product
What Cilera adds to Cilium and Hubble
Every capability listed here is available now. One read-only Helm chart per cluster, outbound HTTPS only.
How Cilera relates to Hubble
Built on Hubble's flow data. Hubble and Hubble Relay must be enabled in each cluster.
- Hubble gives you live flows and a Hubble UI service map per cluster, and multi-cluster views through Cluster Mesh with Hubble Relay.
- Cilera adds a map across every cluster without Cluster Mesh, change detection, threat detection, compliance evidence, policies in plain language and cluster insight.
Map and flows
Which workloads communicate, across every connected cluster, and why traffic is dropped.
- Multi-cluster map at cluster, namespace and workload level, updated every minute.
- Expand any object in place, or open it on the full canvas.
- Cross-cluster links without Cluster Mesh, each labelled exact or inferred from load balancer or egress addresses.
- Clusters grouped by region or platform.
- Filters for cluster, namespace, workload, port, protocol and verdict. Filtered views can be shared as links.
- Path tracer: every path between two workloads, with verdicts and matching policies.
- A live flow terminal and a traffic matrix.
- Drop reasons, with Cilium drop codes.
- Optional HTTP detail: method, path template, status class and p50/p95 latency per endpoint. Requires Cilium L7 visibility.
Change detection
What differs from normal, not only what is happening now.
- Baselines: yesterday, or the previous window.
- Paths flagged as new, went silent, started dropping or got slower.
- Time scrubber across 7 days, with windows from 15 minutes to 24 hours.
Threat detection
Continuous detection, with the flow evidence kept for investigation.
- Port scans, lateral movement (new paths between namespaces), new internet egress, policy-denial spikes and unusual control-plane egress.
- Unencrypted cross-cluster traffic flagged as a posture finding.
- Contact with known command-and-control, malware and crypto-mining hosts, from abuse.ch threat intelligence (Feodo Tracker, URLhaus, ThreatFox), raised to critical.
- MITRE ATT&CK mapping, with a view by technique.
- Incidents with flow evidence, status, assignee and notes.
- AI explanations of each incident in plain language. AI does not change policies or the cluster.
- Suppressions for activity your team has reviewed and expects.
Policies
What each network policy allows, without reading the YAML.
- CiliumNetworkPolicy, CiliumClusterwideNetworkPolicy and Kubernetes NetworkPolicy, shown in plain language.
- Policies can be edited by hand in the Cilera console. Cilera never applies anything to the cluster.
Segmentation and compliance
Zero-trust segmentation verified against observed traffic, with compliance evidence on a 15-minute schedule.
- PCI DSS v4.0, SOC 2, NIST SP 800-53 Rev. 5 and CIS Kubernetes Benchmark v1.9.
- 8 automated checks, evaluated every 15 minutes, covering encryption in transit, segmentation zones, egress control and monitoring coverage.
- Manual attestations for controls that cannot be checked automatically.
- Segmentation zones: group namespaces into zones and verify workload segmentation (microsegmentation) against observed flows.
- Downloadable HTML evidence reports, with history.
Cluster insight
How Cilium is configured in each connected cluster.
- Datapath, kube-proxy replacement, encryption, IPAM, Hubble, Cluster Mesh, egress gateway and versions, per cluster.
Access and security
Who can see and change what in the Cilera console.
- Owner and member roles. Owner-only controls for credentials, invites, zones and suppressions.
- Tenant isolation enforced in the database. Hashed ingest tokens.
- A separate ingest credential per cluster, issued through a signed, time-limited onboarding token.
Data retention
How long each type of data is kept.
- 7 days of flow detail, 90 days of hourly rollups, and 90 days of detections and compliance history.
early-access
Connect each cluster with one Helm command
The Cilera console is in early access. Once you have access, each cluster connects with this command.
The exact command and values file for each cluster are generated in the Cilera console.