Skip to content

Cilium overlay: transparent pod-to-pod encryption (WireGuard) for regulated tiers #162

Description

@gangster

Context

Follow-up from the Cilium overlay networking change.

Overlay VXLAN traffic is unencrypted node-to-node (plaintext within the VPC). Standard-tier risk class is unchanged (intra-VPC), but for hipaa/pci "encryption in transit everywhere" this is a gap.

Ask

Expose a Cilium transparent encryption knob (WireGuard preferred; IPsec alternative) in the cilium module, defaulted off, and enable it for regulated compliance_tier clusters. Validate throughput/latency impact.

Acceptance

  • compliance_tier in [hipaa, pci] clusters run with pod-to-pod encryption enabled.
  • Module variable + per-tier wiring; documented in security/compliance docs (09/10).

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/networkVPC, Cilium, TGW, DNS, Tailscale, GatewaydeferredIntentionally parked until a trigger (prod, regulated tier, second zone, ...)enhancementNew feature or requestsecuritySecurity hardening, posture, or risk reduction

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions