Skip to content

Hubble: add option to sanitize sensitive L7 data from flows #23887

@rolinh

Description

@rolinh

Hubble has the capability of providing visibility on L7 protocols such as HTTP or Kafka. This layer 7 protocol visibility feature is opt-in and requires users to either create a L7 policy or to add explicit pod annotations to be enabled. Layer 7 Hubble flows, however, may contain sensitive information, for instance as part of some HTTP headers or in a URL itself.

Hubble should provide an option for users to decide which potentially sensitive L7 data to keep in Hubble flows and it should be finely configurable.

Metadata

Metadata

Assignees

Labels

area/agentCilium agent related.kind/featureThis introduces new functionality.pinnedThese issues are not marked stale by our issue bot.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions