Skip to content

Network policy with Cilium and Linkerd Layer7 #11653

Closed Answered by wmorgan
ventaubain asked this question in Q&A
Discussion options

You must be logged in to vote

As I understand it, Cilium CNI supports only L4 policies. L7 policies in Cilium require adding Cilium mesh, which runs set of per-node Envoy proxies to every host, an approach that we consider to have lower security and worse operational characteristics.

So our recommendation is L4 policies in Cilium CNI and L7 policies with Linkerd.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by ventaubain
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants