Submitted:
06 January 2026
Posted:
07 January 2026
You are already at the latest version
Abstract
Keywords:
1. Introduction
- We identify and analyze the interplay between security and energy efficiency in K8s environments.
- We implement and evaluate a range of common K8s security mechanisms, providing insights into their impact on energy consumption.
- We investigate diverse cluster operating conditions, including a realistic, containerized e-commerce workload with reproducible load generation and observability to measure the security-energy interactions.
2. Background
2.1. Traffic Encryption
2.2. Runtime Security
2.3. Network Security Monitoring
2.4. Vulnerability Scanning
2.5. Energy Observability
3. Related Work
4. Experimentation Setup and Methodology
4.1. Experimental Setup
4.2. Experimental Workflow and Scenarios
- Encryption: WireGuard, Istio (mTLS).
- Runtime: Falco, Cilium Tetragon.
- Network Monitoring: Zeek.
- Vulnerability Scanning: Trivy.
4.3. Synthetic Workload and Triggering Mechanisms
4.4. Energy Attribution
5. Results
5.1. Encryption Consumption
5.2. Runtime Detection Consumption
5.3. Network Security Monitoring Consumption
5.4. Energy Consumption over Realistic Workload
5.5. Vulnerability Scanning Consumption
5.6. Overall Consumption
6. Conclusion and Future Work
Author Contributions
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
| 1 | |
| 2 | |
| 3 | |
| 4 | |
| 5 | |
| 6 | |
| 7 | |
| 8 | |
| 9 | |
| 10 | |
| 11 | |
| 12 | |
| 13 | |
| 14 | |
| 15 | |
| 16 |
References
- European Commission. Commission Recommendation (EU) 2024/2143 of 29 July 2024 setting out guidelines for the interpretation of Article 3 of Directive (EU) 2023/1791 of the European Parliament and of the Council as regards the energy efficiency first principle. https://eur-lex.europa.eu/eli/reco/2024/2143/oj/eng, 2024. Notified under document C(2024) 5284. Official Journal of the European Union, L series, 9 August 2024.
- Mao, Y.; Yu, X.; Huang, K.; Zhang, Y.J.A.; Zhang, J. Green edge AI: A contemporary survey. Proceedings of the IEEE 2024.
- Almihat, M.G.M.; Kahn, M.T.E.; Aboalez, K.; Almaktoof, A.M. Energy and Sustainable Development in Smart Cities: An Overview. Smart Cities 2022, 5, 1389–1408. [CrossRef]
- Szpilko, D.; Fernando, X.; Nica, E.; Budna, K.; Rzepka, A.; Lăzăroiu, G. Energy in Smart Cities: Technological Trends and Prospects. Energies 2024, 17. [CrossRef]
- Snousi, H.M. Adaptive fog computing architecture for scalable smart city infrastructure. In Proceedings of the ECCSUBMIT Conferences, 2025, Vol. 3, pp. 52–60.
- Aslanpour, M.S.; Toosi, A.N.; Cheema, M.A.; Chhetri, M.B. FaasHouse: sustainable serverless edge computing through energy-aware resource scheduling. IEEE Transactions on Services Computing 2024, 17, 1533–1547.
- Rana, M.; Mamun, Q.; Islam, R. Balancing Security and Efficiency: A Power Consumption Analysis of a Lightweight Block Cipher. Electronics 2024, 13. [CrossRef]
- Donenfeld, J.A. WireGuard: Next Generation Kernel Network Tunnel. In Proceedings of the NDSS, 2017, pp. 1–12.
- Center for Internet Security. CIS Kubernetes Benchmark v1.11.1. Center for Internet Security, 2025. Available at https://www.cisecurity.org/benchmark/kubernetes.
- National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA), 2022.
- Fahad, M.; Shahid, A.; Manumachu, R.R.; Lastovetsky, A. A Comparative Study of Methods for Measurement of Energy of Computing. Energies 2019, 12. [CrossRef]
- Amaral, M.; Chen, H.; Chiba, T.; Nakazawa, R.; Choochotkaew, S.; Lee, E.K.; Eilam, T. Kepler: A Framework to Calculate the Energy Consumption of Containerized Applications. In Proceedings of the 2023 IEEE 16th International Conference on Cloud Computing (CLOUD). IEEE, 2023. [CrossRef]
- Centofanti, C.; Santos, J.; Gudepu, V.; Kondepu, K. Impact of power consumption in containerized clouds: A comprehensive analysis of open-source power measurement tools. Computer Networks 2024, 245, 110371. [CrossRef]
- Pijnacker, B.; Setz, B.; Andrikopoulos, V. Container-level Energy Observability in Kubernetes Clusters. arXiv preprint arXiv:2504.10702 2025.
- Werner, S.; Borges, M.C.; Wolf, K.; Tai, S. A Comprehensive Experimentation Framework for Energy-Efficient Design of Cloud-Native Applications. In Proceedings of the 2025 IEEE 22nd International Conference on Software Architecture (ICSA). IEEE, 2025, pp. 176–186.
- Kaur, K.; Garg, S.; Kaddoum, G.; Ahmed, S.H.; Atiquzzaman, M. KEIDS: Kubernetes-based energy and interference driven scheduler for industrial IoT in edge-cloud ecosystem. IEEE Internet of Things Journal 2019, 7, 4228–4237.
- Rao, W.; Li, H. Energy-aware Scheduling Algorithm for Microservices in Kubernetes Clouds. Journal of Grid Computing 2025, 23, 2.
- Beena, B.; Ranga, P.C.; Holimath, V.; Sridhar, S.; Kamble, S.S.; Shendre, S.P.; Priya, M.Y. Adaptive Energy Optimization in Cloud Computing Through Containerization. IEEE Access 2025.
- Ali, D.; Sofia, R.C. Experimenting with Energy-Awareness in Edge-Cloud Containerized Application Orchestration, 2025, [arXiv:cs.NI/2511.09116].
- Koukis, G.; Skaperas, S.; Kapetanidou, I.A.; Mamatas, L.; Tsaoussidis, V. Evaluating CNI Plugins Features & Tradeoffs for Edge Cloud Applications. In Proceedings of the 2024 IEEE Symposium on Computers and Communications (ISCC), 2024, pp. 1–6. [CrossRef]
- Kapetanidou, I.A.; Nizamis, A.; Votis, K. An evaluation of commonly used Kubernetes security scanning tools. In Proceedings of the 2025 2nd International Workshop on MetaOS for the Cloud-Edge-IoT Continuum, 2025, pp. 20–25.
- Viktorsson, W.; Klein, C.; Tordsson, J. Security-performance trade-offs of kubernetes container runtimes. In Proceedings of the 2020 28th International symposium on modeling, analysis, and simulation of computer and telecommunication systems (MASCOTS). IEEE, 2020, pp. 1–4.
- Koukis, G.; Skaperas, S.; Kapetanidou, I.A.; Tsaoussidis, V.; Mamatas, L. An Open-Source Experimentation Framework for the Edge Cloud Continuum. In Proceedings of the IEEE INFOCOM 2024 - IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS), 2024, pp. 01–07. [CrossRef]









| Work | Category | Domain | Technique | Platform | Key findings |
|---|---|---|---|---|---|
| Amaral et al. [12] | Energy attribution/ measurement | Cloud-native observability | eBPF + HW counters; model with RAPL/NVML when available | K8s; pod/node metrics (Prometheus) | Low error reported overall |
| Pijnacker et al. [14] | Energy attribution/ measurement | Cloud-native observability | Split node power (Redfish static/dynamic) and redistribute dynamic by CPU usage | K8s; iDRAC/Redfish | Accurate node totals; misattribution in container level |
| Werner et al. [15] | Architecture energy efficiency | Cloud microservices | Architecture comparison—Monolith, Serverless (Knative), Runtime Improvement (GraalVM), Service Reduction | K8s; TeaStore | Runtime Improvement lowers energy per request; Serverless increases energy |
| Kaur et al. [16] | Energy-aware control | IIoT, Edge-Cloud orchestration | Scheduler minimizing energy/carbon and interference | K8s Edge-Cloud | Improvement in interference and energy utilization over baselines |
| Rao & Li [17] | Energy-aware control | Cloud data-center microservices | ISSA-based placement | K8s; microservices web apps | At least 5% energy reduction |
| Beena et al. [18] | Energy-aware control | Containerized cloud | ACO/PSO + DVFS with ARAA/ARKLM | K8s | DVFS lowest average CPU; ACO fastest completion |
| Aslanpour et al. [6] | Energy-aware control | Smart-city / IoT edge | Energy-aware scheduler using node SoC/capacity; House-Allocation-style placement | k3s + OpenFaaS; 10x RPi edge cluster; | 76% reduction in wasted energy vs. K8s |
| Ali & Sofia [19] | Energy-aware control | Edge-Cloud IoT | CODECO PDLC-CA: energy-aware node ranking from energy metrics; scheduler recommendations | k3s on Raspberry Pi 4 + laptop master; Kepler/Prometheus; JMeter | Lower energy that default K8s (especially at high load) |
| Snousi et al. [5] | Energy-aware control | Smart-city IoT | Context-aware Decision Engine + LSTM-based Resource Orchestration for predictive placement | K8s across edge-fog-cloud | 31% lower energy |
| Koukis et al. [20] | Security measures resource utilization | Edge-Cloud networking and security | CNI + security features: tunneling, WireGuard/IPsec, eBPF, Istio | Vanilla K8s and MicroK8s | WireGuard drives highest CPU and Istio highest throughput |
| Kapetanidou et al. [21] | Security measures resource utilization | Cloud-native security | Vulnerability and misconfiguration scanners | K8s | Low overall overhead; Trivy peaks higher in memory |
| Viktorsson et al. [22] | Security measures resource utilization | Cloud-native runtime isolation | Container runtimes runC vs gVisor vs Kata | K8s; Redis, Spark, TeaStore | Hardened environments are slower and add memory overhead |
| Parameter | System Specifications |
|---|---|
| Cluster Nodes | 3 (1 Control Plane, 2 Worker nodes) |
| Hardware Specs per node | 4 vCPUs, 4 GB RAM, 40 GB storage |
| Kernel Version | 5.15.0 |
| Containerd Version | 1.7.26 |
| Kubernetes Distribution | Vanilla K8s |
| Kubernetes Version | 1.31 |
| CNI Plugin & Version | Calico (v3.29.1) |
| Experiment | Baseline | Exp. Baseline | Avg. diff. from baseline | Max diff. from baseline | Avg. diff. from exp. baseline | Max diff. from exp. baseline |
|---|---|---|---|---|---|---|
| WireGuard | 242.32 W | 249.50 W | 24.57 W | 36.18 W | 17.39 W | 29 W |
| Istio | 242.32 W | 249.50 W | 15.70 W | 26.18 W | 8.52 W | 19 W |
| Falco + EG | 242.32 W | 249.17 W | 9.12 W | 11.58 W | 2.27 W | 4.73 W |
| Tetragon + EG | 242.32 W | 249.17 W | 8.01 W | 9.98 W | 1.16 W | 3.13 W |
| Zeek | 242.32 W | 255.64 W | 14.20 W | 18.58 W | 0.88 W | 5.26 W |
| Trivy | 242.32 W | 244.62 W | 15.64 W | 23.68 W | 13.34 W | 21.38 W |
| OB + Load | 242.32 W | 243.73 W | 2.63 W | 4.18 W | 1.22 W | 2.77 W |
| OB + Load + Security | 242.32 W | 244.95 W | 4.02 W | 5.58 W | 1.39 W | 2.95 W |
| OB + Security | 242.32 W | 243.73 W | 2.30 W | 2.88 W | 0.89 W | 1.47 W |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).