Skip to main content

Suite placement (PacketWolf)

Netra and PacketWolf are Zyvor suite counterparts covering the same eBPF territory from opposite directions — not a wired pipeline.

NetraPacketWolf
LicenseZyvor Production License v1.0Suite flagship
CNIAny / none (cgroup v2)Cilium required
Datapath/sys/fs/bpf/netra onlyHubble + Cilium maps + custom eBPF
EnforceTime-leased, fails open to observePlatform containment + AutoPolicy
Reach forNon-Cilium fleets, lighter emergency kill-switch, Path/Drop/Congestion diagnosticsCilium-standardized fleets needing full intelligence / operator tooling

On a Cilium cluster: PacketWolf owns day-2 network intelligence; Netra may run alongside for CNI-independent diagnostics and short-lease emergency denies. Both may read Hubble Relay independently. Netra never pins over Cilium-owned BPF maps.

There is no Netra↔PacketWolf API sync, shared CRD, or required install pair today. SIEM/Prometheus/webhooks export sideways into a third plane if you need a unified view.

Full co-existence rules: repository docs/packetwolf.md.

Next: Architecture · Security · zyvor.dev/packetwolf