Security: Mutual TLS (mTLS) for pod-to-pod encryption, transparent proxying.
2. eBPF & Cilium
eBPF (Extended Berkeley Packet Filter): Running sandboxed programs in the Linux kernel without changing kernel source code. Replacing IPTables.
Cilium Architecture: Sidecarless mesh, CiliumNetworkPolicies (L3/L4/L7), Hubble for observability and service map visualization.
π οΈ Job-Essential Exercises
The Zero-Trust Network Policy:
Deploy Cilium. Deploy three pods: Frontend, Backend, and Hacker. Write a CiliumNetworkPolicy that completely locks down the namespace, explicitly allowing only Frontend to communicate with Backend on TCP port 8080.
Proving Zero-Trust:
kubectl exec into Hacker and attempt to curl the Backend. It must timeout.
Hubble Observability:
Enable Hubble. Generate traffic between your pods. View the Hubble UI or CLI to see a live visual graph of the network flows and blocked packets.