PageSourceSearch

https://cilium.io/component---src-templates-blog-post-jsx-content-…ay-install-index-md-973be393e9cc52d66467.js

js cilium.io collected 2026-09-24 08:29:18 UTC 40,089 bytes, 2 lines download raw bytes

1"use strict";(self.webpackChunkcilium_io=self.webpackChunkcilium_io||[]).push([[8115],{6452:function(e,n){n.A={thomasGraf:{header:"Thomas Graf",bio:'Thomas Graf is a Co-Founder of Cilium and the CTO & Co-Founder of <a href="https://isovalent.com/?utm_source=website-cilium&utm_medium=referral&utm_campaign=cilium-enterprise">Isovalent</a>, the company behind Cilium. Before that, Thomas spent 15 years as\n    a kernel developer working on the <a href="https://kernel.org">Linux kernel</a> in networking, security and eventually eBPF.'},lizRice:{header:'<a href="https://twitter.com/lizrice">Liz Rice</a>',bio:'Liz is Chief Open Source Officer at <a href="https://isovalent.com/?utm_source=website-cilium&utm_medium=referral&utm_campaign=cilium-enterprise" target="_blank" rel="noopener noreferrer">Isovalent</a>, the company behind Cilium. She is also chair of the CNCF\'s Technical Oversight Committee, and the author of Container Security published by O\'Reilly.'},luanGuimaraes:{header:"Luan Guimarães",bio:"Luan is a Brazilian rock climber, amateur musician, and\n   programmer and am enthusiastic about free software communities and other\n   open knowledge initiatives. He has been working as a Site Reliability\n   Engineer at Wildlife Studios, using and building infrastructure tools on\n   top of Kubernetes in order to support millions of users around the world."},joshVanLeeuwen:{header:"Josh Van Leeuwen",bio:"Josh interned at Jetstack during the summer of 2017 before continuing to\n    work part time during his final year of study at the University of Bristol.\n    During this year, Josh developed a Kubernetes custom controller that\n    automates the delegation of RBAC permissions based on time and event\n    triggers. This work was later awarded the best Software Development Tool\n    Final Year Project. Josh now works full time at Jetstack where if he’s not\n    writing more Go, he’s making good food."},howardHao:{header:"Howard Hao",bio:" Howard Hao has been working as a Site Reliability Engineer for five years at\n    Ect888.com since graduating from Shanghai Jiao Tong University. His team\n    consists of 7 members and has been focusing on the construction of\n    container orchestration platform like Kubernetes for one and a half years."},sergeyGeneralov:{header:"Sergey Generalov",bio:"Sergey is a member of the technical staff at Isovalent\n    and focuses on helping Cilium users solve challenges related\n    to network policies, monitoring, and connectivity troubleshooting\n    by building tools like Network Policy Editor, Hubble UI and more."},liWenquan:{header:"Li Wenquan",bio:"Hello everyone, I am Li Wenquan from China. You can call me David. I\n    started my Docker journey from 2014 and now work as a project manager of\n    enterprise container platform, which is built on Kubernetes and Mesos. I\n    got to know Cilium project from Kubecon, it is so interesting and\n    promising. I've learned a lot from it, such as BPF, XDP and how to replace\n    kube-proxy in a elegant way and I'd love to contribute to it."},alexanderAlemayhu:{header:"Alexander Alemayhu",bio:"Alexander Alemayhu is a software engineer at Isovalent,\n    the company behind Cilium. He has been working on eBPF and Linux\n     kernel technologies for several years, focusing on networking and observability solutions."},DanielBorkmann:{header:"Daniel Borkmann",bio:"Daniel Borkmann is a Distinguished Software Engineer, Isovalent at Cisco"},ThomasGraf:{header:"Thomas Graf",bio:"Thomas Graf is the CTO & Co-Founder Isovalent and also the Vice President Security Cisco"},JedSalazar:{header:"Jed Salazar",bio:"Jed Salazar is a Senior Solutions Architect, Isovalent"},JedSalazarandJoeStringer:{header:"Jed Salazar and Joe Stringer",bio:"Jed Salazar is a Senior Solutions Architect at Isovalent\n    and Joe Stringer is a Principal Engineer, Isovalent at Cisco"},JosephIrving:{header:"Joseph Irving",bio:"Joseph Irving is a Platform Engineer Lead at RVU (Uswitch)"},BillMulligan:{header:"Bill Mulligan",bio:"Bill Mulligan is a Cilium and eBPF Community Pollinator,\n    Isovalent at Cisco and a Governing Board Member of the eBPF Foundation."},OndrejBlazek:{header:"Ondrej Blazek",bio:"Ondrej Blazek is an Infrastru
