Uppsats

Zero Trust in Kubernetes: A Comparative Analysis between Calico and Cilium

Yrkesexamen på grundnivå

Mälardalens universitet/Institutionen för datavetenskap och datateknik

Publicerad: 2026

Språk: Engelska

Sammanfattning

As Zero Trust continues to grow in adoption, it is important to understand the effects of Zero Trust and the impact it could have on Kubernetes environments as Kubernetes continues to grow into a dominant platform for the purpose of container orchestration and cluster management. The purpose of this thesis is to investigate this impact using two different Container Network Interfaces (CNI): Calico and Cilium, in Kubernetes environments, thereafter, comparing the differences between the CNIs as well. The thesis aimed to evaluate the impact on latency, throughput and resource utilization of CPU and memory after implementing WireGuard encryption and thereafter another evaluation after implementing Zero Trust Access. The comparison between Calico and Cilium was also done to find the difference in the operational complexity with policy building as well as the variation in impact because of the different networking solutions they use, Calico with iptables-based and Cilium with eBPF-based architecture. To find the answers for the research questions, two isolated Kubernetes environments were deployed in a Proxmox virtualized environment with each their own CNI, Calico or Cilium. There were three phases in each environment that were evaluated with measurement tests and utilization observation, these were the baseline phase where CNIs were installed and the environments networks were configured, however no additional security mechanisms. The second phase to be evaluated was with WireGuard encryption enabled in both environments and the last phase was when Zero Trust policies were enforced on top of the WireGuard encryption being enabled. The measurements for the results were collected via the use of k6 for HTTP latency, iperf3 for throughput testing and Prometheus with Grafana for the monitoring and visualization of CPU and memory utilization. The results of the study demonstrated that WireGuard encryption introduced measurable but limited overhead in both environments. The impact on the throughput values and memory utilization were however significant whereas the latency and CPU utilization remained relatively stable. The effect of implementing Zero Trust policies were minor as most of the impact came from the WireGuard encryption. However, the results did differ between the two CNIs, whereas the environment using Cilium achieved higher throughput values, whilst Calico demonstrated more stable and predictable patterns on the performance differences. The study done in this report contributes to a broader knowledge and understanding of the trade-offs for performance when implementing Zero Trust networking within Kubernetes environments.

Information

Författare
Sakrak, Ethem
Lärosäte / institution
Mälardalens universitet/Institutionen för datavetenskap och datateknik
Publiceringsdatum
2026
Uppsatstyp
Yrkesexamen på grundnivå
Språk
Engelska