logoalt Hacker News

Gigachadtoday at 4:32 AM1 replyview on HN

Encrypted by Cloudflare, so they just use the keys to decrypt it again.


Replies

koito17today at 6:06 AM

Many organizations, surprisingly, still do things like using Kubernetes with TLS terminated at the ingress. In that case, you just need the splitter in the same network as the nodes hosting the ingress controller. Or inspect the unencrypted traffic within the cluster.

It takes a non-trivial amount of work to set up a service mesh (and mutual TLS between services), so many k8s clusters end up with unencrypted traffic inside the cluster network.

show 1 reply