Show HN: Kloak, A secret manager that keeps K8s workload away from secrets

Kloak is an agentless Kubernetes security solution that uses eBPF to intercept HTTPS traffic and replace secret placeholders with actual credentials at the network edge, ensuring applications never directly access sensitive data and eliminating a major attack surface for credential theft. This approach delivers enterprise-grade secret management without code changes, sidecar overhead, or latency impact, while maintaining compatibility with standard Kubernetes Secrets and requiring only simple YAML labels for enablement. For IT organizations, Kloak reduces operational complexity and security risk by shifting secrets enforcement from application-layer to kernel-layer, significantly lowering the blast radius of compromised workloads.

Hacker News3 min read
Read full article
Show HN: Kloak, A secret manager that keeps K8s workload away from secrets
Kloak is an agentless Kubernetes security solution that uses eBPF to intercept HTTPS traffic and replace secret placeholders with actual credentials at the network edge, ensuring applications never directly access sensitive data and eliminating a major attack surface for credential theft. This approach delivers enterprise-grade secret management without code changes, sidecar overhead, or latency impact, while maintaining compatibility with standard Kubernetes Secrets and requiring only simple YAML labels for enablement. For IT organizations, Kloak reduces operational complexity and security risk by shifting secrets enforcement from application-layer to kernel-layer, significantly lowering the blast radius of compromised workloads.