Susheel Thapa
Skip to content
>_ST
KuberneteseBPFCiliumFalcoTetragonDevOps

Kubernetes Zero-Trust & eBPF Runtime Threat Detection

Production Kubernetes cluster hardening using Cilium network policies, Tetragon eBPF kernel event tracing, and Falco runtime alerting.

Kubernetes eBPF Runtime Architecture

An in-depth Kubernetes security engineering deployment enforcing zero-trust network boundaries and deep kernel-level visibility without application sidecars.

Architecture Overview

    flowchart TD
  subgraph K8s ["Kubernetes Node (Linux Kernel 5.15+)"]
      subgraph UserSpace ["User Space Pods"]
          WebPod["Frontend Service"]
          ApiPod["Checkout API"]
          Attacker["Compromised Pod"]
      end

      subgraph eBPFPlane ["eBPF In-Kernel Tracing"]
          Cilium["Cilium CNI (L3/L4/L7 Network Policy)"]
          Tetragon["Tetragon eBPF Sensor (kprobe / tracepoint)"]
      end

      subgraph SecurityPlane ["Control & Alerting"]
          Falco["Falco Detection Engine"]
          SIEM["Security Operations (Prometheus / Sentinel)"]
      end
  end

  WebPod -->|Allowed mTLS Traffic| ApiPod
  Attacker -.->|Unauthorized Port Scan| ApiPod
  Attacker -->|Attempted Root Shell| eBPFPlane

  eBPFPlane -->|Kernel Block & SIGKILL| Attacker
  Tetragon -->|JSON Telemetry Stream| Falco
  Falco -->|Real-Time P1 Alert| SIEM
  

Key Implementation Details

  1. Cilium Network Policies:
    • Explicit default-deny-ingress and default-deny-egress across all tenant namespaces.
    • Mutual TLS (mTLS) with automated cryptographic identity attestation.
  2. Tetragon eBPF Tracing Policies:
    • Traced sys_execve syscalls inside non-root containers to block unexpected shell invocations (/bin/sh, /bin/bash).
    • Monitored capability additions (CAP_SYS_ADMIN, CAP_NET_ADMIN) to prevent container escape attempts.
  3. CIS Kubernetes Benchmark Compliance:
    • Evaluated worker nodes and control plane with kube-bench achieving a 99.4% pass rating.