PageSourceSearch

https://cilium.io/component---src-templates-blog-post-jsx-content-…-balancing-index-md-659d73e33e36ae744a69.js

js cilium.io collected 2026-09-24 08:26:46 UTC 36,394 bytes, 2 lines download raw bytes

1"use strict";(self.webpackChunkcilium_io=self.webpackChunkcilium_io||[]).push([[2829],{6452:function(e,a){a.A={thomasGraf:{header:"Thomas Graf",bio:'Thomas Graf is a Co-Founder of Cilium and the CTO & Co-Founder of <a href="https://isovalent.com/?utm_source=website-cilium&utm_medium=referral&utm_campaign=cilium-enterprise">Isovalent</a>, the company behind Cilium. Before that, Thomas spent 15 years as\n    a kernel developer working on the <a href="https://kernel.org">Linux kernel</a> in networking, security and eventually eBPF.'},lizRice:{header:'<a href="https://twitter.com/lizrice">Liz Rice</a>',bio:'Liz is Chief Open Source Officer at <a href="https://isovalent.com/?utm_source=website-cilium&utm_medium=referral&utm_campaign=cilium-enterprise" target="_blank" rel="noopener noreferrer">Isovalent</a>, the company behind Cilium. She is also chair of the CNCF\'s Technical Oversight Committee, and the author of Container Security published by O\'Reilly.'},luanGuimaraes:{header:"Luan Guimarães",bio:"Luan is a Brazilian rock climber, amateur musician, and\n   programmer and am enthusiastic about free software communities and other\n   open knowledge initiatives. He has been working as a Site Reliability\n   Engineer at Wildlife Studios, using and building infrastructure tools on\n   top of Kubernetes in order to support millions of users around the world."},joshVanLeeuwen:{header:"Josh Van Leeuwen",bio:"Josh interned at Jetstack during the summer of 2017 before continuing to\n    work part time during his final year of study at the University of Bristol.\n    During this year, Josh developed a Kubernetes custom controller that\n    automates the delegation of RBAC permissions based on time and event\n    triggers. This work was later awarded the best Software Development Tool\n    Final Year Project. Josh now works full time at Jetstack where if he’s not\n    writing more Go, he’s making good food."},howardHao:{header:"Howard Hao",bio:" Howard Hao has been working as a Site Reliability Engineer for five years at\n    Ect888.com since graduating from Shanghai Jiao Tong University. His team\n    consists of 7 members and has been focusing on the construction of\n    container orchestration platform like Kubernetes for one and a half years."},sergeyGeneralov:{header:"Sergey Generalov",bio:"Sergey is a member of the technical staff at Isovalent\n    and focuses on helping Cilium users solve challenges related\n    to network policies, monitoring, and connectivity troubleshooting\n    by building tools like Network Policy Editor, Hubble UI and more."},liWenquan:{header:"Li Wenquan",bio:"Hello everyone, I am Li Wenquan from China. You can call me David. I\n    started my Docker journey from 2014 and now work as a project manager of\n    enterprise container platform, which is built on Kubernetes and Mesos. I\n    got to know Cilium project from Kubecon, it is so interesting and\n    promising. I've learned a lot from it, such as BPF, XDP and how to replace\n    kube-proxy in a elegant way and I'd love to contribute to it."},alexanderAlemayhu:{header:"Alexander Alemayhu",bio:"Alexander Alemayhu is a software engineer at Isovalent,\n    the company behind Cilium. He has been working on eBPF and Linux\n     kernel technologies for several years, focusing on networking and observability solutions."},DanielBorkmann:{header:"Daniel Borkmann",bio:"Daniel Borkmann is a Distinguished Software Engineer, Isovalent at Cisco"},ThomasGraf:{header:"Thomas Graf",bio:"Thomas Graf is the CTO & Co-Founder Isovalent and also the Vice President Security Cisco"},JedSalazar:{header:"Jed Salazar",bio:"Jed Salazar is a Senior Solutions Architect, Isovalent"},JedSalazarandJoeStringer:{header:"Jed Salazar and Joe Stringer",bio:"Jed Salazar is a Senior Solutions Architect at Isovalent\n    and Joe Stringer is a Principal Engineer, Isovalent at Cisco"},JosephIrving:{header:"Joseph Irving",bio:"Joseph Irving is a Platform Engineer Lead at RVU (Uswitch)"},BillMulligan:{header:"Bill Mulligan",bio:"Bill Mulligan is a Cilium and eBPF Community Pollinator,\n    Isovalent at Cisco and a Governing Board Member of the eBPF Foundation."},OndrejBlazek:{header:"Ondrej Blazek",bio:"Ondrej Blazek is an Infrastru
1cture Engineer at Seznam.cz"},LeonardCohnenandMoritzEckert:{header:"Leonard Cohnen and Moritz Eckert",bio:"Leonard Cohnen and Moritz Eckert are team members at Edgeless Systems"},PolArroyo:{header:"Pol Arroyo",bio:"Pol Arroyo is a DevOps Engineer at Hetzner Cloud."},JedSalazarandMartynasPumputis:{header:"Jed Salazar and Martynas Pumputis",bio:"Jed Salazar is a Senior Solutions Architect, Isovalent and Martynas Pumputis is a Principal Software Engineer, Isovalent at Cisco"},ShedrackAkintayo:{header:"Shedrack Akintayo",bio:"Shedrack Akintayo is a Community Manager at\n    Isovalent helping build the eBPF and Cilium open source communities"},AmirKheirkhahan:{header:"Amir Kheirkhahan",bio:"Amir Kheirkhahan is a DevOps Specialist at DB Schenker handling design, development,\n     deployment and maintenance of wide range of devops toolchain on top of Kubernetes clusters"},PaulArah:{header:"Paul Arah",bio:"Paul Arah is a Community Builder focused on Security at Isovalent (Cisco)"},HimalKumar:{header:"Himal Kumar, Bhaskar Dutta, Arman Pashamokhtari",bio:"Himal Kumar, Bhaskar Dutta, Arman Pashamokhtari are all part of the\n     CanopusAI team Real Time Network Observability, powered by eBPF and Agentic AI"},DoniaChaiehloudj:{header:"Donia Chaiehloudj",bio:"Donia Chaiehloudj is a Senior Software Engineer and Community Oriented at Isovalent.\n    She has been working on Cilium and eBPF technologies, focusing on networking and security solutions."},KatieMeinders:{header:"Katie Meinders",bio:"Katie Meinders is a Community Builder at Isovalent where\n    she helps grow the Cilium and eBPF communities through storytelling,\n    social media, showcasing user success, and building connections across the open source ecosystem."},PeaceSandy:{header:"Peace Sandy",bio:"Peace Sandy is an LFX mentee who contributed to improving Cilium SEO, AEO, and\n    AIO during her mentorship period."},NehaAggarwal:{header:"Neha Aggarwal",bio:"Neha Aggarwal is a Principal Engineer at Microsoft."},CharityMbisi:{header:"Charity Mbisi",bio:"Charity Mbisi is an LFX mentee who contributed to improving Cilium's SEO, AEO, and AIO during his mentorship period.\n    Professionally, Charity Mbisi is a Software Engineer consulting in the Fin-tech and banking industry, specializing in building cloud native computing solutions and optimized service delivery."},andreMartinsAndFerozSalam:{header:"André Martins and Feroz Salam",bio:"André Martins is a Cilium maintainer and Software Engineer, Isovalent at Cisco.\n    Feroz Salam is a member of the Cilium Security Team and a Security Engineer, Isovalent at Cisco."},ChristianHernandez:{header:"Christian Hernandez",bio:"Christian is a well rounded technologist with experience in infrastructure engineering, systems administration, enterprise architecture, tech support, advocacy, and product management. Passionate about OpenSource and containerizing the world one application at a time. He is currently a maintainer of the Argo Project and OpenGitops. Currently, he works as a Technical Marketing Engineer and Tech Lead at Cisco. He focuses on GitOps practices, DevOps, Kubernetes, Network Security, and Containers."},AkilaInduranga:{header:"Akila Induranga",bio:'Akila is a Senior Software Engineer at WSO2, and a maintainer of <a href="https://openchoreo.dev/" target="_blank" rel="noopener noreferrer">OpenChoreo</a>, an open-source internal developer platform for Kubernetes and a CNCF sandbox project.\n    He works on the platform\'s observability and networking layers, including the Cilium-based networking module that brings identity-based policy and Hubble observability to OpenChoreo cells.'}}},9807:function(e,a,n){n.r(a),n.d(a,{Head:function(){return p},default:function(){return m}});var t=n(8453),i=n(6540),r=n(6452);function o(e){const a=Object.assign({h1:"h1",p:"p",h2:"h2",span:"span",h3:"h3",ul:"ul",li:"li",h4:"h4",strong:"strong",a:"a",ol:"ol"},(0,t.RP)(),e.components),{BlogAuthor:n}=a;return n||function(e,a){throw new Error("Expected "+(a?"component":"object")+" `"+e+"` to be defined: you likely forgot to import, pass, or provide it.")}("BlogAuthor",!0),i.createElement(i.Fragment,null,i.createElement(a.h1,null,"Understanding Kubernetes Load Balancing"),"\n",i.createElement(a.h1,null,"I.Introduction"),"\n",i.createElement(a.p,null,"Kubernetes Load Balancing is a means to distribute network traffic to application instances. This can be within the same cluster or different c
