Technical explanation
Cilium functions as a Kubernetes Container Network Interface implementation. When Kubernetes creates or removes a pod sandbox, the container runtime invokes the configured CNI plugin. Cilium establishes the pod’s network connectivity, connects the workload to the node’s networking environment, allocates or obtains an address through the configured IPAM mode, and coordinates the endpoint with the Cilium agent. Its eBPF datapath then supplies routing, service load balancing, policy enforcement, and network visibility.
Cilium provides substantially more functionality than the minimum CNI contract, but those additional capabilities do not change its primary Kubernetes networking role. Hubble supplies integrated network observability, yet Cilium is not merely a container-metrics monitor. Resource utilization such as CPU and memory is normally handled through Kubernetes metrics and monitoring systems.
Cilium is also not a Container Storage Interface. CSI drivers manage storage volumes, attachment, mounting, and lifecycle operations, which are unrelated to Cilium’s primary responsibilities. Nor is Cilium simply a pod-operation logging mechanism. It can emit datapath events and diagnostic logs, but those are supporting capabilities.
Accordingly, D provides the correct architectural classification for Cilium in a Kubernetes cluster.
Official references
Introduction to Cilium and Hubble ; Cilium Helm Installation .
Study Guide topic: Architecture.
Submit