Axera
FAQ

Questions, answered.

What teams ask when evaluating a self-hosted microsegmentation and NDR platform for Kubernetes.

Does Axera require a specific CNI?

No. The eBPF flow agent is CNI-agnostic and works on OVN-Kubernetes, Cilium, Calico and others. Enforcement uses standard Kubernetes NetworkPolicy (and Istio AuthorizationPolicy where a mesh is present).

Is anything sent to the cloud?

No. Axera is fully self-hosted — the operator, agents, data stores and console all run in your clusters. AI triage can run on-prem with Ollama, or you can opt into an external provider.

Does it enforce automatically?

Segmentation is deploy-when-you-approve by default. NDR active response ships opt-in behind a master switch — you decide whether Axera contains a workload on its own, and every action is verified and auditable.

Do I need a service mesh?

No. Observe and Segment work without a mesh. If you run Istio (ambient or sidecar), Axera adds L3/L4 AuthorizationPolicy alongside NetworkPolicy.

How is it installed?

As a Red Hat certified operator from OperatorHub — one Axera custom resource deploys the whole platform. Helm is available for vanilla Kubernetes, and disconnected/air-gapped installs are supported.

Where does the data live?

In PostgreSQL and Kafka you control — external for production, or in-cluster for evaluation. Nothing leaves your perimeter unless you route it to your SIEM.

Still have a question? Ask us in a demo →