Netkit: eBPF Datapath Closes the Container Networking Performance Gap
Netkit is an eBPF-based Linux datapath that eliminates redundant queue traversals, boosting container network throughput up to 37% with Cilium/Kubernetes.
Cloud-native microservices rely on Linux network namespaces for isolation, but the overhead of crossing namespace boundaries remains a persistent performance bottleneck. Colocating containers on the same host reduces this cost somewhat, yet it still can't match the speed of communication within a single namespace. Prior fixes have either forced application rewrites or sacrificed support for the full Linux networking stack containers expect.
Netkit is an eBPF-based datapath, implemented in the Linux kernel, that specializes the networking stack to eliminate redundant backlog queue traversals during namespace transitions. It transparently redirects packets between namespaces, skipping unnecessary buffering while remaining fully compatible with existing containerized applications—no code changes required.
Integrated into Kubernetes via minimal changes to the Cilium network plugin, netkit delivers up to 37% higher throughput and brings container-to-container communication to parity with process-to-process communication. For engineers running Kubernetes clusters with Cilium, this effectively erases the performance penalty traditionally imposed by network namespace isolation.
This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work