TGViewer
Kubesploit Kubesploit @kubesploit · 2.13K subscribers
Post #1727 295

Forwarded from KubeFM

John Howard, Senior Software Engineer at Solo.io, compares different network encryption approaches in Kubernetes and explains why CNI-based options like IPsec and WireGuard aren't equivalent to TLS.

He clarifies that IPsec and WireGuard typically provide node-to-node encryption rather than workload-to-workload encryption, resulting in less granular identity verification for zero-trust environments. John discusses practical considerations, including FIPS compliance requirements for government use cases and feature trade-offs when implementing IPsec with CNIs like Cilium. He debunks performance misconceptions, explaining that mTLS often outperforms WireGuard despite kernel-level implementation advantages, with benchmarks showing similar latency but 3-4× better throughput for mTLS due to hardware-optimized TLS processing.

Watch the full episode: https://kube.fmhttps://ku.bz/sk-ZF1PG9
More from @kubesploit
  1. Sep 25, 2026This tutorial builds a Docker image with a secret, then shows how it still sits in an earl…
  2. Sep 24, 2026This article explains how Vault piles up unexpired leases when pods keep re-authenticating…
  3. Sep 23, 2026This article asks what a container can block on its own when a dependency turns malicious,…
  4. Sep 23, 2026This week on Learn Kubernetes Weekly 202: 🔥 We Replaced etcd with Google Cloud Spanner 😌…
  5. Sep 22, 2026This article explains what an attacker can really do with leaked Kubernetes credentials, f…
  6. Sep 22, 2026"When an agent goes loose, you might find yourself: your S3 bucket has been deleted by mis…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →