Tetragon

基于 eBPF 的安全可观察性和运行时强制执行。「BPF-based Security Observability and Runtime Enforcement」

Github星跟踪图

License
License
License


Cilium’s new Tetragon component enables powerful
real-time, eBPF-based Security Observability and Runtime Enforcement.

Tetragon detects and is able to react to security-significant events, such as

  • Process execution events
  • System call activity
  • I/O activity including network & file access

When used in a Kubernetes environment, Tetragon is Kubernetes-aware - that is,
it understands Kubernetes identities such as namespaces, pods and so on - so
that security event detection can be configured in relation to individual
workloads.

Tetragon Overview Diagram

See more about how Tetragon is using eBPF.

Getting started

Refer to the official documentation of Tetragon.

To get started with Tetragon, take a look at the getting started
guides
to:

Tetragon is able to observe critical hooks in the kernel through its sensors
and generates events enriched with Linux and Kubernetes metadata:

  1. Process lifecycle: generating process_exec and process_exit events
    by default, enabling full process lifecycle observability. Learn more about
    these events on the process lifecycle use case page.
  2. Generic tracing: generating process_kprobe, process_tracepoint and
    process_uprobe events for more advanced and custom use cases. Learn more
    about these events on the TracingPolicy concept page
    and discover multiple use cases like:

See further resources:

Join the community

Join the Tetragon Slack channel to chat with
developers, maintainers, and other users. This is a good first stop to ask
questions and share your experiences.

How to Contribute

For getting started with local development, you can refer to the
Contribution Guide. If
you plan to submit a PR, please "sign-off"
your commits.

主要指标

概览
名称与所有者cilium/tetragon
主编程语言C
编程语言 (语言数: 8)
平台
许可证Apache License 2.0
所有者活动
创建于2022-03-23 10:25:36
推送于2025-04-24 15:29:17
最后一次提交
发布数50
最新版本名称v1.5.0-pre.0 (发布于 )
第一版名称tetragon-cli (发布于 )
用户参与
星数3.9k
关注者数53
派生数409
提交数4.8k
已启用问题?
问题数580
打开的问题数151
拉请求数2605
打开的拉请求数94
关闭的拉请求数387
项目设置
已启用Wiki?
已存档?
是复刻?
已锁定?
是镜像?
是私有?