Sidecar-less security: Inside the Sunesis CHAMELEON architecture

Cloud-native infrastructure is inherently vulnerable because static deployments give attackers the time they need to move laterally and persist undetected. The CHAMELEON project, powered by the EU-funded project Resilmesh, eliminates this vulnerability by bringing Moving Target Defence (MTD) to Kubernetes.

In this interview, Eva Zupancic, CEO at Sunesis, shares how they built a lightweight, sidecar-less architecture to bridge the gap between theoretical research and industrial-scale cybersecurity.

1. Why are you doing what you’re doing?

Cloud-native infrastructures are built for incredible scale, but they are fundamentally flawed when it comes to proactive security. The industry standard currently relies on static deployment topologies and resource-heavy, sidecar-based service meshes (like Istio). This creates a massive attack surface and gives cyber threat actors their most valuable asset: time. This “dwell time” allows attackers to execute reconnaissance, move laterally, and establish persistence completely undetected. We are building the CHAMELEON project because the industry urgently needs to stop reacting to breaches and start adopting a proactive, “secure-by-design” architecture.

2. How are you solving it?

We solve this by turning static infrastructure into a moving target. Through our CHAMELEON framework, we operationalize Moving Target Defense (MTD) directly within Kubernetes environments. Our custom Operator continuously and unpredictably rotates microservice instances, injects configuration jitter, and deploys deceptive honeytokens. To make this extreme, high-frequency rotation possible without breaking the system, we engineered a lightweight, sidecar-less service mesh powered by NATS JetStream. By utilizing event-driven, subject-based routing instead of traditional proxy tables, we achieve automated system renewal with absolute zero message loss and zero service downtime.

3. Why is your company adding value?

At Sunesis, our core advantage lies at the intersection of deep distributed systems engineering and advanced cybersecurity. Most modern security vendors try to solve vulnerabilities by adding layers – more agents, heavier proxies, and more computational overhead. We do the exact opposite. By stripping out the resource-heavy sidecars and utilizing highly optimized NATS communication, we drastically reduce the CPU and memory footprint of the cluster. We make security a native, invisible behavior of the infrastructure itself. We are proving that you don’t have to sacrifice system performance to achieve military-grade resilience.

4. What was the best thing about being in Resilmesh?

Resilmesh provided the ideal ecosystem to bridge the gap between advanced theoretical research and real-world industrial application. It gave us a highly complex, standardized environment (the SOAPA framework) to properly stress-test our sidecar-less architecture. Integrating CHAMELEON natively into the broader Resilmesh platform allowed us to validate our closed-loop mitigation and telemetry flows at scale. Beyond the tech, the collaboration with top-tier European partners is invaluable, enabling us to share our findings—like our open CRD-2026 resilience dataset—directly with the broader EU cybersecurity community.

Facebook
LinkedIn
X