Securely Extend Kubernetes Networking to Include Virtual Machines
11-05, 15:45–16:15 (US/Central), ROOM 1

Cloud native extends beyond just Kubernetes, it would be great if the Kubernetes networking did as well. The new node-to-node encryption capability introduced in the Cilium makes it possible to have workloads external to an Kubernetes cluster, such as virtual machines, participating as labeled entities in a transparently encrypted Cilium managed network alongside Kubernetes pods. Once configured as part of the secure clustermesh, not only do the external virtual machine get the benefits of transparent encryption, but also Cilium powered observability and access control via label based network policy!

This talk will review how to setup a transparently encrypted Cilium clustermesh with support for external virtual machines, how to observe these external workloads using Cilium Hubble, and provide examples of using Cilium network policy to secure access between these virtual machines and microservices running inside a Cilium managed Kubernetes clusters.

Jef Spaleta has more than a decade of experience in the technology industry; as software engineer, open source contributor, IoT hardware developer, operations, and most recently as a community advocate at Isovalent.