PageSourceSearch

https://cilium.io/component---src-templates-blog-post-jsx-content-…-in-review-index-md-a792f0fb4508da1ac754.js

js cilium.io collected 2026-09-24 08:29:34 UTC 21,221 bytes, 2 lines download raw bytes

1"use strict";(self.webpackChunkcilium_io=self.webpackChunkcilium_io||[]).push([[8569],{3864:function(e,n,t){t.r(n),t.d(n,{Head:function(){return h},default:function(){return g}});var a=t(8453),i=t(6540),r=t(6452);function o(e){const n=Object.assign({p:"p",strong:"strong",em:"em",span:"span",a:"a",h2:"h2",h3:"h3",h4:"h4",ul:"ul",li:"li"},(0,a.RP)(),e.components),{BlogAuthor:t}=n;return t||function(e,n){throw new Error("Expected "+(n?"component":"object")+" `"+e+"` to be defined: you likely forgot to import, pass, or provide it.")}("BlogAuthor",!0),i.createElement(i.Fragment,null,i.createElement(n.p,null,i.createElement(n.strong,null,i.createElement(n.em,null,"Author: Paul Arah, Isovalent"))),"\n",i.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 1008px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/76087e6f10c1449055ee72dde2fa9d4b/7385a/cover.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 52.38095238095239%; position: relative; bottom: 0; left: 0; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/76087e6f10c1449055ee72dde2fa9d4b/2ff5b/cover.webp 252w,\n/static/76087e6f10c1449055ee72dde2fa9d4b/4d583/cover.webp 504w,\n/static/76087e6f10c1449055ee72dde2fa9d4b/905a7/cover.webp 1008w,\n/static/76087e6f10c1449055ee72dde2fa9d4b/bb9f8/cover.webp 1512w,\n/static/76087e6f10c1449055ee72dde2fa9d4b/8fb31/cover.webp 1800w"\n              sizes="(max-width: 1008px) 100vw, 1008px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/76087e6f10c1449055ee72dde2fa9d4b/019e0/cover.png 252w,\n/static/76087e6f10c1449055ee72dde2fa9d4b/0dcb2/cover.png 504w,\n/static/76087e6f10c1449055ee72dde2fa9d4b/832a9/cover.png 1008w,\n/static/76087e6f10c1449055ee72dde2fa9d4b/19357/cover.png 1512w,\n/static/76087e6f10c1449055ee72dde2fa9d4b/7385a/cover.png 1800w"\n            sizes="(max-width: 1008px) 100vw, 1008px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/76087e6f10c1449055ee72dde2fa9d4b/832a9/cover.png"\n            alt="cover"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",i.createElement(n.p,null,"2024 has been a remarkable year for Tetragon. This year witnessed increased adoption, the release of many exciting features, a record number of conference talks, and exponential growth within the community. As we approach the year's end, we reflect on the progress made as a community and look ahead to the future."),"\n",i.createElement(n.p,null,"Since the initial release of Tetragon 1.0 last year, the sub-project has continued to set the standard for eBPF-based security observability and runtime enforcement. Platform and security teams worldwide, from small companies to prominent enterprises, use Tetragon to secure their environments efficiently and effectively."),"\n",i.createElement(n.p,null,"While the 2024 ",i.createElement(n.a,{href:"https://github.com/cilium/cilium.io/blob/main/Annual-Reports/Cilium_Annual_Report_2024.pdf"},"Cilium annual report")," covered some major statistics for the Tetragon project, this blog zooms in on what we, as a community, have accomplished this year."),"\n",i.createElement(n.h2,null,"Release Highlights"),"\n",i.createElement(n.h3,null,"Tetragon 1.1"),"\n",i.createElement(n.h4,null,"Kubernetes Identity-Aware Policies"),"\n",i.createElement(n.p,null,"Tetragon 1.1 introduced features that enabled deeper integration with Kubernetes, including Kubernetes Identity-Aware Policies. Previously, tracing policies (which define the situations Tetragon should react to and how) were applied at a cluster-wide scope. With this update, Tetragon’s security observability and runtime enforcement can be used with precision to specific Kubernetes workloads based on their identity. This improvement reduces noise and overhead while providing security tailored to specific workloads."),"\n",i.createElement(n.h4,null,"Redaction Filters"),"\n",i.createElement(n.p,null,"Tetragon events, exposed via gRPC and JSON logs, c
1an include sensitive information such as passwords or environment variables. Tetragon 1.1 introduced redaction filters, enabling users to redact specific fields from exported data, ensuring sensitive information is not inadvertently exfiltrated."),"\n",i.createElement(n.h4,null,"CRI-O Runtime Hooks Support"),"\n",i.createElement(n.p,null,'Tetragon requires Kubernetes metadata to enable Kubernetes Identity-Aware Policies. Retrieving this metadata from the Kubernetes API can cause delays between container startup and policy application, which is undesirable, especially in enforcement scenarios. Runtime hooks solve this issue by directly "hooking" into the container runtime system, ensuring the Tetragon agent sets up the necessary state before the container starts. With Tetragon 1.1, CRI-O runtime hooks are automatically configured via a Tetragon init container.'),"\n",i.createElement(n.h3,null,"Tetragon 1.2"),"\n",i.createElement(n.h3,null,"Persistent Enforcement"),"\n",i.createElement(n.p,null,"Before Tetragon 1.2, enforcement policies depended on the Tetragon agent’s uptime. If the agent went down—due to restarts or failures—the eBPF programs responsible for enforcement were removed, potentially causing a security lapse. Tetragon 1.2 ensures that the eBPF programs responsible for enforcement continue running even during agent downtime, enhancing security and minimizing risk."),"\n",i.createElement(n.h4,null,"Improved Child Process Visibility"),"\n",i.createElement(n.p,null,"Child process visibility is crucial for detecting malicious activities such as process injection and lateral movement. Tetragon already allowed tracking all child processes spawned by specific binaries, but earlier versions required users to rely on PID values, which can be non-deterministic. Version 1.2 introduced a more intuitive way to track process ancestry across complex execution chains."),"\n",i.createElement(n.h4,null,"Containerd Support"),"\n",i.createElement(n.p,null,"Containerd, one of the most popular container runtimes, is now supported in Tetragon 1.2. Previously, the runtime hook system enabling Kubernetes Identity-Aware Policies supported only CRI-O. With this update, the runtime hook system was redesigned from an init container to a DaemonSet, providing flexibility to support both CRI-O and Containerd. This expansion brings Tetragon’s full capabilities to a broader range of Kubernetes deployments."),"\n",i.createElement(n.h2,null,"Conferences"),"\n",i.createElement(n.p,null,"Tetragon had a strong presence at major cloud native events in 2024. These events included KubeCon, Cilium + eBPF Day, and CloudNativeSecurityCon. Here are some of the highlights:"),"\n",i.createElement(n.ul,null,"\n",i.createElement(n.li,null,i.createElement(n.a,{href:"https://www.youtube.com/watch?v=yWB8n_e4N14"},"Dealing with eBPF’s Observability Data Deluge - Anna Kapuścińska, Isovalent")),"\n",i.createElement(n.li,null,i.createElement(n.a,{href:"https://www.youtube.com/watch?v=ejkJiq7AMHs"},"Bee-Lieve in the Metadata: Pollenating Build Attestations on Kubernetes with Tetragon and EBPF - Tom Meadows, TestifySec")),"\n",i.createElement(n.li,null,i.createElement(n.a,{href:"https://www.youtube.com/watch?v=YDIW2CY8WPI"},"Brewing the Kubernetes Storm Center: Open Source Threat Intelligence for the Cloud Native Ecosystem - Constanze Roedig, Technische Universität Wien & James Callaghan, ControlPlane")),"\n",i.createElement(n.li,null,i.createElement(n.a,{href:"https://www.youtube.com/watch?v=YNDp7Id7Bbs"},"Don't Get Blown up! Avoiding Configuration Gotchas for Tetragon Newbies - Pratik Lotia, Reddit")),"\n",i.createElement(n.li,null,i.createElement(n.a,{href:"https://www.youtube.com/watch?v=QKE8WMv-6qw"},"What Agent to Trust with Your K8s: Falco, Tetrago, or KubeArmor? - Henrik Rexed, Dynatrace")),"\n",i.createElement(n.li,null,i.createElement(n.a,{href:"https://www.youtube.com/watch?v=Hw469I5GKmY"},"From Observability to Enforcement: Lessons Learned Implementing eBPF Runtime Security - Anna Kapuścińska & Kornilios Kourtis, Isovalent")),"\n",i.createElement(n.li,null,i.createElement(n.a,{href:"https://www.youtube.com/watch?v=towNkbPMDjE"},"Panel: Exploring eBPF Use Cases in Cloud-Native Security")),"\n",i.createElement(n.li,null,i.createElement(n.a,{href:"https://www.youtube.com/watch?v=4ACOEB4PnQo"},"Tutorial: Sailing the Security Seas with Tetragon - Duffie Cooley, Isovalent")),"\n"),"\n",i.createElement(n.h2,null,"Community Meetings"),"\n",i.createElement(n.p,null,"This year, we kicked off a monthly ",i.createElement(n.a,{href:"https://isogo.to/tetragon-meeting-notes"},"Tetragon community meeting")," on the second Monday of the month. We held the first community meeting in March and have held 9 community meetings so far this year baring the months where the community meetings coincided with KubeCon. The community meetings have been great to onboard new members to the community, discuss ongoing PRs, and learn about all the exciting work and development in Tetragon.\nWe look forward to continued participation and growth in the community meetings as we go into 2025."),"\n",i.createElement(n.h2,null,"Community Voices"),"\n",i.createElement(n.p,null,"The Tetragon community has shared many exciting testimonials about their experiences. One quote that encapsulates Tetragon's impact on cloud native security comes from Marcos Hernandez, Platform Engineering Lead at Google Cloud:"),"\n",i.createElement(n.p,null,i.createElement(n.strong,null,i.createElement(n.em,null,"“eBPF tracing is very powerful. I recently deployed a hashtag#Tetragon TracingPolicy CR to my Google Distributed Cloud Virtual (GDCV) clusters at the edge as an experiment. The level of visibility and control it offers through the various supported hook points is really cool. Love the programmatic, low level access to kernel events. hashtag#Cilium hashtag#GoogleDistributedCloud.”"))," - Marcos Hernandez, Platform Engineering Lead at Google Cloud (",i.createElement(n.a,{href:"https://www.linkedin.com/posts/activity-7270097966017703936-mvrp/?utm_source=share&utm_medium=member_desktop"},"Read the LinkedIn post"),")"),"\n",i.createElement(n.h2,null,"Looking Ahead"),"\n",i.createElement(n.p,null,"As we close the chapter on 2024, it’s clear that Tetragon has made significant str
1ides in enhancing cloud native security observability and runtime enforcement. From major feature releases to a growing community and vibrant presence at key conferences, the project’s trajectory is nothing short of inspiring."),"\n",i.createElement(n.p,null,"The Tetragon community’s dedication, innovation, and collaboration have been pivotal to this success. As we look to 2025, we are excited to continue pushing the boundaries of what’s possible with eBPF powered security observability and runtime enforcement with Tetragon, empowering teams worldwide to secure their cloud native environments with confidence."),"\n",i.createElement(n.p,null,"Here’s to another year of growth, innovation, and community-driven success. See you in 2025!"),"\n",i.createElement(n.p,null,"For the Tetragon Community:"),"\n",i.createElement(n.p,null,"Paul Arah\nCommunity Builder – Security"),"\n",i.createElement(t,r.A.PaulArah))}var s=function(e){void 0===e&&(e={});const{wrapper:n}=Object.assign({},(0,a.RP)(),e.components);return n?i.createElement(n,e,i.createElement(o,e)):o(e)};var l=t(8125),c=t(5805),u=t(8838),d=t(2744);const m=e=>{const{data:{mdx:n},children:t}=e,{frontmatter:{path:a,title:r,date:o,tags:s,ogSummary:u}}=n;return i.createElement(d.A,{headerWithSearch:!0},i.createElement(l.A,{path:a,content:t,date:o,title:r,tags:s,summary:u}),i.createElement(c.A,{className:"my-10 md:my-20 lg:my-28"}))},h=e=>{var n,t;let{data:{mdx:a,site:r},location:{pathname:o}}=e;const{frontmatter:{title:s,ogImage:l,ogSummary:c,dateIso:d,tags:m,author:h}}=a,{siteUrl:g}=r.siteMetadata,p=`${c.slice(0,133)}...`,b=`${g}${o}`,f=null!=l&&null!==(n=l.childImageSharp)&&void 0!==n&&null!==(t=n.resize)&&void 0!==t&&t.src?`${g}${l.childImageSharp.resize.src}`:null,y={title:s,description:p,image:l||null,slug:o},w={"@context":"https://schema.org","@type":"BlogPosting",headline:s,description:p,url:b,datePublished:d,dateModified:d,author:h?{"@type":"Person",name:h}:{"@type":"Organization",name:"Cilium",url:g},publisher:{"@type":"Organization",name:"Cilium",url:g,logo:{"@type":"ImageObject",url:`${g}/images/social-preview.jpg`}},...f&&{image:{"@type":"ImageObject",url:f,width:1200,height:630}},...(null==m?void 0:m.length)>0&&{keywords:m.join(", ")}};return i.createElement(u.A,{data:y,type:"article",datePublished:d,jsonLd:w})};function g(e){return i.createElement(m,e,i.createElement(s,e))}}
1,6452:function(e,n){n.A={thomasGraf:{header:"Thomas Graf",bio:'Thomas Graf is a Co-Founder of Cilium and the CTO & Co-Founder of <a href="https://isovalent.com/?utm_source=website-cilium&utm_medium=referral&utm_campaign=cilium-enterprise">Isovalent</a>, the company behind Cilium. Before that, Thomas spent 15 years as\n    a kernel developer working on the <a href="https://kernel.org">Linux kernel</a> in networking, security and eventually eBPF.'},lizRice:{header:'<a href="https://twitter.com/lizrice">Liz Rice</a>',bio:'Liz is Chief Open Source Officer at <a href="https://isovalent.com/?utm_source=website-cilium&utm_medium=referral&utm_campaign=cilium-enterprise" target="_blank" rel="noopener noreferrer">Isovalent</a>, the company behind Cilium. She is also chair of the CNCF\'s Technical Oversight Committee, and the author of Container Security published by O\'Reilly.'},luanGuimaraes:{header:"Luan Guimarães",bio:"Luan is a Brazilian rock climber, amateur musician, and\n   programmer and am enthusiastic about free software communities and other\n   open knowledge initiatives. He has been working as a Site Reliability\n   Engineer at Wildlife Studios, using and building infrastructure tools on\n   top of Kubernetes in order to support millions of users around the world."},joshVanLeeuwen:{header:"Josh Van Leeuwen",bio:"Josh interned at Jetstack during the summer of 2017 before continuing to\n    work part time during his final year of study at the University of Bristol.\n    During this year, Josh developed a Kubernetes custom controller that\n    automates the delegation of RBAC permissions based on time and event\n    triggers. This work was later awarded the best Software Development Tool\n    Final Year Project. Josh now works full time at Jetstack where if he’s not\n    writing more Go, he’s making good food."},howardHao:{header:"Howard Hao",bio:" Howard Hao has been working as a Site Reliability Engineer for five years at\n    Ect888.com since graduating from Shanghai Jiao Tong University. His team\n    consists of 7 members and has been focusing on the construction of\n    container orchestration platform like Kubernetes for one and a half years."},sergeyGeneralov:{header:"Sergey Generalov",bio:"Sergey is a member of the technical staff at Isovalent\n    and focuses on helping Cilium users solve challenges related\n    to network policies, monitoring, and connectivity troubleshooting\n    by building tools like Network Policy Editor, Hubble UI and more."},liWenquan:{header:"Li Wenquan",bio:"Hello everyone, I am Li Wenquan from China. You can call me David. I\n    started my Docker journey from 2014 and now work as a project manager of\n    enterprise container platform, which is built on Kubernetes and Mesos. I\n    got to know Cilium project from Kubecon, it is so interesting and\n    promising. I've learned a lot from it, such as BPF, XDP and how to replace\n    kube-proxy in a elegant way and I'd love to contribute to it."},alexanderAlemayhu:{header:"Alexander Alemayhu",bio:"Alexander Alemayhu is a software engineer at Isovalent,\n    the company behind Cilium. He has been working on eBPF and Linux\n     kernel technologies for several years, focusing on networking and observability solutions."},DanielBorkmann:{header:"Daniel Borkmann",bio:"Daniel Borkmann is a Distinguished Software Engineer, Isovalent at Cisco"},ThomasGraf:{header:"Thomas Graf",bio:"Thomas Graf is the CTO & Co-Founder Isovalent and also the Vice President Security Cisco"},JedSalazar:{header:"Jed Salazar",bio:"Jed Salazar is a Senior Solutions Architect, Isovalent"},JedSalazarandJoeStringer:{header:"Jed Salazar and Joe Stringer",bio:"Jed Salazar is a Senior Solutions Architect at Isovalent\n    and Joe Stringer is a Principal Engineer, Isovalent at Cisco"},JosephIrving:{header:"Joseph Irving",bio:"Joseph Irving is a Platform Engineer Lead at RVU (Uswitch)"},BillMulligan:{header:"Bill Mulligan",bio:"Bill Mulligan is a Cilium and eBPF Community Pollinator,\n    Isovalent at Cisco and a Governing Board Member of the eBPF Foundation."},OndrejBlazek:{header:"Ondrej Blazek",bio:"Ondrej Blazek is an Infrastru