1ompute regions or clusters."),"\n",i.createElement(a.p,null,"To ensure proper utilization and desired performance, each healthy running instance of your application has to get a portion of the traffic. Traffic has to be distributed by load balancing between these instances; the distribution weight will depend on the algorithm."),"\n",i.createElement(a.h2,null,"Services in Kubernetes"),"\n",i.createElement(a.p,null,"Services are used to expose applications running inside the cluster behind a single outward-facing endpoint, even when the workload is split across multiple backends. This is what makes load balancing possible."),"\n",i.createElement(a.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 1008px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/871170d4ed2c664388206c69f420d020/8355f/services.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 35.714285714285715%; position: relative; bottom: 0; left: 0; background-image: url(\'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAHCAYAAAAIy204AAAACXBIWXMAAAsTAAALEwEAmpwYAAABQklEQVR42n2RXUvDMBSG96f9MV54oYi/QC9UUAQVkfmBYyiyyXTt6JImbZombZekr2lqRXbhgZcT8vGcvOeM8BNt2wb9DeuAXG6glIIxBtbaIOdcEOD8m3495BH+CVVZjF8zrFYRtNKoqwpaa0gpocoCj+8Ss0j5M4nbaQnCdQ80/iv3HxRUqADqKlkvJowHVCjLEgnlIFmJQvqHhCClCQ5PI1w8rJFnFHvHMebLHCPrrfBcYOfoBteTOUxTBYtCFNg/o/4SwyKKcDWe4uUrR5JmKIRA0zQ9OE1R11UoIIQHcs7DJiNrnykYY8FWd2m5jBHHMbS3WuoaSveWCaHgjODgnOPyqUCRM+yeZJjH6v8edtY7sNYqgIbctSDjDOPJJ95mK8hC4O55gYRwjIbpbmsAGmN/p7ut1hk420/f2U1YfwPwVheuLRyOlwAAAABJRU5ErkJggg==\'); background-size: cover; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/871170d4ed2c664388206c69f420d020/2ff5b/services.webp 252w,\n/static/871170d4ed2c664388206c69f420d020/4d583/services.webp 504w,\n/static/871170d4ed2c664388206c69f420d020/905a7/services.webp 1008w,\n/static/871170d4ed2c664388206c69f420d020/bb9f8/services.webp 1512w,\n/static/871170d4ed2c664388206c69f420d020/83a93/services.webp 2016w,\n/static/871170d4ed2c664388206c69f420d020/9c988/services.webp 2560w"\n              sizes="(max-width: 1008px) 100vw, 1008px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/871170d4ed2c664388206c69f420d020/019e0/services.png 252w,\n/static/871170d4ed2c664388206c69f420d020/0dcb2/services.png 504w,\n/static/871170d4ed2c664388206c69f420d020/832a9/services.png 1008w,\n/static/871170d4ed2c664388206c69f420d020/19357/services.png 1512w,\n/static/871170d4ed2c664388206c69f420d020/29ed2/services.png 2016w,\n/static/871170d4ed2c664388206c69f420d020/8355f/services.png 2560w"\n            sizes="(max-width: 1008px) 100vw, 1008px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/871170d4ed2c664388206c69f420d020/832a9/services.png"\n            alt="Load Balancer"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",i.createElement(a.h2,null,"Why Kubernetes Load Balancing?"),"\n",i.createElement(a.p,null,"The main goals that Load Balancing is trying to achieve are Service Reliability, Availability, and Performance (Horizontal Scalability).\nLoad balancing ensures reliability by using health checks and readiness probes to steer traffic away from failing pods. By distributing incoming requests across multiple replicas, it guarantees high availability, ensuring that the failure of a single pod or even an entire physical node does not result in application downtime."),"\n",i.createElement(a.h1,null,"II.How does Kubernetes Load Balancing Work?"),"\n",i.createElement(a.p,null,"Load Balancing in Kubernetes clusters can be split into two perspectives."),"\n",i.createElement(a.h2,null,"Types of Load Balancing"),"\n",i.createElement(a.p,null,"Not all load balancing works the same way. Different layers of the network stack offer different trade-offs between performance, intelligence, and flexibility. Understanding these distinctions helps in choosing the right approach for a given workload, whether you need raw throughput at the network edge or fine-grained routing logic at the application level."),"\n",i.createElement(a.h3,null,"Internal Load Balancing"),"\n",i.createElement(a.p,null,"Internal load balancing refers to the distribution of traffic within a Kubernetes cluster itself among pods of the same application or service.