Miguel Duarte Barroso
Miguel is a Principal Software Engineer for Openshift Virtualization at Red Hat.
His main interests are SDN / NFV, functional programming, containers, and virtualization.
Miguel is a member of the Network Plumbing Working Group, a maintainer of several CNI plugins (whereabouts, macvtap), and a contributor to some others (ovn-kubernetes, multus).
Red Hat
Job title –Principal Software Engineer
Session
By default, Kubernetes networking follows an open model—every pod within a cluster is connected to a single, shared network, allowing unrestricted communication. To enforce traffic restrictions, users must manually define Network Policies, which can be complex and cumbersome to design.
But what if we could rethink how Kubernetes networks are designed?
Join our interactive workshop as we challenge conventional Kubernetes networking. Using OVN-Kubernetes (a robust networking solution for Kubernetes) and KubeVirt (a virtual machine orchestrator for Kubernetes), we’ll explore how to create multiple, isolated cluster networks within the same Kubernetes cluster.
Through step-by-step guidance, you’ll learn how to:
✅ Set up a KIND (Kubernetes in Docker) cluster with OVN-Kubernetes and KubeVirt plugins
✅ Create multiple user-defined, isolated networks
✅ Attach workloads (VMs and pods) to these networks
✅ Achieve native workload isolation through network segmentation—without extra policy configurations
This hands-on tutorial will equip you with practical skills to secure Kubernetes workloads easily while meeting high-security standards. No more complex Network Policies—just simple, effective isolation.
Ready to rethink Kubernetes networking? Join us and take control of your cluster’s connectivity! No prior experience required! Just bring your laptop with Podman (or Docker), Kind and Kubectl installed.