---
title: "Kernel-Level eBPF L3-L7 Kubernetes Microsegmentation | Zero-Trust Architecture Canon"
description: "Yavaş iptables kurallarını ortadan kaldıran, çekirdek seviyesinde Cilium eBPF ile kriptografik kimlik tabanlı L3/L4/L7 paket filtreleme ve şeffaf WireGuard şifrelemesi sağlayan mikro-segmentasyon mimarisi."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_architectures_og.jpg"
canonicalUrl: "https://tinycto.tv/tr/zero-trust/architectures/cilium-ebpf-microsegmentation"
locale: "tr"
---

# Kernel-Level eBPF L3-L7 Kubernetes Microsegmentation (`zt-arch-05`)

> **Sütun**: NETWORKS | **Arketip**: NETWORK_MICROSEGMENTATION
> **Engellenen MITRE ATT&CK Teknikleri**: T1046, T1021, T1090, T1567

## Mimari Özeti

Yavaş iptables kurallarını ortadan kaldıran, çekirdek seviyesinde Cilium eBPF ile kriptografik kimlik tabanlı L3/L4/L7 paket filtreleme ve şeffaf WireGuard şifrelemesi sağlayan mikro-segmentasyon mimarisi.

## Saldırgan Modeli

Ele geçirilen web konteynerinin pod ağı üzerinde port taraması ve veritabanlarına yetkisiz sızma girişiminde bulunması.

## NIST SP 800-207 Temel İlkeleri

- All communication is secured regardless of network location.
- Access to resources is determined by dynamic policy including client identity and application characteristics.

## 3 Kademeli Olgunluk Yapılandırmaları

### INITIAL Seviyesi

- **Uygulama Kapsamı**: Cilium installed in kube-proxy replacement mode across single cluster.
- **Kimlik Doğrulama Zorlaması**: L3/L4 NetworkPolicies blocking cross-namespace traffic by default.
- **Ağ İzolasyonu**: Pod-to-pod network separation without in-transit encryption.

### ADVANCED Seviyesi

- **Uygulama Kapsamı**: Multi-cluster Cilium ClusterMesh with transparent node-to-node WireGuard encryption.
- **Kimlik Doğrulama Zorlaması**: L7 HTTP/gRPC method and path authorization enforced via eBPF.
- **Ağ İzolasyonu**: DNS-aware egress policies restricting pods to explicit external FQDNs.

### OPTIMAL Seviyesi

- **Uygulama Kapsamı**: Zero-trust runtime fabric with eBPF-enforced SPIFFE identity validation and BGP peering.
- **Kimlik Doğrulama Zorlaması**: Cryptographic mutual authentication per packet with automated revocation.
- **Ağ İzolasyonu**: Complete isolation of control plane, tenant workloads, and GPU compute fabrics.

## Terraform HCL Manifest

```hcl
resource "helm_release" "cilium" {
  name       = "cilium"
  repository = "https://helm.cilium.io/"
  chart      = "cilium"
  namespace  = "kube-system"

  set {
    name  = "kubeProxyReplacement"
    value = "true"
  }
  set {
    name  = "encryption.enabled"
    value = "true"
  }
  set {
    name  = "encryption.type"
    value = "wireguard"
  }
}
```

## Kubernetes / Tetragon Policy Manifest

```yaml
apiVersion: "cilium.io/v2"
kind: CiliumNetworkPolicy
metadata:
  name: "secure-payment-gateway"
  namespace: "production"
spec:
  endpointSelector:
    matchLabels:
      app: payment-api
  ingress:
  - fromEndpoints:
    - matchLabels:
        app: checkout-frontend
    toPorts:
    - ports:
      - port: "8443"
        protocol: TCP
      rules:
        http:
        - method: "POST"
          path: "/v1/charges"
  egress:
  - toFQDNs:
    - matchName: "api.stripe.com"
    toPorts:
    - ports:
      - port: "443"
        protocol: TCP
```


```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Kernel-Level eBPF L3-L7 Kubernetes Microsegmentation | Zero-Trust Architecture Canon",
  "description": "Yavaş iptables kurallarını ortadan kaldıran, çekirdek seviyesinde Cilium eBPF ile kriptografik kimlik tabanlı L3/L4/L7 paket filtreleme ve şeffaf WireGuard şifrelemesi sağlayan mikro-segmentasyon mimarisi.",
  "url": "https://tinycto.tv/tr/zero-trust/architectures/cilium-ebpf-microsegmentation"
}
```
