M2 · VPC-native networking
Cilium and eBPF
14 / 61

Dataplane V2 turns Kubernetes intent into eBPF programs

GKE deploys anetd on each node. It interprets Services and NetworkPolicies, then programs eBPF for routing, load balancing and enforcement.

1Watch objectsanetd observes Services, Endpoints and policies.
2Compile intentRules are translated into efficient data-plane state.
3Program kerneleBPF handles packets without long iptables chains.
4Route and enforceService translation and policy occur in the node kernel.
5Export evidenceLogging can report policy decisions and dropped traffic.
Dataplane V2 is implemented with Cilium, but GKE owns the supported configuration surface.