Changelog

Changelog

New features, improvements, and fixes across Nyx — policy enforcement, observability, and AI-assisted workflows for Kubernetes.

Nyx 1.1

From seeing to understanding

Nyx 1.0 gave you kernel-native visibility and control over your cluster's network — on Linux and Windows nodes alike, with a minimal footprint. Nyx 1.1 goes from seeing your network to understanding it: it learns what normal looks like, flags what isn't, watches your workloads' health, and lets each team focus on its own slice of a shared cluster.

Anomaly detection

Nyx now learns what normal looks like for each namespace — a seven-day, time-of-week-aware baseline of connection and deny rates — and raises an alert when behaviour deviates from it. A namespace that's quiet every night but suddenly chatty at 3am gets flagged, even if the same traffic level would be unremarkable at noon.

Every anomaly comes with a plain-language, AI-generated explanation of what fired and why. Detection itself is statistical; the AI's job is to make the alert readable — what changed, compared to what baseline, and where to look next.

Anomaly detection starts working once the baseline has learned your cluster's rhythm. Nyx observes before it alerts — a fresh install won't cry wolf on day one.

First-seen destination alerts

The classic exfiltration and command-and-control signal: a workload reaches out to an external host it has never contacted before. Nyx now alerts the first time it happens.

Because TLS destinations are captured via SNI, this covers HTTPS endpoints by hostname — not just IP. A new connection to an unfamiliar domain is visible as exactly that.

With this release, Nyx watches for suspicious behaviour four complementary ways: a fixed line you set (thresholds), a known-bad signature (metadata-API probes, lateral movement), unusual-for-you (anomaly detection), and never-seen-before (first-seen destinations). One detection model misses what the others catch.

Workload health

Network security tools usually stop at the wire. Nyx now understands the workloads behind it.

Pod restart counts, readiness, crashloop and zombie detection, and node hotspots are available as dashboard widgets — and the observe page now shows each workload's live health at a glance with a colour-coded vitals view. Workload health and network posture, in one place.

Nyx workload vitals panel showing the frontend deployment as healthy, with pod readiness, restart count, and services.

Product lens

Shared clusters are the norm; shared noise doesn't have to be. You can now filter everything — dashboards, flow logs, observe, and enforcement views — down to a single product.

The product lens shows your product's security perimeter: what stays inside it, what crosses in, and what leaves. It also shows your product's policy coverage, so a team can see exactly how much of its own surface is governed — without wading through everyone else's traffic.

Nyx traffic map filtered to the API Team product, showing its namespaces, traffic flows, and policy coverage.
Learn more about products in the docs

Improvements & fixes

  • Connection-rate dashboard widget — live connection rate charted against your namespace's seasonality-aware baseline, so spikes read as spikes, not guesses.
  • Better TLS visibility — destinations revealed by TLS SNI are now captured end to end, so egress to HTTPS endpoints is visible by hostname rather than IP.
  • More reliable enforcement — established connections now deterministically survive a new-connection deny, with identical behaviour on Linux and Windows. Parity that's real, not a checkbox.
  • Smarter AI — the models behind natural-language querying and policy generation have been upgraded for more accurate answers and better-fitting policy suggestions.
  • Alert threshold fix — greater-than-or-equal alert thresholds now fire correctly at the boundary value.

No updates match your search.

Start enforcing zero trust today.

Free Scout tier. Three namespaces. No credit card.
Upgrade when you're ready.