The Secure Way
Kubernetes networking with Cilium, the secure way
Default-deny network policy, transparent encryption and egress control with Cilium and Hubble.
11 guides
- API server and webhook traffic under default deny, the secure wayKeep the Kubernetes API server and admission webhooks working under Cilium default deny: kube-apiserver entity, webhook ingress, and failurePolicy traps.
- Blocking the cloud metadata endpoint from pods, the secure wayStop Kubernetes pods from reading 169.254.169.254: a Cilium deny policy that cannot be overridden, the hostNetwork gap, IMDSv2 hop limits, and a test.
- Cilium kube-proxy replacement, the secure wayReplace kube-proxy with Cilium without widening exposure: NodePorts on the private NIC only, source ranges on every service type, no kube-proxy leftovers.
- Cilium L2 announcements in a cloud VPC, the secure wayCilium L2 announcements answer ARP for service IPs. In a cloud VPC that rarely works, and making it work weakens anti-spoofing. Limit it where you use it.
- Cilium policy audit mode to enforcement, the secure wayRoll out Cilium network policies with Policy Audit Mode without switching off every policy in the cluster: per-endpoint audit, AUDIT verdicts, exit criteria.
- Cilium WireGuard transparent encryption, the secure wayTurn on Cilium WireGuard encryption so pod traffic between nodes is never sent in clear: node encryption, strict mode, the gaps it leaves, and how to check.
- Cilium with minimal capabilities on Talos, the secure wayRun Cilium on Talos Linux with the smallest privilege set: no SYS_MODULE, no privileged or nsenter init containers, KubePrism, and no exec into the agent.
- Default-deny network policies generated from Hubble flows, the secure wayBuild Kubernetes default-deny network policies from real Hubble flows: collect enough traffic, reduce it to edges, write narrow Cilium policies, and verify.
- Egress isolation for CI build pods, the secure wayIsolate Kubernetes CI build pods with Cilium: egressDeny for the API server, nodes, metadata and private ranges, plus an FQDN allowlist for builds.
- FQDN egress allowlists with the Cilium DNS proxy, the secure wayWrite Cilium toFQDNs egress allowlists that hold: restrict what pods may resolve, not only where they connect, and block internal ranges an FQDN may resolve to.
- Hubble for network forensics, the secure wayUse Cilium Hubble as network evidence: export flows before the ring buffer forgets, keep the right fields, redact secrets, lock the API, and query offline.
T Academy
Every guide here is taught hands-on in H2-CSPE Secure Platform Engineering: a real host in your browser, and every objective checked on the machine.
Start free