Skip to content
Docs · Network flows

Integrations

Network flows

Live flows and topology from Cilium Hubble, Calico Whisker or NetObserv.

When a cluster runs a supported flow backend, a Network Flows row appears in the sidebar. Kubyl picks the backend automatically, in this order:

  1. Cilium Hubble Relay, over gRPC through a temporary loopback port-forward. TLS is supported.
  2. Calico Whisker.
  3. NetObserv, through Loki.

Override per cluster with netflow.clusters.<id>.backend (hubble, whisker, netobserv or off) and the matching hubble, whisker or loki endpoint settings.

Flows and topology

The Flows table lists individual connections. The Topology is a force-directed graph you can zoom between Namespaces and Workloads. Nodes are sized by volume, edge width shows volume, and verdict styles distinguish forwarded, dropped (dashed) and no-reply traffic. Drag to pan, scroll to zoom, click to select and double-click to filter to a node or edge.

Scope a view to a cluster or a namespace (Open Namespace Network Flows on a favorite). The time window defaults to 15 minutes.

KeysAction
EnterFlow details (table) / show flows of the selection (topology)
SpacePause
CorSorDFilter to the connection / source / destination
TSwitch between flow table and topology
OOpen the pod
GJump to the newest flows
NorWTopology by namespaces / workloads
FFit the graph
]or[Next / previous connection

Filter language

Keys: ns, pod, workload, ip, port, kind, node, service, label, proto, dir, verdict, policy, reason, bytes, packets, http.method, http.code, http.path and dns. Operators are =, !=, >, <, >= and <=. Commas mean OR, * is a glob, values can be quoted, a src. or dst. prefix restricts a term to one side, and bare words are free text. The filter box completes keys and values.

Example
ns=payments verdict=dropped dst.port=5432,6379 src.workload=api-*

Privacy

Flows are never saved to disk, only view options are. URL query values in HTTP flows are dropped unless you set netflow.keep_query_values. netflow.max_flows (20,000) and netflow.max_age_minutes (60) bound memory use.

Limitations

  • Hubble with mutual TLS is reported as unsupported.
  • Hubble doesn't report byte or packet counts per flow.
  • NetObserv behind a LokiStack gateway shows metrics only.
  • Drops on OVN-Kubernetes don't include ACL names.

Something missing or wrong? Open an issue on GitHub.