1cture Engineer at Seznam.cz"},LeonardCohnenandMoritzEckert:{header:"Leonard Cohnen and Moritz Eckert",bio:"Leonard Cohnen and Moritz Eckert are team members at Edgeless Systems"},PolArroyo:{header:"Pol Arroyo",bio:"Pol Arroyo is a DevOps Engineer at Hetzner Cloud."},JedSalazarandMartynasPumputis:{header:"Jed Salazar and Martynas Pumputis",bio:"Jed Salazar is a Senior Solutions Architect, Isovalent and Martynas Pumputis is a Principal Software Engineer, Isovalent at Cisco"},ShedrackAkintayo:{header:"Shedrack Akintayo",bio:"Shedrack Akintayo is a Community Manager at\n    Isovalent helping build the eBPF and Cilium open source communities"},AmirKheirkhahan:{header:"Amir Kheirkhahan",bio:"Amir Kheirkhahan is a DevOps Specialist at DB Schenker handling design, development,\n     deployment and maintenance of wide range of devops toolchain on top of Kubernetes clusters"},PaulArah:{header:"Paul Arah",bio:"Paul Arah is a Community Builder focused on Security at Isovalent (Cisco)"},HimalKumar:{header:"Himal Kumar, Bhaskar Dutta, Arman Pashamokhtari",bio:"Himal Kumar, Bhaskar Dutta, Arman Pashamokhtari are all part of the\n     CanopusAI team Real Time Network Observability, powered by eBPF and Agentic AI"},DoniaChaiehloudj:{header:"Donia Chaiehloudj",bio:"Donia Chaiehloudj is a Senior Software Engineer and Community Oriented at Isovalent.\n    She has been working on Cilium and eBPF technologies, focusing on networking and security solutions."},KatieMeinders:{header:"Katie Meinders",bio:"Katie Meinders is a Community Builder at Isovalent where\n    she helps grow the Cilium and eBPF communities through storytelling,\n    social media, showcasing user success, and building connections across the open source ecosystem."},PeaceSandy:{header:"Peace Sandy",bio:"Peace Sandy is an LFX mentee who contributed to improving Cilium SEO, AEO, and\n    AIO during her mentorship period."},NehaAggarwal:{header:"Neha Aggarwal",bio:"Neha Aggarwal is a Principal Engineer at Microsoft."},CharityMbisi:{header:"Charity Mbisi",bio:"Charity Mbisi is an LFX mentee who contributed to improving Cilium's SEO, AEO, and AIO during his mentorship period.\n    Professionally, Charity Mbisi is a Software Engineer consulting in the Fin-tech and banking industry, specializing in building cloud native computing solutions and optimized service delivery."},andreMartinsAndFerozSalam:{header:"André Martins and Feroz Salam",bio:"André Martins is a Cilium maintainer and Software Engineer, Isovalent at Cisco.\n    Feroz Salam is a member of the Cilium Security Team and a Security Engineer, Isovalent at Cisco."},ChristianHernandez:{header:"Christian Hernandez",bio:"Christian is a well rounded technologist with experience in infrastructure engineering, systems administration, enterprise architecture, tech support, advocacy, and product management. Passionate about OpenSource and containerizing the world one application at a time. He is currently a maintainer of the Argo Project and OpenGitops. Currently, he works as a Technical Marketing Engineer and Tech Lead at Cisco. He focuses on GitOps practices, DevOps, Kubernetes, Network Security, and Containers."},AkilaInduranga:{header:"Akila Induranga",bio:'Akila is a Senior Software Engineer at WSO2, and a maintainer of <a href="https://openchoreo.dev/" target="_blank" rel="noopener noreferrer">OpenChoreo</a>, an open-source internal developer platform for Kubernetes and a CNCF sandbox project.\n    He works on the platform\'s observability and networking layers, including the Cilium-based networking module that brings identity-based policy and Hubble observability to OpenChoreo cells.'}}},8993:function(e,n,a){a.r(n),a.d(n,{Head:function(){return m},default:function(){return h}});var t=a(8453),s=a(6540),l=a(6452);function i(e){const n=Object.assign({span:"span",h5:"h5",h2:"h2",p:"p",a:"a",ul:"ul",li:"li",table:"table",thead:"thead",tr:"tr",th:"th",tbody:"tbody",td:"td"},(0,t.RP)(),e.components),{BlogAuthor:a}=n;return a||function(e,n){throw new Error("Expected "+(n?"component":"object")+" `"+e+"` to be defined: you likely forgot to import, pass, or provide it.")}("BlogAuthor",!0),s.createElement(s.Fragment,null,s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 960px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/5f70285e7b06e6e9bb7060c43eaee763/7d769/cover.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 56.34920634920635%; position: relative; bottom: 0; left: 0; background-image: url(\'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAIAAADwazoUAAAACXBIWXMAAAsTAAALEwEAmpwYAAACAUlEQVR42m1Rz4/SUBAm0ZN3Lyb+I969edK9ePLunoxZ439gokYvmkAgQCgVKbAoVn5ZlIOyNKxIixsghCAI7bJYCmVXWt57fU5LRGP8DpOZ15lvvn7jsW2bUooxWSOyyR3YBAJpV06fX0Xdc6fvL1jl8/TbDamrX7tT3POOmAe9u9cZDwwghBGynvmfyM2mS4QJcYiAyqbLtXp/Vd+VWpfYr1d6qrH78OBxZnIkL1+xEgyTzbLvyuDs54r+C5eB0u5cbJy8gUQ3TMOi9PNr6+ktD+yp1+u1w8PKpwOe50VRlGU5n88LJQGSo6YsNWqFPF8qvKt+FDudjsOnq9h7e7Zz2ZGdy+XS+/sRJhKLxQKBAMMwqVQqFArF4/FkMpl9yyeT3IsYI5SKrVbL+S/zjETu6TsXPVDAsCAIlUolnU4nEgmO4zKZTDabZVk2GAwWXfj9/rEydq10vRy3rfJLD3hTKBTC4XA0GoVWWA47fT4fvFSrVehDCIE67IIQ/NsHxwhH9mymKcqo3+8rigLCIBkOhxCn06nbaW/in0NCiZG9Nh3Za2xrc+uvT1uj7c3NiAvYu9D62FzCm1sRZ1iojb1so1bvTybHo5GqaTpI3Vx7ywLxZK4+2rv55UO5Nxg0JNkwDGe40fnB5brj47mu6zN9sVqZ9H9A2Gq2ewtjtTXiF/4eN/oLCA8qAAAAAElFTkSuQmCC\'); background-size: cover; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/5f70285e7b06e6e9bb7060c43eaee763/2ff5b/cover.webp 252w,\n/static/5f70285e7b06e6e9bb7060c43eaee763/4d583/cover.webp 504w,\n/static/5f70285e7b06e6e9bb7060c43eaee763/10c02/cover.webp 960w"\n              sizes="(max-width: 960px) 100v
1w, 960px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/5f70285e7b06e6e9bb7060c43eaee763/019e0/cover.png 252w,\n/static/5f70285e7b06e6e9bb7060c43eaee763/0dcb2/cover.png 504w,\n/static/5f70285e7b06e6e9bb7060c43eaee763/7d769/cover.png 960w"\n            sizes="(max-width: 960px) 100vw, 960px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/5f70285e7b06e6e9bb7060c43eaee763/7d769/cover.png"\n            alt="cover"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",s.createElement(n.h5,null,"July 6th, 2025"),"\n",s.createElement(n.h5,null,"Author: Paul Arah, Isovalent@Cisco"),"\n",s.createElement("a",{id:"installing-cilium-on-eks-in-overlay-byocni-and-cni-chaining-mode"}),"\n",s.createElement(n.h2,null,"Installing Cilium on EKS in Overlay(BYOCNI) and CNI Chaining Mode"),"\n",s.createElement(n.p,null,"In the first part of this EKS series, we covered setting up an EKS cluster and installing Cilium in ENI mode.\nIn this second and last of the EKS series, we’ll cover installing Cilium in overlay mode and CNI chaining mode."),"\n",s.createElement("a",{id:"installing-cilium-on-eks-in-cni-chaining-mode"}),"\n",s.createElement(n.h2,null,"Installing Cilium on EKS in CNI chaining mode"),"\n",s.createElement(n.p,null,"Installing Cilium in different modes follows a similar process. The main distinction lies in whether the AWS VPC CNI is disabled and Helm flags used during installation. For brevity sake, I'll skip certain repetitive steps in the installation process with the assumption that you've read the ",s.createElement(n.a,{href:"https://cilium.io/blog/2025/06/19/eks-eni-install/"},"previous blog post")," in this series, or can refer back to it as needed."),"\n",s.createElement(n.h2,null,"Prerequisites"),"\n",s.createElement(n.p,null,"The following prerequisites need to be taken into account:"),"\n",s.createElement(n.ul,null,"\n",s.createElement(n.li,null,"An active AWS Account"),"\n",s.createElement(n.li,null,"Install ",s.createElement(n.a,{href:"https://kubernetes.io/releases/download/#kubectl"},"kubectl"),", ",s.createElement(n.a,{href:"https://helm.sh/docs/intro/install/"},"Helm"),", ",s.createElement(n.a,{href:"https://docs.aws.amazon.com/eks/latest/userguide/setting-up.html"},"eksctl"),", ",s.createElement(n.a,{href:"https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html"},"awscli"),", and ",s.createElement(n.a,{href:"https://docs.cilium.io/en/stable/gettingstarted/k8s-install-default/#install-the-cilium-cli"},"Cilium CLI")),"\n"),"\n",s.createElement(n.h2,null,"Creating our EKS cluster"),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="yaml"><pre class="language-yaml"><code class="language-yaml"><span class="token key atrule">apiVersion</span><span class="token punctuation">:</span> eksctl.io/v1alpha5\n<span class="token key atrule">kind</span><span class="token punctuation">:</span> ClusterConfig\n<span class="token key atrule">metadata</span><span class="token punctuation">:</span>\n  <span class="token key atrule">name</span><span class="token punctuation">:</span> cluster1\n  <span class="token key atrule">region</span><span class="token punctuation">:</span> us<span class="token punctuation">-</span>east<span class="token punctuation">-</span><span class="token number">1</span>\n  <span class="token key atrule">version</span><span class="token punctuation">:</span> <span class="token string">\'1.30\'</span>\n<span class="token key atrule">iam</span><span class="token punctuation">:</span>\n  <span class="token key atrule">withOIDC</span><span class="token punctuation">:</span> <span class="token boolean important">true</span>\n<span class="token key atrule">addonsConfig</span><span class="token punctuation">:</span>\n  <span class="token key atrule">disableDefaultAddons</span><span class="token punctuation">:</span> <span class="token boolean important">true</span>\n<span class="token key atrule">addons</span><span class="token punctuation">:</span>\n  <span class="token punctuation">-</span> <span class="token key atrule">name</span><span class="token punctuation">:</span> coredns\n  <span class="token punctuation">-</span> <span class="token key atrule">name</span><span class="token