News and links on Kubernetes security curated by the @Learnk8s team
Website: https://kubesploit.io/
Post #1727
295
Forwarded from KubeFM
John Howard, Senior Software Engineer at Solo.io, compares different network encryption approaches in Kubernetes and explains why CNI-based options like IPsec and WireGuard aren't equivalent to TLS.
He clarifies that IPsec and WireGuard typically provide node-to-node encryption rather than workload-to-workload encryption, resulting in less granular identity verification for zero-trust environments. John discusses practical considerations, including FIPS compliance requirements for government use cases and feature trade-offs when implementing IPsec with CNIs like Cilium. He debunks performance misconceptions, explaining that mTLS often outperforms WireGuard despite kernel-level implementation advantages, with benchmarks showing similar latency but 3-4× better throughput for mTLS due to hardware-optimized TLS processing.
Watch the full episode: https://kube.fmhttps://ku.bz/sk-ZF1PG9
He clarifies that IPsec and WireGuard typically provide node-to-node encryption rather than workload-to-workload encryption, resulting in less granular identity verification for zero-trust environments. John discusses practical considerations, including FIPS compliance requirements for government use cases and feature trade-offs when implementing IPsec with CNIs like Cilium. He debunks performance misconceptions, explaining that mTLS often outperforms WireGuard despite kernel-level implementation advantages, with benchmarks showing similar latency but 3-4× better throughput for mTLS due to hardware-optimized TLS processing.
Watch the full episode: https://kube.fmhttps://ku.bz/sk-ZF1PG9








