Kubernetes

Securely access Kubernetes clusters

Reach every cluster, pod, workload and service without port forwarding, VPN gateways or complex firewall configs. Cerberus builds direct, encrypted WireGuard® peer-to-peer connections between clusters, workloads and external resources, giving your teams fast, reliable remote access that stays governed end to end by Zero Trust.

ClusterAPI serverPodskubectlCI runner
Encrypted peer-to-peer tunnel

Private access to every cluster

Reach the API server, pods and services over an encrypted mesh, never the public internet, scoped per user and per namespace to your identity provider.

How it works

1

Install as a DaemonSet

Deploy Cerberus to your cluster with a single manifest or Helm chart. New nodes join the network automatically.

2

Connect over the mesh

Reach the API server, ClusterIP services and pods directly, and resolve in-cluster DNS from your laptop or CI.

3

Scope access by identity

Grant per-user and per-namespace access mapped to your identity provider, with short-lived keys for CI/CD.

Connectivity

Connect external workloads to services

Cerberus seamlessly connects non-Kubernetes workloads, applications and databases with your Kubernetes services.

Reach ClusterIP services directly
Resolve in-cluster DNS from anywhere
No ingress or port-forward workarounds
LaptopServerMobileCloud
Encrypted peer-to-peer tunnel
Control plane

Securely access the control plane

Direct remote access to the Kubernetes API from anywhere, without exposing it to the public internet.

Keep the API server off the public internet
Authenticate kubectl with your identity provider
No bastion hosts or jump boxes to run
Access

Manage access to Kubernetes

Granular access control lets you manage which user and server groups can reach production or development clusters.

Per-namespace, least-privilege access
Scoped, short-lived access for CI/CD runners
Every access logged and auditable
UserPolicyServer
Encrypted peer-to-peer tunnel

Secure your clusters today

Give your team and pipelines private, least-privilege access in minutes. No bastions, no public endpoints.