Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Kloak, A secret manager that keeps K8s workload away from secrets

Details

External ID
47903690
Source
HN
Company
—
Product
Kloak, A secret manager that keeps K8s workload away from secrets
Website domain
getkloak.io
Launched
April 25, 2026
Cohort
—
Upvotes
63
Upvotes percentile
0.8586118251928021
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Enrichment

Theme
systems tools and desktop utilities
Vertical
Security
Function
Compliance & governance
Audience
B2B
AI stance
Not AI
Project type
Commercial product
Normalized one-liner
secrets management for kubernetes workloads
Manually corrected
False

Could you build this?

No Transparently intercepting outbound HTTPS traffic in Kubernetes using pure eBPF to rewrite headers at the kernel level requires deep Linux kernel, network socket manipulation, and eBPF/uprobe expertise.

What it would actually take: Building Kloak requires writing C/eBPF code attached to kernel socket ops (or uprobes on SSL libraries like OpenSSL/BoringSSL) to inspect TLS traffic or plaintext socket buffers prior to encryption, along with a Go Kubernetes operator using Cilium/ebpf to manage maps and intercept rules dynamically. Handling TLS payload rewriting at the kernel network level or via TLS uprobes requires overcoming verifier limits, connection tracking, TCP sequence number rewriting, and strict memory safety guarantees.

Discussion

20 comments analyzed.

Competitors mentioned: Google Secrets Manager, AWS Secrets Manager, Infisical agent vault, Openboa/Vault, gearsec.io

Concerns raised: User trust issues with MITM plus access to secrets, Single point of failure with egress proxy approach, eBPF implementation challenges for API key signature rewriting, Hijacked pod could exfiltrate kloak secrets via HTTP call, Applications refusing to work with plain HTTP

Feature requests: Integration with external secret operators (AWS Secrets Manager, Vault), Direct integration with secrets managers via ESO, KMS just-in-time decryption to reduce secret exposure window, Per-node proxy architecture instead of centralized, Better documentation separating webhook app from eBPF injection code

Competitors

Other products that read as similar to this one — 533 launches clear the similarity bar, closest 8 shown.

Attention rank: #64 of 534 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 173 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a compliance & governance tool for Media & entertainment yet.