VOOZH about

URL: https://thenewstack.io/beyond-kube-proxy-tigera-calico-harnesses-ebpf-for-a-faster-data-plane/

⇱ Beyond Kube-Proxy: Project Calico Harnesses eBPF for a Faster Data Plane - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2020-03-17 08:36:57
Beyond Kube-Proxy: Project Calico Harnesses eBPF for a Faster Data Plane
news,
Cloud Native Ecosystem / Kubernetes / Networking

Beyond Kube-Proxy: Project Calico Harnesses eBPF for a Faster Data Plane

Thanks to the power of the newly-introduced eBPF in the Linux kernel, Tigera has been able to outfit its Kubernetes-focused Calico network management software with a new data plane mode, one that can speed pod-to-pod data communication and eliminate the dependency on Kubernetes' kube-proxy for traffic management.
Mar 17th, 2020 8:36am by Joab Jackson
👁 Featued image for: Beyond Kube-Proxy: Project Calico Harnesses eBPF for a Faster Data Plane

Thanks to the power of the newly-introduced eBPF in the Linux kernel, Tigera has been able to outfit its Kubernetes-focused Calico network management software with a new data plane mode, one that can speed pod-to-pod data communication and eliminate the dependency on Kubernetes’ kube-proxy for traffic management.

Tigera had started releasing work with eBPF almost a year ago, but this is the first release of Calico that fully harnesses the power of the new Linux kernel technology, Alex Pollitt, Tigera co-founder and chief technology officer, said.

“We wanted to derive what we were doing from fundamentals, to be confident we were building the right thing for users,” said Pollitt. “We looked at every networking building block in the Linux kernel, understood how they worked, how they interacted.”

The new data plane will be offered as an option alongside the traditional Calico data plane. Those organizations using a new version of Linux kernel (preferably 4.8 or newer) will be able to take advantage of the new solution, Pollitt said. In particular, organizations, where performance is a top priority, should test this release, he said. The new eBPF data-plane mode, available as a tech review, can both scale to a higher throughput while using less CPU per GBit.

Currently, over 150,000 Kubernetes clusters run Calico, including not only bare-metal implementations but those running across Amazon Web Services, Azure and Google Cloud. Originally created for OpenStack, Calico was designed to make it easy to get data packets from one part of the network to another, using internet technologies like IP routing, rather than switching, virtual networks, overlay networks or other complex approaches.

Anticipating containers, Calico was designed for very dynamic environments and can manage hundreds of thousands of end-points that can change the location at any time. Calico meshes very well with Google’s Zero Trust Security model, which assumes networks and hosts will be breached, and so limits the amount of damage that can be done.

Enter eBPF

👁 Image

Click to embiggen.

The eBPF (extended Berkeley Packet Filter), a recent introduction to the Linux kernel, is a virtual machine inside the kernel that provides advanced, high-speed extensible network packet filtering. Work that used to be done by an external module can be executed, much more quickly, by the kernel itself.

For Calico, eBPF provided the tools to hasten data traffic while reducing the networking complexity of high-end Kubernetes deployments. Use of this data plane eliminates the need for kube-proxy, Kubernetes’ built-in network proxy that handles load balancing through iptables. Although fine for everyday use, kube-proxy doesn’t scale well as the number of services that are mapped in iptables grow. It requires IPVS (IP Virtual Server) to effectively scale for thousands of services.

👁 Image
The Calico data plane offers a similar scalable performance as IPVS, by way of a more efficient lookup map, but without the need of kube-proxy at all. It reduces first packet latency to servers, which would lead to a noticeable improvement in environments with lots of provisioned services are constantly spun up. The in-kernel functionality reduces the CPU overhead. The data plane preserves external client source IP addresses all the way to the pod (great for troubleshooting), and also supports DSR (Direct Server Return), in which the return traffic doesn’t need to loop back through the original ingress.

The newly released Calico version 3.13 also includes an auto-detection capability to detect the IP address range used for pods when running on kubeadm. Calico v3.13 will be available in Calico Enterprise v2.8.

The folks at Calico will explain this technology in more detail today, March 17, on a Cloud Native Computing Foundation webinar at 10:30 a.m. PDT.

The Cloud Native Computing Foundation is a sponsor of  The New Stack.

TRENDING STORIES
Joab Jackson is a senior editor for The New Stack, covering cloud native computing and system operations. He has reported on IT infrastructure and development for over 30 years, including stints at IDG and Government Computer News. Before that, he...
Read more from Joab Jackson
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Tigera.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.