When a cluster runs a supported flow backend, a Network Flows row appears in the sidebar. Kubyl picks the backend automatically, in this order:
- Cilium Hubble Relay, over gRPC through a temporary loopback port-forward. TLS is supported.
- Calico Whisker.
- NetObserv, through Loki.
Override per cluster with netflow.clusters.<id>.backend (hubble, whisker, netobserv or off) and the matching hubble, whisker or loki endpoint settings.
Flows and topology
The Flows table lists individual connections. The Topology is a force-directed graph you can zoom between Namespaces and Workloads. Nodes are sized by volume, edge width shows volume, and verdict styles distinguish forwarded, dropped (dashed) and no-reply traffic. Drag to pan, scroll to zoom, click to select and double-click to filter to a node or edge.
Scope a view to a cluster or a namespace (Open Namespace Network Flows on a favorite). The time window defaults to 15 minutes.
| Keys | Action |
|---|---|
| Enter | Flow details (table) / show flows of the selection (topology) |
| Space | Pause |
| CorSorD | Filter to the connection / source / destination |
| T | Switch between flow table and topology |
| O | Open the pod |
| G | Jump to the newest flows |
| NorW | Topology by namespaces / workloads |
| F | Fit the graph |
| ]or[ | Next / previous connection |
Filter language
Keys: ns, pod, workload, ip, port, kind, node, service, label, proto, dir, verdict, policy, reason, bytes, packets, http.method, http.code, http.path and dns. Operators are =, !=, >, <, >= and <=. Commas mean OR, * is a glob, values can be quoted, a src. or dst. prefix restricts a term to one side, and bare words are free text. The filter box completes keys and values.
ns=payments verdict=dropped dst.port=5432,6379 src.workload=api-*Privacy
Flows are never saved to disk, only view options are. URL query values in HTTP flows are dropped unless you set netflow.keep_query_values. netflow.max_flows (20,000) and netflow.max_age_minutes (60) bound memory use.
Limitations
- Hubble with mutual TLS is reported as unsupported.
- Hubble doesn't report byte or packet counts per flow.
- NetObserv behind a LokiStack gateway shows metrics only.
- Drops on OVN-Kubernetes don't include ACL names.