punctuation">:</span> vpc<span class="token punctuation">-</span>cni</code></pre></div>'}}),"\n",s.createElement(n.p,null,"Notice that in the cluster config file, the AWS VPC CNI has been added to the list of add-ons with which we create the cluster. This is because in CNI chaining mode, we want both the AWS VPC CNI and Cilium present in the cluster as opposed to ENI mode, where we entirely remove the AWS VPC CNI."),"\n",s.createElement(n.ul,null,"\n",s.createElement(n.li,null,"Using eksctl, create the cluster."),"\n"),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">eksctl create cluster -f cilium-eks-config.yaml</code></pre></div>'}}),"\n",s.createElement(n.ul,null,"\n",s.createElement(n.li,null,"Since we have no node group yet, there will be no nodes in our cluster, and the pods will be stuck in a pending state."),"\n"),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="shell"><pre class="language-shell"><code class="language-shell">kubectl get pod <span class="token parameter variable">-n</span> kube-system\n\nNAME                      READY   STATUS    RESTARTS   AGE\ncoredns-c7bbdfbb8-j2wdg   <span class="token number">0</span>
1/1     Pending   <span class="token number">0</span>          2m24s\ncoredns-c7bbdfbb8-mcgt5   <span class="token number">0</span>/1     Pending   <span class="token number">0</span>          2m24s\n\n- Next, we need to <span class="token function">install</span> Cilium <span class="token keyword">in</span> our cluster. We’ll <span class="token keyword">do</span> this using Helm. But first, we need to grab the value of our Kubernetes <span class="token function">service</span> <span class="token function">host</span> by running the <span class="token builtin class-name">command</span> below:\n\n```shell\nkubectl cluster-info\n\nKubernetes control plane is running at https://xxxxxxxxxxxxxxxxxxxx.yyy.eu-west-2.eks.amazonaws.com\nCoreDNS is running at https://xxxxxxxxxxxxxxx.gr7.eu-west-2.eks.amazonaws.com/api/v1/namespaces/kube-system/services/kube-dns:dns/proxy</code></pre></div>'}}),"\n",s.createElement(n.ul,null,"\n",s.createElement(n.li,null,"Up next, we install Cilium using Helm with the command below"),"\n"),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="shell"><pre class="language-shell"><code class="language-shell">helm repo <span class="token function">add</span> cilium https://helm.cilium.io/\nhelm repo update\nhelm <span class="token function">install</span> cilium cilium/cilium <span class="token parameter variable">--version</span> <span class="token number">1.17</span>.5 <span class="token punctuation">\\</span>\n  <span class="token parameter variable">--namespace</span> kube-system <span class="token punctuation">\\</span>\n  <span class="token parameter variable">--set</span> <span class="token assign-left variable">cni.chainingMode</span><span class="token operator">=</span>aws-cni <span class="token punctuation">\\</span>\n  <span class="token parameter variable">--set</span> <span class="token assign-left variable">cni.exclusive</span><span class="token operator">=</span>false <span class="token punctuation">\\</span>\n  <span class="token parameter variable">--set</span> <span class="token assign-left variable">enableIPv4Masquerade</span><span class="token operator">=</span>false <span class="token punctuation">\\</span>\n  <span class="token parameter variable">--set</span> <span class="token assign-left variable">routingMode</span><span class="token operator">=</span>native<span class="token punctuation">\\</span>\n  <span class="token parameter variable">--set</span> <span class="token assign-left variable">k8sServiceHost</span><span class="token operator">=</span>xxxxxxxxxxxxxx.gr7.eu-west-2.eks.amazonaws.com<span class="token punctuation">\\</span>\n  <span class="token parameter variable">--set</span> <span class="token assign-left variable">k8sServicePort</span><span class="token operator">=</span><span class="token number">443</span>\n</code></pre></div>'}}),"\n",s.createElement(n.p,null,"Notice we're installing Cilium with a different set of flags? So what these flags do:"),"\n",s.createElement(n.table,null,s.createElement(n.thead,null,s.createElement(n.tr,null,s.createElement(n.th,null,"Helm Flag"),s.createElement(n.th,null,"Description"))),s.createElement(n.tbody,null,s.createElement(n.tr,null,s.createElement(n.td,null,s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">--namespace kube-system</code>'}})),s.createElement(n.td,null,"Specifies the Kubernetes namespace where Cilium will be installed.")),s.createElement(n.tr,null,s.createElement(n.td,null,s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">--set cni.chainingMode=aws-cni</code>'}})),s.createElement(n.td,null,"Sets the CNI chaining mode to ",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">aws-cni</code>'}}),". This allows Cilium to integrate with the AWS CNI plugin.")),s.createElement(n.tr,null,s.createElement(n.td,null,s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">--set cni.exclusive=false</code>'}})),s.createElement(n.td,null,"Sets the CNI exclusive mode to false, meaning Cilium will not be the only CNI plugin and can coexist with other CNI plugins.")),s.createElement(n.tr,null,s.createElement(n.td,null,s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">--set enableIPv4Masquerade=false</code>'}})),s.createElement(n.td,null,"Disables IPv4 masquerading. This means packets exiting the cluster will not have their source IP addresses translated to the node's IP address.")),s.createElement(n.tr,null,s.createElement(n.td,null,s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">--set routingMode=native</code>'}})),s.createElement(n.td,null,"Enables native routing mode. This mode does not rely on encapsulation (e.g., VXLAN or Geneve) for routing packets between nodes.")),s.createElement(n.tr,null,s.createElement(n.td,null,s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">--set endpointRoutes.enabled=true</code>'}})),s.createElement(n.td,null,"Enables endpoint routes. This allows Cilium to manage routing at the endpoint level, creating more specific routes for the network traffic.")))),"\n",s.createElement(n.ul,null,"\n",s.createElement(n.li,null,"Next, we create a corresponding node group for our cluster."),"\n"),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="yaml"><pre class="language-yaml"><code class="language-yaml"><span class="token key atrule">apiVersion</span><span class="token punctuation">:</span> eksctl.io/v1alpha5\n<span class="token key atrule">kind</span><span class="token punctuation">:</span> ClusterConfig\n\n<span class="token key atrule">metadata</span><span class="token punctuation">:</span>\n  <span class="token key atrule">name</span><span class="token punctuation">:</span> cluster1\n  <span class="token key atrule">region</span><span class="token punctuation">:</span> eu<span class="token punctuation">-</span>west<span class="token punctuation">-</span><span class="token number">2</span>\n\n<span class="token key atrule">managedNodeGroups</span><span class="token punctuation">:</span>\n  <span class="token punctuation">-</span> <span class="token key atrule">name</span><span class="token punctuation">:</span> ng<span class="token punctuation">-</span><span class="token number">1</span>\n    <span class="token key atrule">desiredCapacity</span><span class="token punctuation">:</span> <span class="token number">2</span>\n    <span class="token key atrule">privateNetworking</span><span class="token punctuation">:</span> <span class="token boolean important">true</span></code></pre></div>'}}),"\n",s.createElement(n.p,null,"To create the node group, run the command below"),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">eksctl create nodegroup -f nodegroup.yaml</code></pre></div>'}}),"\n",s.createElement(n.ul,null,"\n",s.createElement(n.li,null,"Afterwards, we can check the status of the nodes to ensure that they are in a ready state."),"\n"),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="shell"><pre class="language-shell"><code class="language-shell">kubectl get nodes\n\n\nNAME                                            STATUS   ROLES    AGE     VERSION\nip-192-168-125-58.eu-west-2.compute.internal    Ready    <span class="token operator">&lt;</span>none<span class="token operator">></span>   3h25m   v1.30.11-eks-473151a\nip-192-168-128-147.eu-west-2.compute.internal   Ready    <span class="token operator">&lt;</span>none<span class="token operator">></span>   3h25m   v1.30.11-eks-473151a\n\n- Validate health check: cilium-health is a tool available <sp
1an class="token keyword">in</span> Cilium that provides visibility into the overall health of the cluster’s networking and connectivity. You can check node-to-node health with cilium-health status:\n\n```shell\n\nkubectl <span class="token parameter variable">-n</span> kube-system <span class="token builtin class-name">exec</span> ds/cilium -- cilium status\n</code></pre></div>'}}),"\n",s.createElement(n.ul,null,"\n",s.createElement(n.li,null,"Additionally, you can run the connectivity tests to ensure your installation works properly."),"\n"),"\n",s.createElement("a",{id:"installing-cilium-on-eks-in-byocni-or-overlay-mode"}),"\n",s.createElement(n.h2,null,"Installing Cilium on EKS in BYOCNI or Overlay Mode"),"\n",s.createElement(n.p,null,'BYOCNI mode ("Bring your own CNI"), or overlay, creates an overlay network for pods using UDP-based encapsulation protocols such as