Cilium's host firewall extends Kubernetes network policies to secure the underlying nodes themselves using eBPF technology. It addresses the security gap where traditional Kubernetes network policies don't apply to host-level traffic like SSH, kubelet, or monitoring agents. The solution treats nodes as special endpoints with
Table of contents
The Node as a Blind SpotHow Cilium’s Host Firewall WorksEnabling Host FirewallAudit ModeObserve Network Traffic with HubbleWriting Host Network PoliciesEnforcing the PolicyBest Practices and Troubleshooting TipsConclusionAdditional Resources:Sort: