1"use strict";(self.webpackChunkcilium_io=self.webpackChunkcilium_io||[]).push([[2787],{8009:function(e,n,t){t.r(n),t.d(n,{Head:function(){return h},default:function(){return d}});var a=t(8453),s=t(6540);function i(e){const n=Object.assign({p:"p",strong:"strong",em:"em",span:"span",h2:"h2",a:"a",h3:"h3",ul:"ul",li:"li"},(0,a.RP)(),e.components);return s.createElement(s.Fragment,null,s.createElement(n.p,null,s.createElement(n.strong,null,s.createElement(n.em,null,"Author: Paul Arah, Isovalent@Cisco"))),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n class="gatsby-resp-image-wrapper"\n style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 1008px; "\n >\n <a\n class="gatsby-resp-image-link"\n href="/static/c855a3ad18822770a9106df1884b5b5d/7385a/cover.png"\n style="display: block"\n target="_blank"\n rel="noopener"\n >\n <span\n class="gatsby-resp-image-background-image"\n style="padding-bottom: 52.38095238095239%; position: relative; bottom: 0; left: 0; display: block;"\n ></span>\n <picture>\n <source\n srcset="/static/c855a3ad18822770a9106df1884b5b5d/2ff5b/cover.webp 252w,\n/static/c855a3ad18822770a9106df1884b5b5d/4d583/cover.webp 504w,\n/static/c855a3ad18822770a9106df1884b5b5d/905a7/cover.webp 1008w,\n/static/c855a3ad18822770a9106df1884b5b5d/bb9f8/cover.webp 1512w,\n/static/c855a3ad18822770a9106df1884b5b5d/8fb31/cover.webp 1800w"\n sizes="(max-width: 1008px) 100vw, 1008px"\n type="image/webp"\n />\n <source\n srcset="/static/c855a3ad18822770a9106df1884b5b5d/019e0/cover.png 252w,\n/static/c855a3ad18822770a9106df1884b5b5d/0dcb2/cover.png 504w,\n/static/c855a3ad18822770a9106df1884b5b5d/832a9/cover.png 1008w,\n/static/c855a3ad18822770a9106df1884b5b5d/19357/cover.png 1512w,\n/static/c855a3ad18822770a9106df1884b5b5d/7385a/cover.png 1800w"\n sizes="(max-width: 1008px) 100vw, 1008px"\n type="image/png"\n />\n <img\n class="gatsby-resp-image-image"\n src="/static/c855a3ad18822770a9106df1884b5b5d/832a9/cover.png"\n alt="cover"\n title=""\n loading="lazy"\n decoding="async"\n style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n />\n </picture>\n </a>\n </span>'}}),"\n",s.createElement(n.p,null,"The evolution into cloud native architectures fundamentally changed how we think about processes from a security perspective. Before cloud native environments, processes were relatively stable and long-lived. You could audit them, understand their behavior patterns, and apply security controls with reasonable confidence. Containers changed this model. Processes now spawn and die in milliseconds, run in isolated namespaces, share the same kernel with dozens of other workloads, and operate at a scale that makes manual security review next to impossible."),"\n",s.createElement(n.p,null,"The need for runtime security has never been more important. Tetragon's eBPF-based security observability and runtime enforcement provides the visibility and control needed to secure processes in these dynamic environments. But to use it effectively, you need to understand both the Linux process model and how attackers exploit it in containerized systems."),"\n",s.createElement(n.h2,null,"The Linux Process Model in the Container Context"),"\n",s.createElement(n.p,null,"When you execute a container, you're creating processes that run on the same kernel as every other process on that node, just with different namespace and cgroup configurations. Every container process is still just a Linux process with a process ID, parent-child relationships, memory space, and file descriptors. The container runtime manages the creation of these processes with specific isolation primitives. When Kubernetes schedules a pod, it is instructing the container runtime to fork processes with carefully configured namespaces for PID, network, mount, UTS, and IPC isolation."),"\n",s.createElement(n.p,null,"This model creates s
1ome interesting challenges from a security point of view. For example, a container escape involves manipulating these namespace boundaries or exploiting kernel vulnerabilities that affect all processes regardless of their namespace configuration. The shared kernel between processes becomes both a performance benefit and a security concern."),"\n",s.createElement(n.h2,null,"Process Namespaces and Security Implications"),"\n",s.createElement(n.p,null,"The process namespace is particularly relevant for security. Inside a container, processes see themselves starting from PID 1, but on the host, these processes have different PIDs in the root namespace. Monitoring tools that run inside containers only see the container's namespace view, missing the broader context of what's happening on the node; on the other hand, monitoring tools that lack namespace awareness miss the container context."),"\n",s.createElement(n.p,null,"Because Tetragon operates at the kernel level, it has visibility across all namespaces, seeing both the container's and the host's views. This kernel-level visibility allows Tetragon to track process relationships even when they cross namespace boundaries. Being able to monitor processes across namespace boundaries is essential for detecting container escapes, where a process might spawn in one namespace and then attempt actions in another namespace."),"\n",s.createElement(n.h2,null,"Why the Shared Kernel Model Matters"),"\n",s.createElement(n.p,null,"Because all containers on a node share the kernel, a vulnerability in kernel code affects every workload. This is fundamentally different from virtual machines, where each VM runs its own kernel. The ",s.createElement(n.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2022-0847"},"Dirty Pipe vulnerability")," exemplified this perfectly: an unprivileged process in any container could exploit the vulnerability to overwrite files across namespace boundaries, potentially gaining control over the entire node."),"\n",s.createElement(n.h2,null,"Understanding Linux Capabilities in Containers"),"\n",s.createElement(n.p,null,"Before diving into specific attacks, we need to understand Linux capabilities because they're central to how container security works. In the old world, processes were either root (UID 0) or standard users (!=UID 0). This binary system was too rigid. Sometimes unprivileged processes need specific privileges. The kernel introduced capabilities to provide more granular security controls. Capabilities can be implemented on files or processes."),"\n",s.createElement(n.p,null,"Container runtimes use capabilities to implement security boundaries. A typical container runs with a restricted capability set compared to root. The default Docker capability set includes things like ",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">CAP_NET_RAW</code>'}})," (raw sockets) and ",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">CAP_CHOWN</code>'}})," (change file ownership), but drops dangerous capabilities like ",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">CAP_SYS_ADMIN</code>'}}),"."),"\n",s.createElement(n.p,null,"However, privileged containers get all capabilities, including ",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">CAP_SYS_ADMIN</code>'}}),', which is essentially the "new root" in Linux. This is why privileged containers are so dangerous. With ',s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">CAP_SYS_ADMIN</code>'}}),", you can load kernel modules, mount arbitrary filesystems, change namespaces, and perform numerous other operations that break container isolation."),"\n",s.createElement(n.h3,null,"The runc Vulnerability (CVE-2019-5736)"),"\n",s.createElement(n.p,null,"The Runc container escape ",s.createElement(n.a,{href:"https://kubernetes.io/blog/2019/02/11/runc-and-cve-2019-5736/"},"(CVE-2019-5736)")," remains one of the most instructive examples. The vulnerability allowed a malicious container to overwrite the runc binary on the host. When an administrator executed commands like docker exec, the compromised runc would execute with host privileges."),"\n",s.createElement(n.p,null,"From a process perspective, this attack exploited how runc handles file descriptors. The malicious container would write to ",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">/proc/self/exe</code>'}}),", a symbolic link pointing to the running process's binary. Because runc was the process executing into the container, this link pointed to the host's runc binary. The write operation could overwrite the actual runc binary on the host filesystem, bypassing container isolation entirely."),"\n",s.createElement(n.p,null,"What makes this particularly deadly is that the attack leverages legitimate behaviour. Writing to ",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">/proc/self/exe</code>'}})," isn't inherently suspicious in all contexts, but from a container it absolutely is. This is where context-aware monitoring becomes crucial. We can write tracing policies that can detect this pattern by monitoring file write operations to sensitive paths with awareness of whether the acting process is containerized:"),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="yaml"><pre class="language-yaml"><code class="language-yaml"><span class="token key atrule">spec</span><span class="token punctuation">:</span>\n <span class="token key atrule">kprobes</span><span class="token punctuation">:</span>\n <span class="token comment"># https://www.kernel.org/doc/html/latest/core-api/kernel-api.html#c.security_file_permission</span>\n <span class="token punctuation">-</span> <span class="token key atrule">call</span><span class="token punctuation">:</span> <span class="token string">\'security_file_permission\'</span>
1\n <span class="token key atrule">syscall</span><span class="token punctuation">:</span> <span class="token boolean important">false</span>\n <span class="token key atrule">args</span><span class="token punctuation">:</span>\n <span class="token punctuation">-</span> <span class="token key atrule">index</span><span class="token punctuation">:</span> <span class="token number">0</span>\n <span class="token key atrule">type</span><span class="token punctuation">:</span> <span class="token string">\'file\'</span>\n <span class="token punctuation">-</span> <span class="token key atrule">index</span><span class="token punctuation">:</span> <span class="token number">1</span>\n <span class="token key atrule">type</span><span class="token punctuation">:</span> <span class="token string">\'int\'</span>\n <span class="token key atrule">selectors</span><span class="token punctuation">:</span>\n <span class="token punctuation">-</span> <span class="token key atrule">matchArgs</span><span class="token punctuation">:</span>\n <span class="token punctuation">-</span> <span class="token key atrule">index</span><span class="token punctuation">:</span> <span class="token number">0</span>\n <span class="token key atrule">operator</span><span class="token punctuation">:</span> <span class="token string">\'Equal\'</span>\n <span class="token key atrule">values</span><span class="token punctuation">:</span>\n <span class="token punctuation">-</span> <span class="token string">\'/usr/bin/runc\'</span> <span class="token comment">#adjust to your actual runc path</span>\n <span class="token comment"># MAY_WRITE</span>\n <span class="token punctuation">-</span> <span class="token key atrule">index</span><span class="token punctuation">:</span> <span class="token number">1</span>\n <span class="token key atrule">operator</span><span class="token punctuation">:</span> <span class="token string">\'Mask\'</span>\n <span class="token key atrule">values</span><span class="token punctuation">:</span>\n <span class="token punctuation">-</span> <span class="token string">\'2\'</span>\n <span class="token comment">#Only suspicious when NOT in the host PID namespace</span>\n <span class="token key atrule">matchNamespaces</span><span class="token punctuation">:</span>\n <span class="token punctuation">-</span> <span class="token key atrule">namespace</span><span class="token punctuation">:</span> Pid\n <span class="token key atrule">operator</span><span class="token punctuation">:</span> NotIn\n <span class="token key atrule">values</span><span class="token punctuation">:</span>\n <span class="token punctuation">-</span> <span class="token string">\'host_ns\'</span>\n <span class="token comment">#kill the offending process</span>\n <span class="token key atrule">matchActions</span><span class="token punctuation">:</span>\n <span class="token punctuation">-</span> <span class="token key atrule">action</span><span class="token punctuation">:</span> Sigkill</code></pre></div>'}}),"\n",s.createElement(n.p,null,"This policy hooks into the kernel function that installs file descriptors, watching for attempts to open ",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">/proc/self/exe</code>'}})," for writing. The enforcement action kills the process attempting this operation."),"\n",s.createElement(n.h3,null,"The Dirty Pipe vulnerability (CVE-2022-0847)"),"\n",s.createElement(n.p,null,"The Dirty Pipe vulnerability ",s.createElement(n.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2022-0847"},"(CVE-2022-0847)")," demonstrates how kernel-level bugs enable privilege escalation regardless of container configuration. The vulnerability existed in the Linux kernel's pipe handling code, specifically in how the kernel handled copy-on-write semantics for pipe buffers."),"\n",s.createElement(n.p,null,"The attack worked by creating a pipe, writing data to it, then splicing that data to overwrite arbitrary file contents, even read-only files. An attacker could overwrite setuid binaries or critical system files like ",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">/etc/passwd</code>'}})," to gain root access."),"\n",s.createElement(n.p,null,"What's particularly interesting from a monitoring perspective is the attack pattern. The exploit required specific sequences of system calls: creating pipes with ",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">pipe()</code>'}}),", writing data with ",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">write()</code>'}}),", and then using ",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">splice()</code>'}})," to copy data into file page caches. While each individual system call is legitimate, the combination in this specific pattern is highly suspicious."),"\n",s.createElement(n.h2,null,"When Legitimate Tools Become Weapons"),"\n",s.createElement(n.p,null,"Modern attackers increasingly use legitimate system tools for malicious purposes, a technique called ",s.createElement(n.a,{href:"https://www.crowdstrike.com/en-us
1/cybersecurity-101/cyberattacks/living-off-the-land-attack/"},'"living off the land."')," Instead of dropping custom malware that could be easily detected, they chain together native utilities to achieve their objectives. A typical example: an attacker gains initial access through a web application vulnerability, uses curl to download a script, executes it with bash, uses find to locate sensitive files, compresses them with tar, and exfiltrates with nc or curl. Every binary involved is legitimate. Relying on signature-based detection would not suffice. This is where behavioral monitoring shines. The sequence of operations is suspicious, even though individual commands aren't."),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n class="gatsby-resp-image-wrapper"\n style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 1008px; "\n >\n <a\n class="gatsby-resp-image-link"\n href="/static/c4464c97c2925b25a08e953c6ea77a0c/c5a1d/chain.png"\n style="display: block"\n target="_blank"\n rel="noopener"\n >\n <span\n class="gatsby-resp-image-background-image"\n style="padding-bottom: 25%; position: relative; bottom: 0; left: 0; background-image: url(\'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAFCAYAAABFA8wzAAAACXBIWXMAAAsTAAALEwEAmpwYAAAA0klEQVR42o1Py24EMQib///FHnrstju7TQIBQh4umZV6bZGsIGJsc+CPykR4powqgv/U0SdwywtiA2oKd8e0B5oyqho6h5A0iCpqlWgdFFwzAxHDe0eKmc/1Emx94e2j4f4tKKUg5QI+30HpRIqFfDtR708QVzAzHonwlQQaZlIVuRA+SwiP+RKU/RFQc4wYznBSa1e/q8fb+vg9yb1fYisCbfT429h7e+UgNhSqQRwXgUgiJYfQwr6iFIkUHAbrQi6RtO4QDmsjuBTpNUwcrQ38ALhdhuSKuNmdAAAAAElFTkSuQmCC\'); background-size: cover; display: block;"\n ></span>\n <picture>\n <source\n srcset="/static/c4464c97c2925b25a08e953c6ea77a0c/2ff5b/chain.webp 252w,\n/static/c4464c97c2925b25a08e953c6ea77a0c/4d583/chain.webp 504w,\n/static/c4464c97c2925b25a08e953c6ea77a0c/905a7/chain.webp 1008w,\n/static/c4464c97c2925b25a08e953c6ea77a0c/4cfd3/chain.webp 1126w"\n sizes="(max-width: 1008px) 100vw, 1008px"\n type="image/webp"\n />\n <source\n srcset="/static/c4464c97c2925b25a08e953c6ea77a0c/019e0/chain.png 252w,\n/static/c4464c97c2925b25a08e953c6ea77a0c/0dcb2/chain.png 504w,\n/static/c4464c97c2925b25a08e953c6ea77a0c/832a9/chain.png 1008w,\n/static/c4464c97c2925b25a08e953c6ea77a0c/c5a1d/chain.png 1126w"\n sizes="(max-width: 1008px) 100vw, 1008px"\n type="image/png"\n />\n <img\n class="gatsby-resp-image-image"\n src="/static/c4464c97c2925b25a08e953c6ea77a0c/832a9/chain.png"\n alt="chain"\n title=""\n loading="lazy"\n decoding="async"\n style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n />\n </picture>\n </a>\n </span>'}}),"\n",s.createElement(n.p,null,"A web server process spawning bash is unusual. That bash process immediately running curl to download from the internet is even more suspicious. The downloaded script executing a find for SSH keys and database credentials seals the deal.\nTetragon's child process visibility is crucial here. You can create policies that understand parent-child relationships. For example, you monitor unexpected shells launched from web-facing applications. To detect these behaviors, you can match on the parent binary and ask Tetragon to automatically follow all child processes it spawns."),"\n",s.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="yaml"><pre class="language-yaml"><code class="language-yaml"><span class="token key atrule">spec</span><span class="token punctuation">:</span>\n <span class="token comment"># https://www.kernel.org/doc/html/latest/core-api/kernel-api.html#c.security_bprm_check</span>\n <span class="token key atrule">lsmhooks</span><span class="token punctuation">:</span>\n <span class="token punctuation">-</span> <span class="token key atrule">
1hook</span><span class="token punctuation">:</span> <span class="token string">\'bprm_check_security\'</span>\n <span class="token key atrule">args</span><span class="token punctuation">:</span>\n <span class="token punctuation">-</span> <span class="token key atrule">index</span><span class="token punctuation">:</span> <span class="token number">0</span>\n <span class="token key atrule">type</span><span class="token punctuation">:</span> <span class="token string">\'string\'</span>\n <span class="token key atrule">resolve</span><span class="token punctuation">:</span> <span class="token string">\'filename\'</span>\n <span class="token key atrule">selectors</span><span class="token punctuation">:</span>\n <span class="token punctuation">-</span> <span class="token key atrule">matchBinaries</span><span class="token punctuation">:</span>\n <span class="token punctuation">-</span> <span class="token key atrule">operator</span><span class="token punctuation">:</span> <span class="token string">\'In\'</span>\n <span class="token key atrule">values</span><span class="token punctuation">:</span>\n <span class="token punctuation">-</span> <span class="token string">\'/usr/sbin/nginx\'</span>\n <span class="token punctuation">-</span> <span class="token string">\'/usr/bin/node\'</span>\n <span class="token punctuation">-</span> <span class="token string">\'/usr/local/bin/python\'</span>\n <span class="token key atrule">followChildren</span><span class="token punctuation">:</span> <span class="token boolean important">true</span>\n <span class="token key atrule">matchArgs</span><span class="token punctuation">:</span>\n <span class="token punctuation">-</span> <span class="token key atrule">index</span><span class="token punctuation">:</span> <span class="token number">0</span>\n <span class="token key atrule">operator</span><span class="token punctuation">:</span> <span class="token string">\'In\'</span>\n <span class="token key atrule">values</span><span class="token punctuation">:</span>\n <span class="token punctuation">-</span> <span class="token string">\'/bin/bash\'</span>\n <span class="token punctuation">-</span> <span class="token string">\'/bin/sh\'</span>\n <span class="token key atrule">matchActions</span><span class="token punctuation">:</span>\n <span class="token punctuation">-</span> <span class="token key atrule">action</span><span class="token punctuation">:</span> Post</code></pre></div>'}}),"\n",s.createElement(n.p,null,"This sample tracing policy monitors execution starting from nginx, node, or python and follows the children they spawn. If any of those processes creates a shell, Tetragon detects this with full lineage visibility. An activity like this is a strong signal of remote code execution or âliving off the landâ activity."),"\n",s.createElement(n.h2,null,"Building Observability-Driven Prevention Policies"),"\n",s.createElement(n.p,null,"The most powerful of Tetragon is translating detection events into prevention policies. This is different from traditional security tools that rely on signature-based detection or predefined rule sets. Instead, you observe actual behavior of your workloads in your environment, understand what the expected behavior is, and finally create policies that block deviations from this expected behavior. There are generally two ways to go about this:"),"\n",s.createElement(n.h3,null,"The Allowlist Approach: Least Privilege"),"\n",s.createElement(n.p,null,"Allowlist policies specify what actions applications are allowed to perform and block everything else. This is the ideal security posture: only grant the minimal capabilities and privileges an application needs. The challenge has always been determining what an application actually needs. Trial and error (remove capabilities until something breaks) is frustrating and risky. Static analysis of code doesn't account for runtime behavior. Observability solves this. Deploy your application with full monitoring, exercise all its functionality (including edge cases and error paths), and observe what capabilities it uses, what files it accesses, and what network connections it makes. This baseline behaviour becomes your allowlist policy."),"\n",s.createElement(n.p,null,"For example, you might observe that your frontend application:"),"\n",s.createElement(n.ul,null,"\n",s.createElement(n.li,null,"Executes only node and npm binaries"),"\n",s.createElement(n.li,null,"Accesses only files in /app and /tmp"),"\n",s.createElement(n.li,null,"Makes network connections only to backend services on ports 8080 and 6379"),"\n",s.createElement(n.li,null,"Runs with only CAP_NET_BIND_SERVICE capability"),"\n"),"\n",s.createElement(n.p,null,"Your allowlist policy enforces exactly this behavior and blocks everything else. If an attacker compromises the application and tries to run bash, download additional tools, access /etc/sh
1adow, or connect to external IPs, the policy blocks it."),"\n",s.createElement(n.h3,null,"The Denylist Approach: Known Bad Behavior"),"\n",s.createElement(n.p,null,"Denylists specify behaviors that should be blocked while allowing everything else. They're less secure than allowlists (there's more opportunity for attackers to maneuver), but easier to implement and less likely to break legitimate functionality. The key to effective denylists is learning from real attacks. Don't guess what malicious behavior looks like; observe it during security exercises, CTF challenges, or incident response. An observability-driven approach means your denylist is based on actual attacker behavior in your environment."),"\n",s.createElement(n.h2,null,"Practical Deployment Strategies"),"\n",s.createElement(n.p,null,"When deploying Tetragon in production, follow these practices to maximize effectiveness while minimizing operational risk."),"\n",s.createElement(n.ul,null,"\n",s.createElement(n.li,null,s.createElement(n.strong,null,"Start Passive:")," Deploy Tetragon in monitoring enforcement mode before enabling any enforcement. This establishes baselines and identifies legitimate behaviors that might otherwise be blocked."),"\n",s.createElement(n.li,null,s.createElement(n.strong,null,"Focus on Security Significant Events:")," You don't need to monitor everything equally. For example, production namespaces running internet-facing services warrant more scrutiny than development environments. Workloads handling sensitive data need stricter policies than internal tools."),"\n",s.createElement(n.li,null,s.createElement(n.strong,null,"Use Kubernetes Identity Aware Policies:")," Leverage namespaces and labels to create targeted policies. Your database pods have different legitimate behaviors than your frontend pods. Policies should reflect this."),"\n",s.createElement(n.li,null,s.createElement(n.strong,null,"Test Thoroughly"),": Before enforcing policies in production, test in development and staging. Reproduce workload patterns and verify policies don't break legitimate operations. Treat security policies as code: version control, review, test, then deploy."),"\n",s.createElement(n.li,null,s.createElement(n.strong,null,"Iterate Continuously"),": Applications evolve, new vulnerabilities emerge, and attack techniques change. Regularly review Tetragon events, identify new patterns, and update policies accordingly.