Add a warning when TLS isn't enabled for Hubble Relay
details
- Finding IDs
- F-CILIUM-001-002
- Status
- merged to main/pre-release only
- Recorded credit
- Reported by @1seal
- Reported date
- Rationale
- warns that Hubble Relay without TLS exposes sensitive observability data to any reachable in-cluster client outside the intended trust boundary. public PR #44772 merged on 2026-04-22 and is present in main / v1.20.0-pre.* only; not fixed for stable users in v1.19.5, v1.18.11, or v1.17.17.
- PR opened by
- @ferozsalam
- PR state observed
- closed; GitHub merged: true; 2026-09-24
- PR observation basis
- Public PR metadata recorded in the 2026-09-24 evidence audit; not a live status feed.
- Contribution boundary
- Report-associated upstream work; @1seal code authorship is not claimed. Credit, where recorded, is a separate fact.
F-CILIUM-001-002: Secret handling. The contribution warns about unprotected Relay transport; it does not enable TLS by default. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-CILIUM-001-002
Security area (1seal assessment): Confidentiality. The change warns about unencrypted Hubble Relay/UI traffic; it does not itself enable TLS. Reviewed 21 Sep 2026.