Kloak
Intercepts HTTPS traffic in Kubernetes using eBPF, replacing hashed placeholders with real secrets at the network edge.
Kloak is an agentless Kubernetes security tool that intercepts HTTPS traffic using eBPF to replace hashed placeholders with real secrets at the network edge, preventing application processes from accessing actual credentials. It targets developers, IT, and operations teams in organizations using Kubernetes, particularly those needing secure secret management without code changes. The solution is positioned as a pure eBPF integration with zero latency impact, requiring no sidecars or SDKs, and is fully open source under AGPL-3.0.
Key features
- Secure by design: secrets replaced at network edge
- Zero latency impact via eBPF
- Kubernetes native: works with standard Secrets
- Host restrictions for fine-grained access control
- Zero code changes: no SDK required
- Pure eBPF integration: no sidecars or CNI plugins
- Open source under AGPL-3.0 License
- No social media activity within the last 30 days
GTM channels
- Blog
- Docs
ICP
- DevOps sre teams
- Security teams
- Engineering teams