Platform and SRE teams
Trace a failing connection to its path, its Cilium drop reason and the change behind it, in any cluster.
Cilera reads the Hubble flows your Cilium clusters already produce and joins them into one fleet-wide map, with change detection, threat detection and zero-trust segmentation checks.
capabilities
Built on the flow data Hubble already collects, for platform, security and compliance teams.
Hubble shows one cluster at a time. A multi-cluster view needs Cluster Mesh.
Cilera maps every cluster, namespace and workload together, updated every minute.
Cross-cluster links work without Cluster Mesh. Each one is labelled exact, or inferred from load balancer or egress addresses.


Hubble shows recent flows from a short in-memory buffer.
Cilera compares each path with yesterday or the previous window and flags it as new, went silent, started dropping or got slower.
Scrub back to any window to see when a path changed.


Hubble records each flow, including the suspicious ones.
Cilera continuously checks for port scans, lateral movement between namespaces, new internet egress and policy-denial spikes.
Contact with known malicious hosts is raised to critical. Each incident keeps its flows, maps to MITRE ATT&CK and can be explained in plain language by AI.


Cilium enforces your policies. Auditors ask for proof the segmentation holds.
Group namespaces into segmentation zones. Cilera checks every allowed flow against them and flags lateral movement between namespaces.
Automated checks every 15 minutes against PCI DSS v4.0, SOC 2, NIST SP 800-53 and the CIS Kubernetes Benchmark, with an evidence report for each run.


hubble-and-cilera
Cilera reads flows from Hubble Relay in each cluster. Hubble and Hubble Relay stay as they are.
Cilera
cluster: prod-eu
cluster: prod-us
+ more clusters
how-it-works
Requires Cilium with Hubble and Hubble Relay enabled. No sidecars, no code changes.
One Helm chart per cluster. The command is generated in the Cilera console.
A signed, time-limited token gives the cluster its own ingest credential.
Aggregated flow counts go out over HTTPS. Nothing connects in.
The map updates every minute. Each path is compared with a baseline.
Threat detection runs continuously; compliance checks run every 15 minutes.
teams
Trace a failing connection to its path, its Cilium drop reason and the change behind it, in any cluster.
Verify zero-trust workload segmentation against observed traffic. Investigate lateral movement, new egress and contact with known malicious hosts, with flow evidence and ATT&CK context.
Segmentation and encryption evidence every 15 minutes, from observed traffic.
security
One read-only pod per cluster, in cilera-system. This is what it can access and what it sends.
# chart defaults, no overrides needed securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true capabilities: drop: [ALL] podSecurityContext: runAsNonRoot: true
faq
Answers to the questions platform, security and compliance teams ask before installing the operator.
Cilera is built on Hubble's flow data, so Hubble and Hubble Relay must be enabled in each cluster. On top of that data, Cilera adds a map across every cluster without Cluster Mesh, change detection against a baseline, threat detection with threat intelligence and MITRE ATT&CK mapping, compliance evidence, policies in plain language and cluster configuration insight.
Cilium enforces your network policies. Cilera shows whether traffic matches the workload segmentation you intended: which workloads actually communicate, which flows cross your segmentation zones, and where new paths appear between namespaces. Each finding keeps its flow evidence. Cilera does not enforce or change policies.
Cilium as the CNI, with Hubble and Hubble Relay enabled. The install guides cover Amazon EKS, Google GKE, Azure AKS, self-managed clusters and local kind clusters.
Aggregated flow counts by workload, port and verdict, drop-reason codes, latency, and allowlisted Cilium settings. No packet payloads, and no pod IPs of your workloads. HTTP detail is opt-in. When enabled, paths are templated, and IDs, email addresses and tokens are removed before the data leaves the cluster.
No. The operator is read-only: no writes, and no access to pods, nodes or other Secrets. It does not proxy or block traffic, and it does not inject sidecars. Cilera detects and recommends; your team makes any change to the cluster.
No. Cross-cluster traffic is linked without it. Each link is labelled exact, or inferred from load balancer or egress addresses.
Outbound HTTPS (port 443) to api.cilera.io and ingest.cilera.io. Nothing connects into the cluster.
7 days of flow detail, 90 days of hourly rollups, and 90 days of detections and compliance history.
PCI DSS v4.0, SOC 2, NIST SP 800-53 Rev. 5 and the CIS Kubernetes Benchmark v1.9. Eight automated checks run every 15 minutes. Manual attestations can be added, and evidence reports can be downloaded for each run.
AI explains threat incidents in plain language, based on the flow evidence of each incident. It does not change policies or take any action in your cluster.
early-access
The Cilera console is in early access. Once you have access, each cluster connects with this command.
The exact command and values file for each cluster are generated in the Cilera console.