Skip to main content

k8s-container-mapping

Provides expertise in topology mapping, Pod-to-Pod network flows, eBPF observability, and real-time security for Kubernetes and Containers (Cilium, Hubble, Kiali, Kubeshark, Pixie, Inspektor Gadget, Parca, Tetragon, Falco, Tracee).

Jump to install

Source facts

Repository
dandgabr/Coacus
Last source activity
September 28, 2026 at 14:03
Detected SKILL.md language
English
Stars
4
Forks
3

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.

File Explorer
5 files

Showing SKILL.md

SKILL.md
Source instructions · Read-only preview
name
k8s-container-mapping
description
Provides expertise in topology mapping, Pod-to-Pod network flows, eBPF observability, and real-time security for Kubernetes and Containers (Cilium, Hubble, Kiali, Kubeshark, Pixie, Inspektor Gadget, Parca, Tetragon, Falco, Tracee).
# ☸️ Topology, Traffic, and Security Mapping in Kubernetes & Containers (eBPF & Service Mesh) This skill guides the AI to act as a **Kubernetes Cluster and Container Environment Mapping Specialist**, using kernel-level eBPF technologies, Service Meshes, and dynamic inspection tools to build communication maps between Pods, Services, Namespaces, network policies, and runtime security events. --- ## 🏛️ 1. Mapping Architecture in Kubernetes via eBPF & Service Mesh Combining an eBPF-based CNI with a Service Mesh provides full visibility at the L3, L4, and L7 layers without the need for heavy sidecars: ```mermaid flowchart TD subgraph K8sCluster["Kubernetes Cluster Topology"] subgraph NS_Frontend["Namespace: frontend"] POD_FE["Pod: web-ui (Frontend)"] end subgraph NS_Backend["Namespace: backend"] POD_BE["Pod: api-server (Backend)"] POD_AUTH["Pod: auth-service"] end subgraph NS_Database["Namespace: data"] POD_DB[("Pod: postgresql")] end end subgraph eBPF_Layer["eBPF Kernel Layer (Host Level)"] CILIUM["Cilium CNI & Socket Filtering"] HUBBLE["Hubble Relay & UI"] PIXIE["Pixie (Auto-Telemetry & Scripting)"] GADGET["Inspektor Gadget (Traces & Top)"] TETRAGON["Tetragon (Security Visibility & Enforcement)"] PARCA["Parca (Continuous eBPF Profiling)"] end subgraph Visualizers["Topology Visualizers"] KIALI["Kiali (Istio/Linkerd Mesh Graph)"] KUBESHARK["Kubeshark (API Traffic Analyzer)"] FALCO_TRACEE["Falco & Tracee (Audit Graphs)"] end POD_FE -->|"HTTP GET /api/v1/data"| POD_BE POD_BE -->|"mTLS gRPC /auth"| POD_AUTH POD_BE -->|"TCP 5432 SQL"| POD_DB POD_FE -.-> eBPF_Layer POD_BE -.-> eBPF_Layer POD_DB -.-> eBPF_Layer eBPF_Layer --> HUBBLE & KUBESHARK & KIALI & FALCO_TRACEE ``` --- ## 🛠️ 2. Specialist Tools and Commands ### A. L3/L4/L7 Network and Topology Mapping #### 1. Cilium & Hubble - **Concept**: A high-performance eBPF-based CNI that replaces `kube-proxy` (via eBPF host routing) and **Hubble**, its observability layer that builds real-time service flow graphs, DNS, HTTP, and Network Policy drop monitoring. - **CLI Inspection and Mapping Commands**: ```bash # Observe L7 flows in real time filtered by namespace and protocol hubble observe --namespace backend --protocol http --follow # Inspect traffic drops (Network Policy Drops) hubble observe --verdict DROPPED --namespace backend # Generate a flow map between services and endpoints hubble observe --to-service backend/api-server -o jsonpb | jq '.flow | {src: .source.workload_names, dst: .destination.workload_names, l7: .l7}' ``` #### 2. Kiali (Service Mesh Topology) - **Concept**: A management console and topology visualization for **Istio** and **Linkerd**. It renders directed call graphs, identifying request success rates, mTLS sidecar injection status, Canary/Blue-Green route versioning, and response times. #### 3. Kubeshark (The API Traffic Analyzer for Kubernetes) - **Concept**: An L7 traffic sniffer and analyzer for Kubernetes, capable of intercepting and decoding protocols such as HTTP/1.1, HTTP/2, gRPC, WebSocket, AMQP, Kafka, and Redis in real time, including channels encrypted