WZ-IT connects cluster networking, ingress and gateway, DNS and TLS with identity-based access through NetBird. Public services are exposed safely while internal services avoid unnecessary internet exposure.
The following are trademarks of their respective owners: NetBird (NetBird GmbH). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services.
Kubernetes services
From target architecture through infrastructure and delivery to ongoing operations. Each page explores one part of the same accountable platform.
Kubernetes networking and secure access solve different problems. We design their transitions intentionally so internal admin and business services stay private while public applications receive a controlled entry point.
CNI, services, network policies, namespaces and egress rules govern communication within the platform.
Ingress or Gateway API, load balancers, DNS, certificates, rate limits and optional upstream protection.
Cluster API, dashboards and internal services through NetBird routing peers, network resources and access policies.
OIDC, groups, roles, devices and contractor access are bound to concrete resources and purposes.
Users, locations, services, protocols and traceability requirements define the access model. Ingress, private networks, NetBird policies and administrative access paths follow from it.
Separate public, partner, internal, administrative and cluster infrastructure.
Separate identities, networks, tenants, sites and data flows.
Choose ingress/gateway or private NetBird access for each service.
Implement RBAC, network policies, SSO/MFA and NetBird policies consistently.
Monitor access, certificates, routes and changes and keep them revocable.
From packet flow inside the cluster to the browser or administration device, we consider the complete path and its responsibility boundaries.
Cilium or an appropriate CNI, namespace boundaries, default deny, required flows and network observability.
Traefik, ingress-nginx or Gateway API with load balancing, TLS, redirects and controlled exposure.
cert-manager, DNS automation, internal and public zones and a traceable certificate lifecycle.
Routing peers and network resources for cluster API, dashboards, internal applications and contractor access.
Map identity providers, groups and roles consistently across Kubernetes, platform tools and private access.
Monitor flows, errors, latency, certificates and reachability so root causes remain discoverable.
In addition to the cluster, applications need defined processes for delivery, access, observability, recovery and technical ownership.
GitOps, CI/CD, separate environments, approvals and reproducible rollbacks.
CNI, network policies, ingress or gateway, DNS, TLS and private access.
OIDC, RBAC, secrets, image validation, policies and traceable changes.
Metrics, logs, traces, alerting and SLOs for platform and applications.
Cluster state, persistent data, restore tests and a documented recovery path.
Updates, CVE assessment, capacity, costs and an agreed operating model.
Knowledge base
Boundaries
CNI and network policies govern workload communication. NetBird creates a private, identity-based access path to selected resources. For publicly reachable applications, ingress or Gateway API remains the regular production path.
Move to the part of the platform that matters most for your current initiative.
Clear answers on architecture, delivery, responsibilities and ongoing operations.
Yes. Routing peers and network resources can expose selected services or networks to authorized NetBird users. Identities and policies limit who can access each resource.
No. A CNI provides the pod and service network and implements network policies inside the cluster. NetBird complements the design with private access from users, devices or sites to selected resources.
Typically through a load balancer and ingress controller or Gateway API, combined with DNS, TLS, rate limits and, where required, WAF or DDoS protection. Internal administration services receive a separate private access path.
Yes. Depending on infrastructure and cluster design, the API endpoint can be limited to management networks or NetBird. Access is additionally protected by Kubernetes authentication and RBAC.
Yes. NetBird, WireGuard and classic routing or site-to-site designs can connect locations and private networks. Routes, access policies, DNS and failure behavior are designed together.
We classify public, internal and administrative access and derive the network, exposure and identity policies.
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.
Timo Wevelsiep & Robin Zins
Managing Directors of WZ-IT