\nKubernetes uses services to implement internal load balancing. For internal load balancing services with designated cluster IPs (reachable within the cluster), fit the purpose."),"\n",i.createElement(a.p,null,"When pod A needs to talk to pod B inside the same cluster, it doesn’t use pod B’s direct IP; instead, it uses a Kubernetes service (stable virtual IP).\nBy default, Virtual IPs are managed by kube-proxy, a network agent running on each node. Kube-proxy watches the Kubernetes API for changes to Services and Endpoints and translates them into local networking rules."),"\n",i.createElement(a.p,null,"Originally, this was done using iptables, which relies on 
1sequential list processing, or IPVS, which improved performance through hash tables and advanced algorithms like Round-robin and Least Connection."),"\n",i.createElement(a.p,null,"However, as clusters scale, the overhead of managing thousands of iptables rules can degrade performance. To improve performance, Cilium can replace kube-proxy and iptables. By using eBPF, Cilium processes packets at the lowest level of the network stack without the context switching required by iptables. This provides significantly higher throughput, lower latency, and more granular security."),"\n",i.createElement(a.p,null,"While kube-proxy is limited to Layer 4 (IP/Port), Cilium can perform Layer 7 (HTTP/gRPC) load balancing and observability, providing a more identity-aware networking layer that is both faster and more resilient at scale."),"\n",i.createElement(a.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 664px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/c4e1870cf09fd09bd925daaeb27aafc5/71592/internal-load-balancing.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 52.77777777777778%; position: relative; bottom: 0; left: 0; background-image: url(\'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAAsTAAALEwEAmpwYAAABzklEQVR42qWT30sUURTH5zX6G6RAQl8CIRcqLNBkX+oppEISChV6kTR8CpalmjTMn6thYDshmRXRPti6peuvfYik2E0SLFsLH1owSl2F1mbmznycZnd0SQkWD3w58L2X7znnnu+VTNMkG3sNSdc1NFVF06ysqVsH2UUMI11o5lucnuAL/KNBfEPPmZ6fs3nDNLYFhRA4MAxj16q60O3s6fMhufLZV1GKdOQgdZ1NNq/p+rbgbgJCGKyvbZBMpljLwKrGaHSaBn8PnqcKV/0+Xr57k76f1YjU3tZKW2sLsnyTWCxqk9H3i5w93UtN1SMunlO4VPmQ5K8U47NRqrvu0Kjc43JHE4G3kZ2CZaUncLvLKC4uYnBwwCZfBWcoPOClvKSbk64OXIdllpd+c2vgPtKxAvZfcCMdPURdV/POkSORKSYnJwiHR0gkEja5EP+B9/oQzTdCyN5hWm6/Zn01xafviyhjIR5HwijjIWJfv2SWYv7/Df8NZ4u9wwEKr1RyylNPfu157gaeZJYmsm2j48DZ8l+bqKqwbJTGxh/N5uVn/UhnSsirrbDyca496E6PLPTcOnQG+plc5cPCPB8tP8bin1laWd7ybE6CufyUTcoMCpEYKPJJAAAAAElFTkSuQmCC\'); background-size: cover; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/c4e1870cf09fd09bd925daaeb27aafc5/2ff5b/internal-load-balancing.webp 252w,\n/static/c4e1870cf09fd09bd925daaeb27aafc5/4d583/internal-load-balancing.webp 504w,\n/static/c4e1870cf09fd09bd925daaeb27aafc5/884cf/internal-load-balancing.webp 664w"\n              sizes="(max-width: 664px) 100vw, 664px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/c4e1870cf09fd09bd925daaeb27aafc5/019e0/internal-load-balancing.png 252w,\n/static/c4e1870cf09fd09bd925daaeb27aafc5/0dcb2/internal-load-balancing.png 504w,\n/static/c4e1870cf09fd09bd925daaeb27aafc5/71592/internal-load-balancing.png 664w"\n            sizes="(max-width: 664px) 100vw, 664px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/c4e1870cf09fd09bd925daaeb27aafc5/71592/internal-load-balancing.png"\n            alt="Internal Load Balancing"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",i.createElement(a.h3,null,"External Load Balancing"),"\n",i.createElement(a.p,null,"External load balancing is the gateway that connects outside users to services running inside the cluster. While internal load balancing manages East-West traffic (pod-to-pod), external load balancing handles North-South traffic (internet-to-pod)."),"\n",i.createElement(a.p,null,"This is achieved through three primary methods:"),"\n",i.createElement(a.ul,null,"\n",i.createElement(a.li,null,"NodePort, which exposes a specific port on every node's IP."),"\n",i.createElement(a.li,null,"LoadBalancer, which integrates with infrastructure providers."),"\n",i.createElement(a.li,null,"Ingress, which acts as a Layer 7 smart router (handling hostnames and SSL), sits behind one of the aforementioned service types."),"\n",i.createElement(a.li,null,"Gateway API is a family of API kinds that provide dynamic infrastru
