decoupled from network addressing.

## Use cases
- replace kube-proxy in a kubernetes cluster
- enforce network policies between pods at L3-L7
- observe and troubleshoot network traffic in kubernetes
- implement a service mesh without sidecars
- secure multi-cluster container networking
- manage ingress and egress gateways
- monitor network flows with eBPF

## When to choose
- you run Kubernetes on Linux and want eBPF-based CNI networking
- you need scalable load balancing and kube-proxy replacement
- you require identity-based L3-L7 network security policies
- you want deep network observability and Hubble-based flow visibility

## When to avoid
- your hosts run kernels too old for required eBPF features
- you need a simple non-Kubernetes network setup
- your team cannot operate a kernel-level dataplane or lacks Linux expertise

## Facets
- artifact type: service
- maturity: stable
- function: networking, security, monitoring, tracing, load-testing, api-gateway
- domain: networking, security, cloud-computing, monitoring, microservices
- platform: go, cloud, self-hosted
- tags: ebpf, cni, kubernetes-networking, xdp, service-mesh, kube-proxy-replacement, cncf, network-policy, loadbalancing, containers, devops, linux, kubernetes, docker

## Member repositories
- cilium/cilium (main) score 95

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:11:37.780563+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T16:56:07.382336+00:00, confidence not recorded.
  - readme: https://github.com/cilium/cilium (fetched 2026-08-28T04:11:37.780563+00:00, sha afab9cb95d3e)
  - homepage: https://cilium.io (fetched 2026-08-29T07:53:10.730930+00:00, sha 2628ae4ff5e4)
- Data as of 2026-08-30T08:39:29.467469+00:00.
