Technical explanation
Cilium primarily improves Kubernetes network security through identity-aware policy enforcement across Layers 3 through 7. Standard Kubernetes NetworkPolicy resources provide Layer 3 and Layer 4 controls, while CiliumNetworkPolicy extends enforcement to application-layer rules. Policies can select workloads by labels and identity, restrict protocols and destination ports, control communication with CIDRs or entities, apply DNS/FQDN rules, and authorize supported HTTP or gRPC operations. This multi-layer enforcement is the capability described by D.
API Gateway and Gateway API configurations can contribute to controlling north-south traffic, but they are not Cilium’s primary or comprehensive security mechanism. Database encryption is implemented by database, storage, or encryption-management systems rather than being a general function of Cilium. Persistent-volume backup is similarly outside Cilium’s CNI, network-policy, and observability responsibilities.
Cilium’s identity model is especially important in dynamic Kubernetes environments. Security policy follows workload identities derived from labels instead of depending exclusively on changing pod IP addresses. At Layer 7, traffic is redirected to Envoy when protocol-aware inspection or enforcement is required, while eBPF supplies the efficient kernel datapath for lower-layer processing.
Official references
Introduction to Cilium and Hubble ; Network Policy ; Layer 7 Policies .
Study Guide topic: Network Policy.
Submit