Mirrord 3.0 – Mirror a pod's network traffic and file system accesses locally
metalbear.co
metalbear.co
Does this tool work with any k8s cluster? or does one at first need to install an operator into their cluster?
Does this tool talk to kubernetes API? If yes - then does it rely on kubectl's config or what?
https://mirrord.dev/docs/overview/faq/ - Here I've found an answer to "how exactly does it do it's magic?":
> Does mirrord install anything on the cluster?
> No, mirrord doesn’t install anything on the cluster, nor does it have any persistent state. It does spawn a short-living pod/container to run the proxy, which is automatically removed when mirrord exits.
> If you have any restrictions for pulling external images inside your cluster, you have to allow pulling of ghcr.io/metalbear-co/mirrord image.
and also another important detail:
> Since mirrord uses the dynamic linker to load into the application’s process, it cannot load if the binary is statically linked.
We're currently working on a more enterprise-oriented version where you would have a persistent operator in the cluster, and it would let you properly manage RBAC, rather than relying on each user's kubectl.
Thanks for pointing all of this out! We'll try to make this info more easily accessible.