1cture Engineer at Seznam.cz"},LeonardCohnenandMoritzEckert:{header:"Leonard Cohnen and Moritz Eckert",bio:"Leonard Cohnen and Moritz Eckert are team members at Edgeless Systems"},PolArroyo:{header:"Pol Arroyo",bio:"Pol Arroyo is a DevOps Engineer at Hetzner Cloud."},JedSalazarandMartynasPumputis:{header:"Jed Salazar and Martynas Pumputis",bio:"Jed Salazar is a Senior Solutions Architect, Isovalent and Martynas Pumputis is a Principal Software Engineer, Isovalent at Cisco"},ShedrackAkintayo:{header:"Shedrack Akintayo",bio:"Shedrack Akintayo is a Community Manager at\n    Isovalent helping build the eBPF and Cilium open source communities"},AmirKheirkhahan:{header:"Amir Kheirkhahan",bio:"Amir Kheirkhahan is a DevOps Specialist at DB Schenker handling design, development,\n     deployment and maintenance of wide range of devops toolchain on top of Kubernetes clusters"},PaulArah:{header:"Paul Arah",bio:"Paul Arah is a Community Builder focused on Security at Isovalent (Cisco)"},HimalKumar:{header:"Himal Kumar, Bhaskar Dutta, Arman Pashamokhtari",bio:"Himal Kumar, Bhaskar Dutta, Arman Pashamokhtari are all part of the\n     CanopusAI team Real Time Network Observability, powered by eBPF and Agentic AI"},DoniaChaiehloudj:{header:"Donia Chaiehloudj",bio:"Donia Chaiehloudj is a Senior Software Engineer and Community Oriented at Isovalent.\n    She has been working on Cilium and eBPF technologies, focusing on networking and security solutions."},KatieMeinders:{header:"Katie Meinders",bio:"Katie Meinders is a Community Builder at Isovalent where\n    she helps grow the Cilium and eBPF communities through storytelling,\n    social media, showcasing user success, and building connections across the open source ecosystem."},PeaceSandy:{header:"Peace Sandy",bio:"Peace Sandy is an LFX mentee who contributed to improving Cilium SEO, AEO, and\n    AIO during her mentorship period."},NehaAggarwal:{header:"Neha Aggarwal",bio:"Neha Aggarwal is a Principal Engineer at Microsoft."},CharityMbisi:{header:"Charity Mbisi",bio:"Charity Mbisi is an LFX mentee who contributed to improving Cilium's SEO, AEO, and AIO during his mentorship period.\n    Professionally, Charity Mbisi is a Software Engineer consulting in the Fin-tech and banking industry, specializing in building cloud native computing solutions and optimized service delivery."},andreMartinsAndFerozSalam:{header:"André Martins and Feroz Salam",bio:"André Martins is a Cilium maintainer and Software Engineer, Isovalent at Cisco.\n    Feroz Salam is a member of the Cilium Security Team and a Security Engineer, Isovalent at Cisco."},ChristianHernandez:{header:"Christian Hernandez",bio:"Christian is a well rounded technologist with experience in infrastructure engineering, systems administration, enterprise architecture, tech support, advocacy, and product management. Passionate about OpenSource and containerizing the world one application at a time. He is currently a maintainer of the Argo Project and OpenGitops. Currently, he works as a Technical Marketing Engineer and Tech Lead at Cisco. He focuses on GitOps practices, DevOps, Kubernetes, Network Security, and Containers."},AkilaInduranga:{header:"Akila Induranga",bio:'Akila is a Senior Software Engineer at WSO2, and a maintainer of <a href="https://openchoreo.dev/" target="_blank" rel="noopener noreferrer">OpenChoreo</a>, an open-source internal developer platform for Kubernetes and a CNCF sandbox project.\n    He works on the platform\'s observability and networking layers, including the Cilium-based networking module that brings identity-based policy and Hubble observability to OpenChoreo cells.'}}}}]);
2//# sourceMappingURL=component---src-templates-blog-post-jsx-content-file-path-src-posts-2024-12-31-tetragon-2024-year-in-review-index-md-a792f0fb4508da1ac754.js.map

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.