1cture provisioning and advanced traffic routing. Gateway API is the successor to Ingress. Cilium has native Gateway API support built directly into its Envoy and eBPF data path; no separate ingress controller is needed. A Gateway resource backed by Cilium gets L7 routing, native load balancing, and full Hubble observability on every request without an additional proxy in the path."),"\n"),"\n",i.createElement(a.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 1008px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/3376f4781a860565d7d465d49a490108/dabea/gateway-api.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 37.301587301587304%; position: relative; bottom: 0; left: 0; background-image: url(\'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAHCAYAAAAIy204AAAACXBIWXMAAAsTAAALEwEAmpwYAAABY0lEQVR42l2RS0/CQBSF+dkmrt35D9y5My58EBNMlIWiQiAqlKgJIFJNybSd6Tw60zYkHG9bMYTFSe+0d757bk9DphlKJcZVqusMaZZhODNoDTSEtv/a9CXGVpLlnepZf29sgEVRECSHsjmdc2RFDu9TovmUwLiClEOTGFcIuYDnG+yfEUQZXDxrHN1Z6JSAJaAkt4ZzTIKYJpFDOvuRQ3dqEEuJ71BiznSlZZRU8AXVl/2QhlsMphK3YwGVOgKSu1gaHJ530H2fg9NEoSTuPxT2ThMw6dDujXDzskDbCxDEkpyWjjOs167aJi8yrFYOsSKHTCj8MI44DLFkUeWgdM24hB8wulDgcTRB5y1AfyYQRJKcWHyFFic9WtOWm1hce65639gEwmlVsROM0NRkqSaotLXCxCASCca+wkFT0u8xuHpVOH4wMHYrlF2VQK7SOtlt/Q3kUiOMIuqxVCvEFBTXFr8ByAwJc31kCwAAAABJRU5ErkJggg==\'); background-size: cover; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/3376f4781a860565d7d465d49a490108/2ff5b/gateway-api.webp 252w,\n/static/3376f4781a860565d7d465d49a490108/4d583/gateway-api.webp 504w,\n/static/3376f4781a860565d7d465d49a490108/905a7/gateway-api.webp 1008w,\n/static/3376f4781a860565d7d465d49a490108/24f1e/gateway-api.webp 1080w"\n              sizes="(max-width: 1008px) 100vw, 1008px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/3376f4781a860565d7d465d49a490108/019e0/gateway-api.png 252w,\n/static/3376f4781a860565d7d465d49a490108/0dcb2/gateway-api.png 504w,\n/static/3376f4781a860565d7d465d49a490108/832a9/gateway-api.png 1008w,\n/static/3376f4781a860565d7d465d49a490108/dabea/gateway-api.png 1080w"\n            sizes="(max-width: 1008px) 100vw, 1008px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/3376f4781a860565d7d465d49a490108/832a9/gateway-api.png"\n            alt="Gateway API"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",i.createElement(a.p,null,'For users not running in a cloud environment, such as those on bare metal or on-premises data centers, Kubernetes does not have a native "out-of-the-box" load balancer implementation.'),"\n",i.createElement(a.p,null,'In these cases, tools like Cilium Load Balancer and MetalLB are used, acting as a software-defined load balancer that monitors the cluster and assigns a virtual IP (VIP) from a pre-configured range to the service. It then uses standard network protocols like ARP (Layer 2) or BGP (Layer 3) to announce to the local network that the service is reachable at that specific IP.\nThis allows local environments to have the same "Type: LoadBalancer" experience as cloud users without relying on a cloud provider\'s hardware.'),"\n",i.createElement(a.h2,null,"Layers of Kubernetes Load Balancing"),"\n",i.createElement(a.p,null,"In Kubernetes, load balancing happens across distinct layers of the OSI model, depending on where traffic originates and what information is needed to route it."),"\n",i.createElement(a.h3,null,"Data Link Layer: L2-Aware Load Balancers"),"\n",i.createElement(a.p,null,"The Data Link layer is the second layer of the OSI model, responsible for node-to-node data transfer between directly connected devices."),"\n",i.createElement(a.p,null,"L2-Awareness allows Kubernetes services to be reachable via Address Resolution Protocol (ARP) for IPv4 or Neighbor Discovery Protocol (NDP) for IPv6. Using a feature like Cilium L2 Announcements, a leader node responds to network queries by broadcasting its own MAC address as the destination for a Service's Virtual IP. This bridges the gap between the physical switch and the virtual cluster, making services visible on the local area network (LAN) without requiring complex rout
