SYSTEM Cited by 3 sources
Cilium¶
Cilium is a widely-adopted Kubernetes CNI (cilium.io) built on systems/ebpf: pod networking, L3/L4/L7 policy enforcement, service-mesh data plane, observability — all implemented via eBPF programs attached to TC, XDP, socket, and cgroup hooks.
This wiki currently references Cilium as an example of multi-tenant eBPF on the same host, not for its own internals.
2022 Datadog × Cilium incident¶
Both products use TC classifier (SCHED_CLS) eBPF programs on
pod network interfaces. Cilium attaches with a hardcoded priority
of 1 and a hardcoded handle of 0:1 (per-classifier unique
identifier).
Race condition on pod startup: systems/datadog-workload-protection
sometimes loaded its TC filters before Cilium, unintentionally
grabbing handle 0:1. When Cilium later loaded and replaced
Datadog's filters with its own, Datadog's network-namespace
cleanup logic — which watches for unexpected handle changes to
avoid leaking resources — interpreted the change as a cleanup
signal and deleted Cilium's filters, breaking pod connectivity
(Source: sources/2026-01-07-datadog-hardening-ebpf-for-runtime-security,
CiliumCon 2023 post-mortem).
"Both solutions are independently correct and stable" — Datadog, on what makes the class of bug hard.
Takeaway¶
TC priorities, TC handles, cgroup program ordering, and similar shared kernel resources are effectively an inter-vendor protocol on any host with more than one eBPF tool. The generalised lesson is shared-kernel-resource-coordination:
- Use higher default priorities so infrastructure-level classifiers (CNIs) get to run first.
- Harden cleanup against races — default to never auto-deleting queuing disciplines or shared kernel resources.
- Coordinate with peer vendors on conventions; detect and warn on unexpected co-residents.
Seen in¶
- sources/2026-01-07-datadog-hardening-ebpf-for-runtime-security — the TC-handle-collision outage, post-mortem, and resulting Datadog mitigations (TC priority 10, conservative cleanup, vendor coordination).
- sources/2026-04-16-github-ebpf-deployment-safety — GitHub
builds its eBPF deployment-safety firewall on the Cilium
project's pure-Go
cilium/ebpflibrary (for reading/modifying/loading eBPF programs and attaching to cGroup hooks); not using Cilium CNI itself. Reference for Cilium-the-ecosystem beyond Cilium-the-CNI. - sources/2026-09-17-aws-how-equinix-cut-operational-overhead-with-a-shared-services — Cilium as the CNI in a production shared-services EKS platform (Equinix), in the canonical CNI role: enforcing network policies that isolate workloads at the pod level (tenant isolation) across both the Workloads and Platform accounts, with Hubble (Cilium's eBPF flow-observability layer) providing real-time network observability across all traffic flows — replacing fragmented, per-team monitoring (concepts/observability). A reference for Cilium-the-CNI + Hubble as the observability data plane, not the eBPF-coordination incident above.
Related¶
- systems/ebpf
- systems/kubernetes
- systems/datadog-workload-protection
- shared-kernel-resource-coordination
- patterns/agent-sandbox-with-gateway-only-egress