logo
Dates

Author


Conferences

Tags

Sort by:  

Authors: Peter Kelly
2022-05-20

tldr - powered by Generative AI

The presentation discusses the use of WireGuard and Project Calico to provide full mesh encryption in Kubernetes for compliance and zero-trust security.
  • Encrypting data-in-transit is important for compliance and zero-trust security in Kubernetes
  • Common encryption options include mutual TLS and IPsec
  • Project Calico uses WireGuard for full mesh encryption at a layer below application workloads
  • WireGuard is lightweight, fast, scalable, and easy to configure
  • Calico's data plane components interact with WireGuard to manage the kernel and networking rules
  • The implementation has some gaps and areas for improvement