1ing protocols like BGP."),"\n",i.createElement(a.p,null,"Before Kubernetes can distribute traffic to pods, the external network must first know which physical node in the cluster owns the Service IP. In cloud environments, this is handled by the provider’s Software Defined Network. However, in on-premises or bare-metal environments, the cluster must manage its own physical identity."),"\n",i.createElement(a.h4,null,"L2-Aware Load Balancing and Service Announcement in Cilium"),"\n",i.createElement(a.p,null,"L2-Aware Load Balancer introduces the ability for Kubernetes services to be reachable via Address Resolution Protocol (ARP) announcements. L2 Announcements is a feature that makes services visible and reachable on the local area network. This feature is primarily intended for on-premises deployments within networks without BGP-based routing, such as office or campus networks or home labs."),"\n",i.createElement(a.p,null,"When used, this feature will respond to ARP/NDP queries for ExternalIPs and/or LoadBalancer IPs. These IPs are Virtual IPs (not installed on network devices) on multiple nodes, so for each service, one node at a time will respond to ARP/NDP queries and respond with its MAC address. This node will perform load balancing with the service load balancing feature, thus acting as a north/south load balancer. To use this mode, Kube-proxy Replacement must be enabled."),"\n",i.createElement(a.p,null,i.createElement(a.strong,null,"Failover and Availability"),'\nTo ensure that external traffic always has a reliable path into the cluster, Cilium implements an automated Failover mechanism. Since local networks typically associate a single Service IP with a single physical node at any given time, Cilium must ensure there is always one "active" responder while preventing conflicts where multiple nodes try to claim the same traffic.'),"\n",i.createElement(a.p,null,i.createElement(a.strong,null,"L2 Pods Announcements"),"\nLayer 2-pod announcement is a means that allows individual pods to be directly visible on the local network by assigning each pod an IP address from the local network range and broadcasting its presence to the physical switch."),"\n",i.createElement(a.p,null,"Read More: ",i.createElement(a.a,{href:"https://docs.cilium.io/en/stable/network/l2-announcements/"},"https://docs.cilium.io/en/stable/network/l2-announcements/")),"\n",i.createElement(a.h3,null,"Transport Layer: L4 Load Balancers"),"\n",i.createElement(a.p,null,"The transport layer is the fourth layer of the OSI model, responsible for managing end-to-end communication, flow control, segmentation, and error correction between host systems."),"\n",i.createElement(a.p,null,"Once a packet has physically reached a node, Layer 4 load balancing determines which specific pod should receive it based on IP addresses and TCP/UDP ports. L4 load balancers are highly efficient because they do not inspect the data inside the packet; they simply forward traffic based on the connection header."),"\n",i.createElement(a.p,null,"In Kubernetes, standard ClusterIP and LoadBalancer services operate at this layer. Traditionally managed by kube-proxy using iptables or IPVS, modern CNIs like Cilium now handle this via eBPF. This allows for high-performance North-South (external to internal) and East-West (pod to pod) distribution with minimal latency."),"\n",i.createElement(a.h3,null,"Application Layer: L7 Load Balancers"),"\n",i.createElement(a.p,null,"The application layer is the top-most layer of the OSI model, which is a direct interface between end-user applications and the network."),"\n",i.createElement(a.p,null,"Layer 7 Load Balancers operate using application contexts, including HTTP headers, URL paths, or gRPC methods. This allows advanced routing such as sending /api traffic to one set of pods and /web traffic to another. Ingress controllers and Application Load Balancers operate here."),"\n",i.createElement(a.h1,null,"III. Cilium Standalone XDP L4 Load Balancer"),"\n",i.createElement(a.p,null,"XDP (eXpress Data Path) is a high-performance packet processing framework built on eBPF. Traditional load balancers process packets after the kernel has already done significant work; interrupts, buffer allocation, and traversing firewall chains. XDP skips all of that by intercepting packets as early as possible, before any of that overhead kicks in."),"\n",i.createElement(a.p,null,"The Cilium XDP L4LB comes with full IPv4/v6 dual-stack support that can be deployed and programmed 