via TLS through eBPF uretprobes. - **CLI Usage**: ```bash # Start Kubeshark and open the local web interface kubeshark tap -n production # Filter only calls with HTTP status error >= 400 kubeshark tap "response.status >= 400" ``` #### 4. Pixie (Open Source Kubernetes Observability via eBPF) - **Concept**: A zero-code telemetry platform that automatically collects request traces, network metrics, CPU and memory usage per pod, and complete tables of HTTP/gRPC/SQL messages using **PxL** (Pixie Language) scripts. - **PxL Query for database dependency mapping**: ```python import px # Map latency and SQL queries executed per service df = px.DataFrame(table='pgsql_events', start_time='-5m') df.service = df.ctx['service'] df = df.groupby(['service', 'req']).agg( latency=('latency', px.mean), count=('latency', px.count) ) px.display(df) ``` --- ### B. Kernel Resource Mapping, Profiling, and Runtime Security #### 1. Inspektor Gadget - **Concept**: A collection of packaged tools and eBPF tools for debugging, process mapping, and container auditing in Kubernetes. - **Essential Gadgets**: ```bash # Trace new TCP connections opened by pods in real time kubectl gadget trace tcp --namespace production # Map files opened and modified by containers kubectl gadget trace open -A # Profile the processes consuming the most disk I/O kubectl gadget top block-io ``` #### 2. Parca (Continuous Profiling via eBPF) - **Concept**: A continuous profiling system that captures CPU Flamegraphs, memory allocation, and native calls across the entire container fleet without overhead or code recompilation. #### 3. Tetragon (eBPF-based Security Observability & Runtime Enforcement) - **Concept**: The visibility and security enforcement mechanism of the Cilium project that maps process executions (`execve`), access to confidential files, network socket connections, and privilege escalation with synchronous blocking in the kernel. - **Example TracingPolicy (`monitor-binaries.yaml`)**: ```yaml apiVersion: cilium.io/v1alpha1 kind: TracingPolicy metadata: name: "monitor-exec-sensitive" spec: kprobes: - call: "sys_execve" syscall: true args: - index: 0 type: "string" selectors: - matchArgs: - index: 0 operator: "Prefix" values: - "/bin/bash" - "/bin/sh" - "/usr/bin/nc" ``` #### 4. Falco & Tracee - **Falco (CNCF Graduated Runtime Security)**: Analyzes system call events through kernel drivers or eBPF to detect behavioral anomalies (shells in pods, writes to binary directories, modification of `/etc/passwd`). - **Tracee (Aqua Security)**: An eBPF event forensic tracing mechanism specialized in detecting MITRE ATT&CK techniques for containers and Linux. --- ## 📊 3. Tool Selection Matrix by Use Case | Mapping Need | Recommended Tool | Operating Layer | | :--- | :--- | :--- | | **Pod-to-Pod Topology and Network Policies** | **Cilium + Hubble** | eBPF Kernel / L3-L4-L7 | | **Real-Time HTTP/gRPC Payload Inspection** | **Kubeshark** | eBPF uretprobes / L7 | | **Istio/Linkerd Service Mesh Visualization** | **Kiali** | Sidecar Proxy / Control Plane | | **SQL Query and Dependency Mapping** | **Pixie** | eBPF Kernel / Socket Data | | **CPU/Memory Profiling (Flamegraphs)** | **Parca** | eBPF Perf Events | | **Syscall and File Access Tracing** | **Inspektor Gadget** | eBPF Kprobes / Tracepoints | | **Pod Security Anomaly Detection** | **Tetragon / Falco** | eBPF Kernel Hooks | --- ## 🎯 4. Best Practices and Recommendations - [ ] **Disabling kube-proxy**: When adopting Cilium eBPF, enable `kubeProxyReplacement=true` to reduce iptables overhead and improve inter-service traffic routing. - [ ] **L7 Latency Metrics with Hubble**: Enable `hubble.metrics.enabled="{dns,drop,tcp,flow,port-distribution,icmp,http}"` to export complete data to Prometheus. - [ ] **Network Isolation Policies**: Use Hubble visualization to create least-privilege **CiliumNetworkPolicies** (Default Deny) based on real observed flows.
View on GitHub