Session

Zero Trust Networking on AKS: Implementing Default-Deny with Cilium and eBPF

Kubernetes networking still relies heavily on implicit trust. Once a workload is running inside a cluster, it can typically communicate with any other pod or service without restriction. In modern multi-tenant environments, this flat network model creates a massive blast radius: a single compromised container can instantly become an entry point for lateral movement.

Traditional IP-based firewalls and reactive network security tools struggle in dynamic cloud-native environments where pod IPs shift continuously. Zero Trust changes this paradigm by denying all traffic by default and enforcing strict, identity-aware connections at both L3/L4 and L7 layers.

This hands-on session explores how to implement Zero Trust network security natively on Azure Kubernetes Service (AKS) using Cilium and eBPF. Moving beyond simple policy demos, we’ll dive into the mechanics of eBPF-powered packet filtering and show how to transition live production workloads from wide-open networks to robust default-deny enforcement without introducing performance overhead.

Key Takeaways:
- Why IP-centric security models fail in Kubernetes and how eBPF replaces them with workload identity.
- Practical patterns for designing, testing, and deploying default-deny policies on AKS.
- Combining Cilium network enforcement with Azure-native security monitoring and traffic visibility.

Rolf Schutten

COO & Microsoft Azure MVP | Bridging Strategy and Cloud Execution

Veenendaal, The Netherlands

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top