1independently of Kubernetes."),"\n",i.createElement(a.p,null,"Read More: ",i.createElement(a.a,{href:"https://cilium.io/blog/2022/04/12/cilium-standalone-L4LB-XDP/"},"https://cilium.io/blog/2022/04/12/cilium-standalone-L4LB-XDP/")),"\n",i.createElement(a.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 1008px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/b582c396be19ef64c24682a0cd710d47/c2c3c/xdp.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 75.3968253968254%; position: relative; bottom: 0; left: 0; background-image: url(\'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAPCAYAAADkmO9VAAAACXBIWXMAAAsTAAALEwEAmpwYAAABwElEQVR42p2Ua3OyMBCF+///2vuhyox4F5GrioJyk0A49Wwbp7bFD+/O7GQTNg9nw4a3qqrQdR3atn1yrp3PZ+z3exwOB0RRhDAMJf6Zr5QCzfd9vJnJX3a5XB4QgulZlv3K6/texjiOn4Faa1yvV9lEGGOq+W5lWeJ4PCJNU4lfArmZsl3XFTVBEIBHYl5Gy/Mcu91OnPFLIDczcb1eCzRJElFjVD
1I3DAO42614FIXiTdMMA7noeR6Wy6WopVKjrlEtvDCG6wWwZ0s4Ox+7IMKtUcNAQjabjaikWiY9zrGrgXQBdbBR+iOo/UTmvSpfAwlbLBZSNpO0/gT2WkEXEZrMRxavcMs8mffdQMlFUUi5q9UKtm0LkG1jFPZtjT6ZIffekTr/UPlj9Mcp9JBCAgnh+RHoOI4ofgB1C12d0OQHFOdARl0ld4Xq/4DNvbRpNMfItfDujDHeWrCjGer29jeQfUXIdDrFaDSS0vlhDFD3GtW9vKopP8cv777OWICmh2h1XUvf8QHvLuPT6SRANq9p4J9m2op7fpVMhZPJBJZlYT6fP5U8ZE83hV/R3Aj+BLhofgSM6Xz2yrmPd5vn/gHuonvENQxjFQAAAABJRU5ErkJggg==\'); background-size: cover; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/b582c396be19ef64c24682a0cd710d47/2ff5b/xdp.webp 252w,\n/static/b582c396be19ef64c24682a0cd710d47/4d583/xdp.webp 504w,\n/static/b582c396be19ef64c24682a0cd710d47/905a7/xdp.webp 1008w,\n/static/b582c396be19ef64c24682a0cd710d47/27c85/xdp.webp 1061w"\n              sizes="(max-width: 1008px) 100vw, 1008px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/b582c396be19ef64c24682a0cd710d47/019e0/xdp.png 252w,\n/static/b582c396be19ef64c24682a0cd710d47/0dcb2/xdp.png 504w,\n/static/b582c396be19ef64c24682a0cd710d47/832a9/xdp.png 1008w,\n/static/b582c396be19ef64c24682a0cd710d47/c2c3c/xdp.png 1061w"\n            sizes="(max-width: 1008px) 100vw, 1008px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/b582c396be19ef64c24682a0cd710d47/832a9/xdp.png"\n            alt="XDP"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",i.createElement(a.h2,null,"How Cilium Implements XDP L4LB"),"\n",i.createElement(a.p,null,'In a Cilium-managed cluster, the XDP load balancer operates as a "stand-alone" or "integrated" gateway. When an external packet destined for a Service IP hits the node:'),"\n",i.createElement(a.ol,null,"\n",i.createElement(a.li,null,"XDP Hook: The eBPF program attached to the NIC intercepts the packet."),"\n",i.createElement(a.li,null,"Maglev Lookup: Cilium uses a consistent hashing algorithm (Maglev) to select a backend Pod, ensuring that traffic from the same flow always hits the same destination.\nKubernetes service load balancing implemented by Cilium or Kube-proxy selects backends randomly and ensures that the traffic remains sticky to that backend. In the case of node failure, the upstream load balancer selects a different load balancing node that has no context of the failed node. This can lead to an unexpected disruption on connection oriented protocols.