开源AI工作流:云原生零信任安全 是 AI Skill Hub 本期精选Agent工作流之一。综合评分 7.5 分,整体质量较高。我们推荐使用将其纳入你的 AI 工具库,帮助提升工作效率。
云原生零信任安全,保护AI代理运行环境,实现安全可信赖的AI应用。
开源AI工作流:云原生零信任安全 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。
云原生零信任安全,保护AI代理运行环境,实现安全可信赖的AI应用。
开源AI工作流:云原生零信任安全 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。
# 克隆仓库 git clone https://github.com/spinningfactory/kloak cd kloak # 查看安装说明 cat README.md # 按 README 完成环境依赖安装后即可使用
# 查看帮助 kloak --help # 基本运行 kloak [options] <input> # 详细使用说明请查阅文档 # https://github.com/spinningfactory/kloak
# kloak 配置说明 # 查看配置选项 kloak --config-example > config.yml # 常见配置项 # output_dir: ./output # log_level: info # workers: 4 # 环境变量(覆盖配置文件) export KLOAK_CONFIG="/path/to/config.yml"
<p align="center"> <b>Secure Your Secrets, Agentless</b><br> Kubernetes eBPF HTTPS interceptor. Transparent secret injection without application changes or sidecars. </p>
</div>
---
Kloak transparently intercepts outbound TLS traffic in Kubernetes using eBPF uprobes, replacing hashed placeholders with real secrets at the kernel level before encryption. Applications never handle actual credentials, and no sidecars or code changes are required.
kl::<UUID>). Real secrets exist solely in eBPF maps and are injected in-kernel at TLS write time.getkloak.io/hosts are only sent to specific destination hostnames or IP addresses, preventing exfiltration to unauthorized servers.getkloak.io/port are restricted to connections on a specific destination port.crypto/tls. Works with Python, Node.js, Go, Rust, Ruby, PHP, curl, and any OpenSSL-linked runtime.kubectl configured with cluster accesshelm repo add kloak https://chart.getkloak.io
helm repo update
helm install kloak kloak/kloak -n kloak-system --create-namespace
kubectl get pods -n kloak-system
./examples/setup-demo.sh
export KUBECONFIG=/tmp/kloak-k3s.yaml
The webhook automatically rewrites volume mounts to use the shadow secret. Your application sees only kl::<UUID> placeholders and never handles real credentials.
```
```bash
| Component | Description |
|---|---|
| **Controller** (DaemonSet) | Watches Secrets labeled getkloak.io/enabled=true, creates shadow secrets with length-matched kl::<UUID> placeholders, syncs real values into eBPF maps, and attaches TLS uprobes to container processes via cgroup discovery. |
| **Webhook** (Deployment) | Mutating admission webhook that intercepts Pod creation. Rewrites Secret volume mounts to point to shadow secrets. Evaluates enablement through pod labels or namespace labels. Rejects pods if the shadow secret has not been created yet (fail-closed). Two webhook entries ensure only kloak-enabled namespaces and pods are affected; non-kloak workloads are never impacted, even when the webhook is down. |
| **TLS Uprobes** | Attach to SSL_write / SSL_write_ex (OpenSSL/BoringSSL) and crypto/tls.(*Conn).Write (Go native). Intercept outbound TLS writes, scan for kl:: prefixes. Two rewrite paths: Phase 2 for plaintext rewrite (before encryption), and XOR path for ciphertext patching (after encryption). |
| **XOR Path + TC Egress** | For Go native TLS: computes XOR diff in the uprobe, bridges through tcp_sendmsg kprobe to TC egress, which patches the encrypted packet in-flight and recomputes the GHASH authentication tag via a tail call to tc_ghash_update. |
| **DNS Kprobe** | Kprobe/kretprobe on udp_recvmsg captures DNS responses system-wide. Parses A/AAAA records for watched hostnames and populates dns_ip_map (IP to hostname) with TTL tracking. |
| **Connect/Close Tracepoints** | Hooks sys_enter/exit_connect to track TCP connections (fd to destination IP in conn_ip_map). When the destination matches a DNS-verified hostname, caches the fd in last_verified_fd. Hooks sys_enter_close to clean up stale entries. |
| **Process Tracepoints** | Hooks sched_process_exec and sched_process_exit to track container process lifecycle for uprobe attachment and cleanup. |
kloak开源AI工作流提供了云原生零信任安全保护AI代理的功能,实现安全可信赖的AI应用,但需要进一步优化和完善。
该工具使用 AGPL-3.0 协议,商用场景请仔细阅读协议条款,必要时咨询法律意见。
AI Skill Hub 为第三方内容聚合平台,本页面信息基于公开数据整理,不对工具功能和质量作任何法律背书。
建议在沙箱或测试环境中充分验证后,再部署至生产环境,并做好必要的安全评估。
⚠️ AGPL 3.0 — 最严格的 Copyleft,网络服务端使用也需开源,SaaS 使用受限。
经综合评估,开源AI工作流:云原生零信任安全 在Agent工作流赛道中表现稳健,质量良好。如果你已有明确的使用需求,可以直接上手体验;如果还在评估阶段,建议对比同类工具后再做决策。
| 原始名称 | kloak |
| Topics | workflowbpfebpfkubernetessecretssecrets-managementc |
| GitHub | https://github.com/spinningfactory/kloak |
| License | AGPL-3.0 |
| 语言 | C |
收录时间:2026-05-24 · 更新时间:2026-05-25 · License:AGPL-3.0 · AI Skill Hub 不对第三方内容的准确性作法律背书。
选择 Agent 类型,复制安装指令后粘贴到对应客户端