VXLAN or Geneve. This installation mode has the advantage of being independent of pod network sizing/IP addressing limitations of AWS ENI.'),"\n",s.createElement(n.p,null,"The steps for Cilium in overlay mode is quite similar. We create a cluster with the AWS VPC CNI disabled and then install Cilium with right set of helm flags."),"\n",s.createElement(n.ul,null,"\n",s.createElement(n.li,null,"To get started, we’ll create a ClusterConfig file. In the file below, we’ve disabled kube-proxy and AWS VPC CNI."),"\n"),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="yaml"><pre class="language-yaml"><code class="language-yaml"><span class="token key atrule">apiVersion</span><span class="token punctuation">:</span> eksctl.io/v1alpha5\n<span class="token key atrule">kind</span><span class="token punctuation">:</span> ClusterConfig\n\n<span class="token key atrule">metadata</span><span class="token punctuation">:</span>\n  <span class="token key atrule">name</span><span class="token punctuation">:</span> cluster1\n  <span class="token key atrule">region</span><span class="token punctuation">:</span> eu<span class="token punctuation">-</span>west<span class="token punctuation">-</span><span class="token number">2</span>\n  <span class="token key atrule">version</span><span class="token punctuation">:</span> <span class="token string">\'1.30\'</span>\n<span class="token key atrule">addonsConfig</span><span class="token punctuation">:</span>\n  <span class="token key atrule">disableDefaultAddons</span><span class="token punctuation">:</span> <span class="token boolean important">true</span>\n<span class="token key atrule">addons</span><span class="token punctuation">:</span>\n  <span class="token punctuation">-</span> <span class="token key atrule">name</span><span class="token punctuation">:</span> coredns</code></pre></div>'}}),"\n",s.createElement(n.p,null,"Notice this time our cluster config file doesn’t include the AWS VPC CNI or kube-proxy add-on."),"\n",s.createElement(n.ul,null,"\n",s.createElement(n.li,null,"Using eksctl, create the cluster."),"\n"),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="shell"><pre class="language-shell"><code class="language-shell">eksctl create cluster <span class="token parameter variable">-f</span> cilium-eks-config.yaml</code></pre></div>'}}),"\n",s.createElement(n.p,null,"We need to grab the value of our Kubernetes service host by running the command below:"),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="shell"><pre class="language-shell"><code class="language-shell">kubectl cluster-info\n\nKubernetes control plane is running at https://xxxxxxxxxxxxxxxxxxxx.yyy.eu-west-2.eks.amazonaws.com\nCoreDNS is running at https://xxxxxxxxxxxxxxx.gr7.eu-west-2.eks.amazonaws.com/api/v1/namespaces/kube-system/services/kube-dns:dns/proxy</code></pre></div>'}}),"\n",s.createElement(n.p,null,"Up next, we install Cilium using Helm with the command below"),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="shell"><pre class="language-shell"><code class="language-shell">helm repo <span class="token function">add</span>
1 cilium https://helm.cilium.io/\nhelm repo update\nhelm <span class="token function">install</span> cilium cilium/cilium <span class="token parameter variable">--version</span> <span class="token number">1.17</span>.5 <span class="token punctuation">\\</span>\n  <span class="token parameter variable">--namespace</span> kube-system <span class="token punctuation">\\</span>\n  <span class="token parameter variable">--set</span> <span class="token assign-left variable">egressMasqueradeInterfaces</span><span class="token operator">=</span>eth0<span class="token punctuation">\\</span>\n  <span class="token parameter variable">--set</span> <span class="token assign-left variable">k8sServiceHost</span><span class="token operator">=</span>xxxxxxxxxxxxxxxxxxxxxx.gr7.eu-west-2.eks.amazonaws.com<span class="token punctuation">\\</span>\n  <span class="token parameter variable">--set</span> <span class="token assign-left variable">k8sServicePort</span><span class="token operator">=</span><span class="token number">443</span></code></pre></div>'}}),"\n",s.createElement(n.p,null,"Next, we create a corresponding node group for our cluster."),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="yaml"><pre class="language-yaml"><code class="language-yaml"><span class="token key atrule">apiVersion</span><span class="token punctuation">:</span> eksctl.io/v1alpha5\n<span class="token key atrule">kind</span><span class="token punctuation">:</span> ClusterConfig\n<span class="token key atrule">metadata</span><span class="token punctuation">:</span>\n  <span class="token key atrule">name</span><span class="token punctuation">:</span> cluster1\n  <span class="token key atrule">region</span><span class="token punctuation">:</span> eu<span class="token punctuation">-</span>west<span class="token punctuation">-</span><span class="token number">2</span>\n<span class="token key atrule">managedNodeGroups</span><span class="token punctuation">:</span>\n  <span class="token punctuation">-</span> <span class="token key atrule">name</span><span class="token punctuation">:</span> ng<span class="token punctuation">-</span><span class="token number">1</span>\n    <span class="token key atrule">desiredCapacity</span><span class="token punctuation">:</span> <span class="token number">2</span>\n    <span class="token key atrule">privateNetworking</span><span class="token punctuation">:</span> <span class="token boolean important">true</span></code></pre></div>'}}),"\n",s.createElement(n.p,null,"To create the node group, run the command below"),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="yaml"><pre class="language-yaml"><code class="language-yaml">eksctl create nodegroup <span class="token punctuation">-</span>f nodegroup.yaml</code></pre></div>'}}),"\n",s.createElement(n.ul,null,"\n",s.createElement(n.li,null,"Afterwards, we can check the status of the nodes to ensure that they are in a ready state, use the Cilium health tool and connectivity tests to validate our installation."),"\n"),"\n",s.createElement("a",{id:"a-primer-on-encapsulation-vs-native-direct-routing-in-cilium"}),"\n",s.createElement(n.h2,null,"A Primer on Encapsulation vs Native/Direct Routing in Cilium"),"\n",s.createElement(n.p,null,"Throughout this series, we’ve explored different ways to install Cilium in an EKS cluster. To better understand the trade-offs between these methods and help determine which one is right for you, it's important to examine a core concept in Cilium: routing."),"\n",s.createElement(n.p,null,"Cilium supports two primary networking modes for routing traffic between Kubernetes nodes: encapsulation and native routing each with its own strengths and drawbacks."),"\n",s.createElement(n.p,null,"Encapsulation uses overlay networks like VXLAN or Geneve to tunnel traffic between nodes, forming a mesh of virtual paths. This simplifies setup, avoids IP conflicts, and works well in complex or multi-cloud environments. However, it comes with performance overhead and potential ",s.createElement(n.a,{href:"https://docs.cilium.io/en/stable/network/concepts/routing/"},"maximum transfer unit(MTU)")," issues due to the added packet headers."),"\n",s.createElement(n.p,null,"Native routing, on the other hand, skips tunneling entirely and relies on the underlying network to route PodCIDRs directly. This results in better performance and eliminates MTU concerns, but it requires a network that is aware of all pod IPs typically achievable in on-prem setups or cloud environments."),"\n",s.createElement("a",{id:"is-aws-eni-considered-a-form-of-native-routing-in-cilium"}),"\n",s.createElement(n.h2,null,"Is AWS ENI is considered a form of native routing in Cilium?"),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 1008px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/f48efeee025b423b3b8230054e41f851/b8260/aws-cilium-architecture.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 56.34920634920635%; position: relative; bottom: 0; left: 0; background-image: url(\'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAAsTAAALEwEAmpwYAAACfklEQVR42n2RS08TURiG58/owsTERBPjZeXGtW7duvIvaIy
1QGImC4CVRE0JUEjDeEkFukSgCkWtb2k4v007bmTlz6XRa2kIo0AKPpwg7dfHkvF/eOe/5vm8UkQoTTPQRTPbh/xjAXZ0kGH8s6ycU54bxFj4f6mCiF29phOLM2z/fjz3CCX2j9L2fYOoppanniGwCxZt7x869E+x2nGSr9wqVj7dpPThDq/sC9f4b1F7fpNVzkVbXWaqDt9h8cY3mo/M0758m+HSXRvdldrsvsd15Cnd5HMVxbERyBT00i5kMY+hZCtFfZFZlnUlgZJLkI/Nk276extTiaNIrxBYxcllMVd4NzyPURWzXQ7GDOnapQr5YIy888pZLzvbRreJhXZBohouataSWnuWRlehC+pZDTp6mG+CVazhBFaW4NMpu1zmqiTlwEmCrkvgRbR2jJaJsGWHpxw/rYw7ap/QORIz9wipFs4CiRVdQP/Rg6yn2F96w8+wqrZ8vaX65w86r6/JihOj0EOrEEE03Qz0XIVeIUs6G2Tai4CY5cFOHDfjCRMl7VbSgie8ISE6yOdrJXnyM5sIgm+NdsqsY6uxXkjPj4KVoWXE2hcqOGWdPyImcpEQGyi6LwkCxvDKWX6No5KmkI9Rtg3IuSc3I0HAN+bpGw0hQ0+VYTpo9Oy1HTbMv2ROpI6Q2VRlooZgy0JQ/xHUtqnaYDS9KXlvBlztp63V7jUCs4RltL07Njf0dZw3HE8eBdUqlDOvONGxHGB3p4f3wQ4YGOogvD9NYX6a5sQyN1X8Qgq1FfD93FCj3aMt0Ry428DUsI0RWD6FnVvAclUqQoVLSKP8PP4XwHH4Dm+cB0cLguOQAAAAASUVORK5CYII=\'); background-size: cover; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/f48efeee025b423b3b8230054e41f851/2ff5b/aws-cilium-architecture.webp 252w,\n/static/f48efeee025b423b3b8230054e41f851/4d583/aws-cilium-architecture.webp 504w,\n/static/f48efeee025b423b3b8230054e41f851/905a7/aws-cilium-architecture.webp 1008w,\n/static/f48efeee025b423b3b8230054e41f851/bb9f8/aws-cilium-architecture.webp 