\nLearn by Attacking: Participate in CTF challenges or run red team exercises with Tetragon monitoring active. This teaches both attack techniques and improves your detection capabilities."),"\n"),"\n",s.createElement(n.h2,null,"Conclusion"),"\n",s.createElement(n.p,null,"Process security in Kubernetes requires understanding that containers are just Linux processes with namespace isolation, not virtualized systems. The shared kernel model that makes containers efficient also makes them vulnerable. A kernel exploit in any container affects all workloads on that node."),"\n",s.createElement(n.p,null,"Traditional security tools struggle with this reality. They lack namespace awareness, miss ephemeral workloads, and can't correlate process behavior with Kubernetes identity. Static analysis catches known vulnerabilities but misses zero-days and misconfigurations. Network monitoring sees packets but loses context when pod IPs are reused."),"\n",s.createElement(n.p,null,"Tetragon transforms process security by operating at the kernel level with full namespace awareness. Tetragon observes every process execution, file access, and network connection across all workloads while correlating the Kubernetes context. It correlates events through the process lifecycle, revealing attack patterns that individual events wouldn't show.\nMore importantly, Tetragon enables prevention through observability-driven policy. By monitoring normal application behavior, you can build least-privilege policies that block deviations from expected behavior without breaking legitimate functionality. By observing attacks during security exercises, you can create targeted defenses against real-world threats."),"\n",s.createElement(n.h2,null,"Additional Resources"),"\n",s.createElement(n.ul,null,"\n",s.createElement(n.li,null,s.createElement(n.a,{href:"https://isovalent.com/books/container-security/"},"Container Security, 2nd Edition")),"\n",s.createElement(n.li,null,s.createElement(n.a,{href:"https://www.youtube.com/watch?v=-sfOB1s6mvs&list=PLDg_GiBbAx-kvhwkGkCDdnQzTIe
1EdrJ_F"},"eBPF for Creating Least Privileged Policies: What Do I Need to Know to Prepare for the Next CVEs?")),"\n",s.createElement(n.li,null,s.createElement(n.a,{href:"https://www.youtube.com/watch?v=2BIe4VmSYyQ&list=PLDg_GiBbAx-kvhwkGkCDdnQzTIeEdrJ_F&index=16"},"Past, Present, Future of Tetragon- First Production Use Cases, Lessons Learnt, Where Are We Heading?")),"\n",s.createElement(n.li,null,s.createElement(n.a,{href:"https://www.youtube.com/watch?v=YNDp7Id7Bbs&t=452s"},"Don't Get Blown up! Avoiding Configuration Gotchas for Tetragon Newbies")),"\n",s.createElement(n.li,null,s.createElement(n.a,{href:"https://iximiuz.com/en/posts/oci-containers/"},"What Is a Standard Container: Diving Into the OCI Runtime. Spec Containers Aren't Linux Processes")),"\n"))}var o=function(e){void 0===e&&(e={});const{wrapper:n}=Object.assign({},(0,a.RP)(),e.components);return n?s.createElement(n,e,s.createElement(i,e)):i(e)},l=t(8125),r=t(5805),c=t(8838),p=t(2744);const u=e=>{const{data:{mdx:n},children:t}=e,{frontmatter:{path:a,title:i,date:o,tags:c,ogSummary:u}}=n;return s.createElement(p.A,{headerWithSearch:!0},s.createElement(l.A,{path:a,content:t,date:o,title:i,tags:c,summary:u}),s.createElement(r.A,{className:"my-10 md:my-20 lg:my-28"}))},h=e=>{var n,t;let{data:{mdx:a,site:i},location:{pathname:o}}=e;const{frontmatter:{title:l,ogImage:r,ogSummary:p,dateIso:u,tags:h,author:d}}=a,{siteUrl:m}=i.siteMetadata,g=`${p.slice(0,133)}...`,y=`${m}${o}`,k=null!=r&&null!==(n=r.childImageSharp)&&void 0!==n&&null!==(t=n.resize)&&void 0!==t&&t.src?`${m}${r.childImageSharp.resize.src}`:null,b={title:l,description:g,image:r||null,slug:o},w={"@context":"https://schema.org","@type":"BlogPosting",headline:l,description:g,url:y,datePublished:u,dateModified:u,author:d?{"@type":"Person",name:d}:{"@type":"Organization",name:"Cilium",url:m},publisher:{"@type":"Organization",name:"Cilium",url:m,logo:{"@type":"ImageObject",url:`${m}/images/social-preview.jpg`}},...k&&{image:{"@type":"ImageObject",url:k,width:1200,height:630}},...(null==h?void 0:h.length)>0&&{keywords:h.join(", ")}};return s.createElement(c.A,{data:b,type:"article",datePublished:u,jsonLd:w})};function d(e){return s.createElement(u,e,s.createElement(o,e))}}}]); 2//# sourceMappingURL=component---src-templates-blog-post-jsx-content-file-path-src-posts-2025-11-4-tetragon-process-index-md-b573c3fdfe934c36d64d.js.map
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.