A Kubernetes tool leveraging eBPF for advanced Kubernetes security, auto-generating Network Policies, Seccomp Profiles, and more. - kguardian-dev/kguardian
At the place where I work, we use the runtime’s default seccomp profile. My colleague and I wanted to see which syscalls our pods actually make, so we decided to capture and audit them and then generate a workload-specific list of syscalls.
We ended up building a feature in our security tool that does exactly that.
Blog post: https://dev.to/maheshrayas/part-2-the-seccomp-profile-nobody...
1 comment
michaelfornaroabout 20 hours ago
Using eBPF in Kubernetes is a brilliant way to improve security posture!
Read the full thread on Hacker News →
Related stories
- Hacker News · 1 points · 2 days ago
- Hacker News · 421 points · 6 days ago
- Hacker News · 3 points · 3 days ago
- Hacker News · 1 points · 4 days ago
- Hacker News · 1 points · 6 days ago
- Hacker News · 2 points · about 13 hours ago