Try “car wash”, “subscription box”, “Austin” · Esc to close

Kloak

Secret manager that isolates Kubernetes workloads from secrets

SaaS SaaS & software Show HN · launch post · ▲ 63

Visit site

getkloak.io

What it does

Kloak intercepts HTTPS traffic in Kubernetes clusters using eBPF and replaces hashed placeholders with real secrets at the network layer. Applications send requests with placeholder values (like kloak:MPZVR3GHWT4E6YBCA01JQXK5N8), and Kloak transforms them into actual credentials before the request leaves the pod. The real secret values never reach the application code itself.

Who it is for

Kubernetes operators and teams running containerized applications that need to use API keys, tokens, or other credentials. It targets workloads where accidental credential exposure is a security concern, particularly those that cannot be refactored to use alternative secret-handling patterns.

Pricing

The site does not show prices.

How it stands out

Kloak operates as an agentless system using pure eBPF in kernel space rather than requiring sidecars or custom network plugins. This kernel-level approach claims negligible latency overhead. The product integrates with standard Kubernetes Secrets using labels, requiring no code changes to applications and working with any programming language or framework. It enforces host restrictions to prevent credentials from being used with unintended endpoints. The tool is open source under AGPL-3.0, allowing inspection of the implementation.

What a founder should check

First, verify how eBPF-based secret interception compares to existing Kubernetes secret management tools (including native Secret resources, external secret operators, and sidecar-based approaches). Check whether the latency claim holds under real traffic patterns and whether eBPF has operational limitations across different Kubernetes distributions and kernel versions.

Second, assess the switching costs and lock-in. Evaluate whether the AGPL-3.0 license and agentless design create deployment friction compared to vendor-managed solutions, and whether teams can easily adopt or abandon the tool without rearchitecting applications.

Third, examine the actual security moat. The core mechanism—network-layer secret substitution—may be reproducible by competitors. Determine whether the advantage lies in ease of deployment, the specific eBPF implementation, the label-based integration model, or simply being first to market with this approach in Kubernetes.

Thinking of building something like this?

Every launch here is a competitor to somebody's idea. If yours is close, check it against the market before you build: the Full Check names the rivals, the prices and the gaps.

Check an idea like this

More saas launches

All

Meihus

Mortgage calculator showing early payment impact with international loan flexibility

SaaS SaaS & softwareShow HN ▲ 20

GYST

Digital organizer merging file explorer, whiteboard, notes and design tools

SaaS SaaS & softwareShow HN ▲ 37

Checked ideas in SaaS & software