Hands-on Lab·Kubernetes and Cloud Native Security Associate
Service Mesh Security Capabilities
KCSA asks what a service mesh provides. The honest way to answer is to measure what is missing without one: this guide proves pod-to-pod traffic is in clear by reading it off the node, then shows the identity and HTTP-level policy this CNI already provides without a single sidecar.
Platform Security Guide 37 of 42 Advanced
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 20 min
- Reviewed25 August 2026
Written against the versions above. This cluster is Cilium 1.18.1 with `Encryption: Disabled` and Envoy running as one DaemonSet Pod per node. A sidecar mesh runs one proxy per Pod instead; the capabilities overlap and the deployment model does not.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 36 - the observability half of the same story.
- guide 27 - the L3/L4 policy this page goes beyond.
-
Is there a mesh here at all
-
Proving what unencrypted means
-
The identity policy is actually written against
-
Layer 7 policy, with no sidecar anywhere