Where Does Cilium Store State?
Where Cilium keeps state on Linux nodes, eBPF maps plus etcd roles. Exact folders are covered below.
Last updated
Cilium is eBPF networking with etcd backed state. Your identities, policies, and endpoints live in etcd plus agent maps. Nodes rebuild maps from etcd on restart.
Same etcd plus configs means same network. Exact paths vary by managed versus self run installs. Keep backups of etcd snapshots on schedule. One missing snapshot restores agents without identities. For moves, drain nodes first to avoid split policy during copies. Check the in app storage readout when sizes look wrong on different releases.
Where Cilium Networking stores this, by platform
/var/lib/cilium (agent state, identities in etcd)
Identities live in etcd with eBPF maps rebuilt on start. Back up etcd snapshots on schedule. Match releases before restore. Nodes hold runtime cache.
Frequently asked questions
How do I migrate Cilium state to new nodes?
Back up etcd snapshots plus Cilium config maps with services steady, then install the same release on the new nodes before restore. Identities follow etcd. Mixed releases can refuse old state, so match versions first.
Does Cilium persist eBPF maps?
Yes, in etcd with eBPF maps rebuilt from it on agent start. Nodes hold a working copy plus policy cache. Views rebuild after restore. Export YAMLs from config maps for records, since node files alone are runtime state.
Notice an outdated path? Let us know.