9 ms·
Kubeshark: The API Traffic Viewer for Kubernetes
- mertyildiran 4y agoKubeshark (formerly Mizu) is an observability and monitoring tool that captures all the network traffic inside a Kubernetes cluster, including ingress, egress and across containers and pods. Kubeshark can even capture and display the encrypted (TLS) traffic using various Linux kernel technologies. It supports a wide variety of application layer protocols and RPCs like gRPC, GraphQL, etc. Kubeshark is open-source and free to use. It has a large userbase. We recently renamed the project from "Mizu" to "Kubeshark". Please give Kubeshark a shout-out. It's a carefully crafted tool by a handful of Kubernetes enthusiasts for Kubernetes enthusiasts!
- ElijahLynn 4y agoGreat name!
- EdwardDiego 4y agoLove it, already shared it on Slack :)
- otterley 4y agoCan you talk about the problems it solves for your users? What are the use cases, and why would someone want to use this tool?
- unixhero 4y agoTraffic mapping naturally. A core pattern within Zero Trust and Cyber Security.
- otterley 4y agoWhat does Zero Trust have to do with traffic mapping?
- PLG88 4y agoVisibility and analytics is a key component of zero trust... but the comment above seems to forget that the core concept of zero trust is about any person, device, or application trying to access a network cannot be trusted until authenticated and verified... this should mean using strong identity (e.g., x509) and authentication-before-connect, not trusting or allowing network identity such as IP/DNS/ports.
- deleted 4y ago[deleted]
- _def 4y agoHuh, I was really confused at first because the screenshot was the first thing I looked at and thought that it looks exactly like mizu, which I found and used the first time last week. What a coincidence!
- unity1001 4y agoA way to measure and limit (and eventually suspend/unsuspend) the bandwidth of any service, ingress or container etc would be great to have in K8.
- manibatra 4y agoReally cool. Have previously used proxies/tcpdump to debug a bunch of traffic. This is going to be a useful tool in the toolkit for Kubernetes operators.
- kristopolous 4y agoI was expecting to see Gerald Combs from Sysdig here. Interesting to not.
- jmartrican 4y agoThis is very cool and really needed, can't wait to try it out. One benefit of terminating SSL at the load balancer is that you can read the http traffic sent to your pods. But for those that have SSL terminating at their pods, it would be cool if this tool could be given the SSL certificates of the pods so it can decipher https traffic.
- dilyevsky 4y agoJust private key is not enough bc of PFS - you need to intercept key exchange to grab a temporary session key
- benmmurphy 4y agoOne option is to use ebpf uprobes to dump the key material or plaintext (https://github.com/ehids/ecapture https://github.com/ehids/ecapture ). Should be easy for c-like TLS libraries probably less useful for JIT languages.
- jmartrican 4y agoSolid point. Didn't realize that.
- intelVISA 4y agoTLS termination before the destination? Oof, are you running Cloudflare?
- cassianoleal 4y agoCloud Load Balancers in general have limited feature sets or don't work at all without handling TLS termination. Terminating TLS on the LB doesn't preclude you from also using TLS or mTLS internally though.
- outfar 4y agoHas anyone tried this with a tilt setup?