Kloak, A secret manager that keeps K8s workload away from secrets
Details
- External ID
- 47903690
- Source
- HN
- Company
- —
- Product
- Kloak, A secret manager that keeps K8s workload away from secrets
- Website domain
- getkloak.io
- Launched
- April 25, 2026
- Cohort
- —
- Upvotes
- 63
- Upvotes percentile
- 0.8586118251928021
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Enrichment
- Theme
- systems tools and desktop utilities
- Vertical
- Security
- Function
- Compliance & governance
- Audience
- B2B
- AI stance
- Not AI
- Project type
- Commercial product
- Normalized one-liner
- secrets management for kubernetes workloads
- Manually corrected
- False
Could you build this?
No Transparently intercepting outbound HTTPS traffic in Kubernetes using pure eBPF to rewrite headers at the kernel level requires deep Linux kernel, network socket manipulation, and eBPF/uprobe expertise.
What it would actually take: Building Kloak requires writing C/eBPF code attached to kernel socket ops (or uprobes on SSL libraries like OpenSSL/BoringSSL) to inspect TLS traffic or plaintext socket buffers prior to encryption, along with a Go Kubernetes operator using Cilium/ebpf to manage maps and intercept rules dynamically. Handling TLS payload rewriting at the kernel network level or via TLS uprobes requires overcoming verifier limits, connection tracking, TCP sequence number rewriting, and strict memory safety guarantees.
Discussion
20 comments analyzed.
Competitors mentioned: Google Secrets Manager, AWS Secrets Manager, Infisical agent vault, Openboa/Vault, gearsec.io
Concerns raised: User trust issues with MITM plus access to secrets, Single point of failure with egress proxy approach, eBPF implementation challenges for API key signature rewriting, Hijacked pod could exfiltrate kloak secrets via HTTP call, Applications refusing to work with plain HTTP
Feature requests: Integration with external secret operators (AWS Secrets Manager, Vault), Direct integration with secrets managers via ESO, KMS just-in-time decryption to reduce secret exposure window, Per-node proxy architecture instead of centralized, Better documentation separating webhook app from eBPF injection code
Competitors
Other products that read as similar to this one — 533 launches clear the similarity bar, closest 8 shown.
Attention rank: #64 of 534 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 173 days after the earliest competitor.
- Selvum · hn · 2026-08-17 · 7 upvotes · similarity 0.52
- Secryn · hn · 2026-02-28 · 5 upvotes · similarity 0.51
- shobr · github · 2026-09-27 · 13 upvotes · similarity 0.50
- Data Leak Prevention inside the n8n execution graph. · hn · 2026-06-01 · 18 upvotes · similarity 0.50
- PhishHunt · github · 2026-09-23 · 8 upvotes · similarity 0.48
- A Mutating Webhook to automatically strip PII from K8s logs · hn · 2026-05-05 · 25 upvotes · similarity 0.48
- hetzner-cloud-audit-skills · github · 2026-09-22 · 16 upvotes · similarity 0.48
- 8cryptdo · github · 2026-09-26 · 11 upvotes · similarity 0.48
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a compliance & governance tool for Media & entertainment yet.