product

What Cilera adds to Cilium and Hubble

Every capability listed here is available now. One read-only Helm chart per cluster, outbound HTTPS only.

~/hubble

How Cilera relates to Hubble

Built on Hubble's flow data. Hubble and Hubble Relay must be enabled in each cluster.

  • Hubble gives you live flows and a Hubble UI service map per cluster, and multi-cluster views through Cluster Mesh with Hubble Relay.
  • Cilera adds a map across every cluster without Cluster Mesh, change detection, threat detection, compliance evidence, policies in plain language and cluster insight.
~/map

Map and flows

Which workloads communicate, across every connected cluster, and why traffic is dropped.

  • Multi-cluster map at cluster, namespace and workload level, updated every minute.
  • Expand any object in place, or open it on the full canvas.
  • Cross-cluster links without Cluster Mesh, each labelled exact or inferred from load balancer or egress addresses.
  • Clusters grouped by region or platform.
  • Filters for cluster, namespace, workload, port, protocol and verdict. Filtered views can be shared as links.
  • Path tracer: every path between two workloads, with verdicts and matching policies.
  • A live flow terminal and a traffic matrix.
  • Drop reasons, with Cilium drop codes.
  • Optional HTTP detail: method, path template, status class and p50/p95 latency per endpoint. Requires Cilium L7 visibility.
~/changes

Change detection

What differs from normal, not only what is happening now.

  • Baselines: yesterday, or the previous window.
  • Paths flagged as new, went silent, started dropping or got slower.
  • Time scrubber across 7 days, with windows from 15 minutes to 24 hours.
~/threats

Threat detection

Continuous detection, with the flow evidence kept for investigation.

  • Port scans, lateral movement (new paths between namespaces), new internet egress, policy-denial spikes and unusual control-plane egress.
  • Unencrypted cross-cluster traffic flagged as a posture finding.
  • Contact with known command-and-control, malware and crypto-mining hosts, from abuse.ch threat intelligence (Feodo Tracker, URLhaus, ThreatFox), raised to critical.
  • MITRE ATT&CK mapping, with a view by technique.
  • Incidents with flow evidence, status, assignee and notes.
  • AI explanations of each incident in plain language. AI does not change policies or the cluster.
  • Suppressions for activity your team has reviewed and expects.
~/policies

Policies

What each network policy allows, without reading the YAML.

  • CiliumNetworkPolicy, CiliumClusterwideNetworkPolicy and Kubernetes NetworkPolicy, shown in plain language.
  • Policies can be edited by hand in the Cilera console. Cilera never applies anything to the cluster.
~/compliance

Segmentation and compliance

Zero-trust segmentation verified against observed traffic, with compliance evidence on a 15-minute schedule.

  • PCI DSS v4.0, SOC 2, NIST SP 800-53 Rev. 5 and CIS Kubernetes Benchmark v1.9.
  • 8 automated checks, evaluated every 15 minutes, covering encryption in transit, segmentation zones, egress control and monitoring coverage.
  • Manual attestations for controls that cannot be checked automatically.
  • Segmentation zones: group namespaces into zones and verify workload segmentation (microsegmentation) against observed flows.
  • Downloadable HTML evidence reports, with history.
~/clusters

Cluster insight

How Cilium is configured in each connected cluster.

  • Datapath, kube-proxy replacement, encryption, IPAM, Hubble, Cluster Mesh, egress gateway and versions, per cluster.
~/access

Access and security

Who can see and change what in the Cilera console.

  • Owner and member roles. Owner-only controls for credentials, invites, zones and suppressions.
  • Tenant isolation enforced in the database. Hashed ingest tokens.
  • A separate ingest credential per cluster, issued through a signed, time-limited onboarding token.
~/retention

Data retention

How long each type of data is kept.

  • 7 days of flow detail, 90 days of hourly rollups, and 90 days of detections and compliance history.

Connect a cluster What runs in your cluster

early-access

Connect each cluster with one Helm command

The Cilera console is in early access. Once you have access, each cluster connects with this command.

install
$ helm upgrade --install cilera cilera/cilera-operator -n cilera-system --create-namespace -f cilera-values.yaml

The exact command and values file for each cluster are generated in the Cilera console.

×

early-access

The Cilera console is in early access

The console is not yet publicly available. Request access at [email protected].

Request Early AccessKeep Exploring