Introduction to Cilium
Workshop

A Service is unreachable, Hubble shows a drop, and the policy looks correct at first glance. Without a shared model for CNI, identities, Service paths, and the implemented datapath, teams quickly produce assumptions instead of reliable findings. The workshop therefore connects installation, access control, and diagnostics in one continuous workflow. It is designed for platform engineers, Kubernetes engineers, administrators, and cloud native network engineers who evaluate, introduce, or operate Cilium. Practical Kubernetes and networking fundamentals are required. Prior knowledge of Cilium, Hu

Made in Germany ISO 27001 ISO 9001 DSGVO-konform DORA Compliant 24/7 Support
UDSVolkswagenLiebherrT-SystemsVendureecoConnextPortainerBITMARCKUelzener VersicherungenFJDDWTOCCReiner SCTCyrus IndustrialDGSIEMnanocosmosInheadenSplixSchwarzgruppeINHHadesHiOrg-Serverown3dTikfinityProgram51Buben & MädchenPrime InsightsTELTECElevantiqMoovitCFToolsStadt KölnVivavisAvemio

Workshop overview

Duration, per-participant price and logistics for Introduction to Cilium.

On-site options

  • Live online or on-site at your location

  • In-house: content, duration and focus can be tailored

  • Flexible dates, from 1 participant

  • German; English on request

  • Preconfigured cloud lab (also on-site)

  • Open groups: max. 8 people

  • Seat price same as online: €721.50 × days, excl. VAT

  • On-site in-house: individual quote (travel/logistics as incurred)

  • No published flat on-site surcharge

  • You provide the training room and internet

  • Open sessions: 09:00–16:00 (CET/CEST)

Curriculum

Topics by day at a glance.

Day 1: Position and install Cilium, then make network flows visible

  • Position Cilium in Kubernetes Networking
  • Choose Installation Values and Install Cilium
  • Trace Pod and Service Paths
  • Verify Network Flows with Hubble
  • Validate Cilium with Connectivity Tests
Day 1

Day 2: Restrict network access step by step and prove its effect

  • Introduce Default Deny Safely
  • Implement Identity-Based Cilium Rules for L3/L4
  • Restrict DNS and FQDN Egress
  • Restrict HTTP Access at L7
  • Isolate Policy Errors with Hubble
Day 2

Day 3: Evaluate operational options and diagnose Cilium faults systematically

  • Trace kube-proxy Replacement in the Datapath
  • Encrypt Cross-Node Traffic Transparently with WireGuard
  • Capture Operational Signals and Diagnostic Data
  • Trace Cilium Faults Down to eBPF
  • Resolve a Complete Cilium Incident
Day 3

Workshop schedule

Published daily rhythm. Topics are listed in the curriculum.

09:00–16:00 (CET/CEST)

Official window for open sessions.

Frame

09:00 – Introductions

On day 1: meet the instructor and participants, plus the agenda and workshop structure.

Day 1

09:00 – Q&A

On later days, resolve open questions from the previous day before the day’s topics (usually 09:00–09:30 or 09:00–10:00).

Later days

Content blocks follow the curriculum

Theory and hands-on in the morning and afternoon blocks. The topic list is in the curriculum above.

Topics

12:00–13:00 – Lunch

A shared break before the afternoon.

Break

16:00–16:30 – Q&A

End of the day: questions, exchange and wrap-up.

Close

Prerequisites

What participants should bring.

Hardware

Your own notebook (Linux, macOS or Windows) with permission to install software. Devices available at extra cost.

HardwareNotebook

Environment

Each participant works in a provided cloud lab. Local installation of the training stack is not required.

LabCloud

Prerequisites

Basic Linux/terminal skills are helpful.

Prerequisites

Related workshops

Suggested follow-on courses from the catalog.

Introduction to Gateway API

  • Duration: 3 days