Security News

Cybersecurity news aggregator

☸️
INFO Updates Reddit r/netsec

Replacing Falco with an embedded eBPF sensor for Kubernetes runtime enforcement

  • What: New eBPF-based runtime enforcement for Kubernetes
  • Impact: Improves security for containerized environments
Read Full Article →

Writeup on how we built runtime enforcement into our k8s agent with eBPF instead of shipping Falco alongside it. Covers the syscall tracepoint design, in-kernel filtering with BPF maps, why we picked SIGKILL over BPF LSM, and a staging postmortem where enforcement wasn't namespace-scoped and we took out our own Harbor, Cilium, and RabbitMQ. submitted by /u/JulietSecurity [link] [comments]

Share this article