1512w,\n/static/f48efeee025b423b3b8230054e41f851/0be2b/aws-cilium-architecture.webp 1848w"\n              sizes="(max-width: 1008px) 100vw, 1008px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/f48efeee025b423b3b8230054e41f851/019e0/aws-cilium-architecture.png 252w,\n/static/f48efeee025b423b3b8230054e41f851/0dcb2/aws-cilium-architecture.png 504w,\n/static/f48efeee025b423b3b8230054e41f851/832a9/aws-cilium-architecture.png 1008w,\n/static/f48efeee025b423b3b8230054e41f851/19357/aws-cilium-architecture.png 1512w,\n/static/f48efeee025b423b3b8230054e41f851/b8260/aws-cilium-architecture.png 1848w"\n            sizes="(max-width: 1008px) 100vw, 1008px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/f48efeee025b423b3b8230054e41f851/832a9/aws-cilium-architecture.png"\n            alt="alt text"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",s.createElement(n.p,null,"Yes! AWS ENI is implemented via a specialized Cilium datapath optimized for AWS VPC’s native capabilities. Cilium delegates packet forwarding to the underlying network (or routing layer) rather than using encapsulation like VXLAN or Geneve. AWS ENI fits this model because Pod IPs are directly routable within the AWS VPC, they are allocated from the ENI IP ranges that are natively integrated into the AWS network. The AWS VPC acts as the native network that routes packets between ENIs across nodes. This model simplifies communication of pod traffic within VPCs and avoids the need for SNAT."),"\n",s.createElement(n.h2,null,"Conclusion"),"\n",s.createElement(n.p,null,"In this two-part series, we explored how to deploy Cilium on EKS using different networking modes—starting with ENI mode, and now wrapping up with overlay (BYOCNI) and CNI chaining modes. Each mode offers distinct advantages depending on your infrastructure needs. As you evaluate which deployment mode best fits your environment, understanding the trade-offs between encapsulation and native routing helps you make informed decisions that align with your goals on EKS."),"\n",s.createElement(n.h2,null,"Additional Resources"),"\n",s.createElement(n.ul,null,"\n",s.createElement(n.li,null,s.createElement(n.a,{href:"https://www.youtube.com/watch?v=kurMo3r4Ol4"},"eCHO Episode 106: Live Migration to Cilium in AWS")),"\n",s.createElement(n.li,null,s.createElement(n.a,{href:"https://www.youtube.com/watch?v=A91iQS0F9Ug"},"Life of a packet with Cilium in EKS in CNI chain mode")),"\n",s.createElement(n.li,null,s.createElement(n.a,{href:"https://docs.cilium.io/en/latest/installation/cni-chaining-aws-cni/"}
1,"AWS VPC CNI plugin - Cilium Docs")),"\n",s.createElement(n.li,null,s.createElement(n.a,{href:"https://docs.cilium.io/en/latest/network/concepts/routing/#aws-eni-datapath"},"AWS ENI - Cilium Docs")),"\n",s.createElement(n.li,null,s.createElement(n.a,{href:"https://docs.cilium.io/en/latest/network/concepts/routing/#aws-eni-datapath"},"Routing - Cilium Docs")),"\n",s.createElement(n.li,null,s.createElement(n.a,{href:"https://docs.cilium.io/en/stable/helm-reference/"},"Helm Reference")),"\n"),"\n",s.createElement(a,l.A.PaulArah))}var o=function(e){void 0===e&&(e={});const{wrapper:n}=Object.assign({},(0,t.RP)(),e.components);return n?s.createElement(n,e,s.createElement(i,e)):i(e)};var r=a(8125),c=a(5805),u=a(8838),p=a(2744);const d=e=>{const{data:{mdx:n},children:a}=e,{frontmatter:{path:t,title:l,date:i,tags:o,ogSummary:u}}=n;return s.createElement(p.A,{headerWithSearch:!0},s.createElement(r.A,{path:t,content:a,date:i,title:l,tags:o,summary:u}),s.createElement(c.A,{className:"my-10 md:my-20 lg:my-28"}))},m=e=>{var n,a;let{data:{mdx:t,site:l},location:{pathname:i}}=e;const{frontmatter:{title:o,ogImage:r,ogSummary:c,dateIso:p,tags:d,author:m}}=t,{siteUrl:h}=l.siteMetadata,g=`${c.slice(0,133)}...`,k=`${h}${i}`,b=null!=r&&null!==(n=r.childImageSharp)&&void 0!==n&&null!==(a=n.resize)&&void 0!==a&&a.src?`${h}${r.childImageSharp.resize.src}`:null,y={title:o,description:g,image:r||null,slug:i},f={"@context":"https://schema.org","@type":"BlogPosting",headline:o,description:g,url:k,datePublished:p,dateModified:p,author:m?{"@type":"Person",name:m}:{"@type":"Organization",name:"Cilium",url:h},publisher:{"@type":"Organization",name:"Cilium",url:h,logo:{"@type":"ImageObject",url:`${h}/images/social-preview.jpg`}},...b&&{image:{"@type":"ImageObject",url:b,width:1200,height:630}},...(null==d?void 0:d.length)>0&&{keywords:d.join(", ")}};return s.createElement(u.A,{data:y,type:"article",datePublished:p,jsonLd:f})};function h(e){return s.createElement(d,e,s.createElement(o,e))}}}]);
2//# sourceMappingURL=component---src-templates-blog-post-jsx-content-file-path-src-posts-2025-07-06-eks-byonci-overlay-install-index-md-973be393e9cc52d66467.js.map

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.