\nMaglev consistent hashing minimizes such disruption by ensuring each load-balancing node has a consistent view and ordering of the backend lookup table."),"\n",i.createElement(a.li,null,"Encapsulation/DSR: The packet is either encapsulated (VXLAN/Geneve) or sent via Direct Server Return (DSR) to the target node."),"\n",i.createElement(a.li,null,"XDP_TX: The modified packet is sent back out the same interface immediately, completely bypassing the host's networking stack. XDP_TX is an XDP action that involves TX bouncing the received packet page back out the same NIC it arrived on."),"\n"),"\n",i.createElement(a.p,null,"Read More: ",i.createElement(a.a,{href:"https://cilium.io/blog/2022/04/12/cilium-standalone-L4LB-XDP/"},"https://cilium.io/blog/2022/04/12/cilium-standalone-L4LB-XDP/")),"\n",i.createElement(a.h2,null,"Operating Modes"),"\n",i.createElement(a.p,null,"L4 Load Balancers work in two modes:"),"\n",i.createElement(a.h3,null,"Passthrough Mode"),"\n",i.createElement(a.p,null,"Packets are forwarded without inspecting application data, and the same TCP connection is used from the client to the backend. There is no connection termination in L4 LB. Connections are terminated by backend servers, and responses from backend servers are sent directly to clients with Direct Server Return (DSR). Pass-through LoadBalancers can not terminate SSL certificates."),"\n",i.createElement(a.h3,null,"Proxy Mode"),"\n",i.createElement(a.p,null,"In this operating mode, the load balancer terminates a connection from the client and initiates a different c
1onnection to the downstream service. In proxy mode, the Load Balancer fully handles the TCP handshake, resulting in more flexibility for routing decisions to destinations."),"\n",i.createElement(a.h1,null,"IV. Summary"),"\n",i.createElement(a.p,null,"Kubernetes load balancing is a critical architecture for managing traffic across ephemeral, scaled application instances. By decoupling fixed service endpoints from transient pod IP addresses, it ensures Service Reliability, High Availability, and Performance."),"\n",i.createElement(a.p,null,"To achieve production-grade resilience, these layers use health checks and automated failover mechanisms. Whether through traditional proxy modes or high-performance passthrough with Direct Server Return (DSR) and Maglev consistent hashing, Kubernetes load balancing ensures that network traffic is distributed predictably and efficiently across the entire cluster lifecycle."),"\n",i.createElement(a.p,null,"Cilium redefines this stack by replacing legacy components like kube-proxy and iptables with a unified, eBPF-native data path. This shift provides three distinct advantages across the networking layers ",i.createElement(a.strong,null,"Foundation (L2/L3)")," Cilium bridges the gap for on-premises and bare-metal environments, ",i.createElement(a.strong,null,"Performance (L4/XDP)")," By leveraging XDP (eXpress Data Path), Cilium processes packets at the earliest possible point in the network driver and ",i.createElement(a.strong,null,"Intelligence (L7/Ingress)"),", At the application level, Cilium provides identity-aware routing."),"\n",i.createElement(n,r.A.CharityMbisi))}var s=function(e){void 0===e&&(e={});const{wrapper:a}=Object.assign({},(0,t.RP)(),e.components);return a?i.createElement(a,e,i.createElement(o,e)):o(e)};var l=n(8125),c=n(5805),d=n(8838),h=n(2744);const u=e=>{const{data:{mdx:a},children:n}=e,{frontmatter:{path:t,title:r,date:o,tags:s,ogSummary:d}}=a;return i.createElement(h.A,{headerWithSearch:!0},i.createElement(l.A,{path:t,content:n,date:o,title:r,tags:s,summary:d}),i.createElement(c.A,{className:"my-10 md:my-20 lg:my-28"}))},p=e=>{var a,n;let{data:{mdx:t,site:r},location:{pathname:o}}=e;const{frontmatter:{title:s,ogImage:l,ogSummary:c,dateIso:h,tags:u,author:p}}=t,{siteUrl:m}=r.siteMetadata,g=`${c.slice(0,133)}...`,b=`${m}${o}`,f=null!=l&&null!==(a=l.childImageSharp)&&void 0!==a&&null!==(n=a.resize)&&void 0!==n&&n.src?`${m}${l.childImageSharp.resize.src}`:null,y={title:s,description:g,image:l||null,slug:o},w={"@context":"https://schema.org","@type":"BlogPosting",headline:s,description:g,url:b,datePublished:h,dateModified:h,author:p?{"@type":"Person",name:p}:{"@type":"Organization",name:"Cilium",url:m},publisher:{"@type":"Organization",name:"Cilium",url:m,logo:{"@type":"ImageObject",url:`${m}/images/social-preview.jpg`}},...f&&{image:{"@type":"ImageObject",url:f,width:1200,height:630}},...(null==u?void 0:u.length)>0&&{keywords:u.join(", ")}};return i.createElement(d.A,{data:y,type:"article",datePublished:h,jsonLd:w})};function m(e){return i.createElement(u,e,i.createElement(s,e))}}}]);
2//# sourceMappingURL=component---src-templates-blog-post-jsx-content-file-path-src-posts-2026-04-25-understanding-kubernetes-load-balancing-index-md-659d73e33e36ae744a69.js.map

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.