Cilium Readiness And CNI Ownership
Cilium is not just a CNI swap. It changes the cluster datapath, policy engine, observability surface, and sometimes kube-proxy ownership. Before treating it as production-ready, prove the network contract rather than stopping at Running pods. Define Ownership First Write down what owns each layer: cluster bootstrap -> installs the selected CNI once Cilium operator -> reconciles Cilium configuration and identities Cilium agents -> enforce datapath and policy on each node kube-proxy -> enabled, replaced, or intentionally absent platform team -> node routing, firewall, MTU, upgrades, and rollback app teams -> service labels, ports, and policy intent Do not let RKE2, Helm, GitOps, and manual manifests all believe they own CNI installation. One owner should install and upgrade the datapath. ...