Cilium enforces network policy and encrypts every flow with WireGuard. Hubble shows you what the kernel saw. Tetragon stops the process before it finishes the syscall. No agents, no sidecars.
eBPF lets small, verified programs attach to kernel hook points — syscalls, sockets, the network path — and make decisions there. No kernel module to load, no agent in every pod, no proxy to hop through. Everything on this page is built on it.
Policy is evaluated at the hook point — the socket, the syscall, the packet — so the decision is made before the action completes, not reported after.
The kernel verifier proves every program terminates and stays in bounds before it attaches. A bad program is rejected; it cannot crash the node.
Ruckos ships a pure nftables + eBPF kernel. Cilium replaces kube-proxy entirely, so there is no iptables chain to walk and no per-pod proxy to pay for.
Raw kernel events are joined to pod, namespace, and label metadata in user space, so every policy and every event speaks Kubernetes, not PIDs and IPs.
Cilium is the only networking layer on the cluster. It routes pods, replaces kube-proxy, terminates Gateway API traffic, and enforces identity-based network policy — all from eBPF programs attached to the datapath.
Policy is written against labels and namespaces, not IPs. A pod's identity travels with every packet, so rules keep working when pods reschedule.
Pod-to-pod traffic between nodes is encrypted with WireGuard in the kernel. No certificates to manage for transport, no mesh to operate.
Service load balancing happens in eBPF at the socket layer. Fewer hops, no conntrack tables to overflow, and L2 announcements for bare-metal service IPs.
Cilium's Envoy handles Gateway API routes and TLS termination, so north-south traffic is governed by the same policy engine as east-west.
Hubble reads flow data straight from Cilium's eBPF datapath. Every connection, DNS lookup, HTTP request, and policy drop is visible with the pod identity attached — without a packet capture or a sidecar.
The Hubble UI draws who talks to whom, live, from observed flows. Verify a policy before you enforce it; see what breaks the moment it is applied.
Every packet Cilium drops is recorded with the policy that dropped it. Debug a denied connection in seconds instead of tailing kernel logs.
Flows are decoded at L7 where it matters: DNS names, HTTP methods, paths, and status codes — so you see requests, not just tuples.
Hubble exports flow, drop, TCP, ICMP, DNS, and HTTP metrics to the same Prometheus and Grafana stack the rest of the platform uses.
Tetragon attaches eBPF programs to process, file, and network syscalls. It can observe them, or it can kill the process in the kernel before the syscall returns. The agent that marries those events to Kubernetes metadata runs once per node, not once per pod.
Every exec on every node is recorded with its full ancestry, arguments, and the pod it ran in. A shell spawning in a production container is an event, not a mystery.
Watch or block reads and writes to sensitive paths — secrets, service account tokens, binaries — with a policy, not a filesystem rewrite.
A TracingPolicy can send SIGKILL from inside the kernel. The offending process never gets its syscall result back — there is no race to lose.
Events stream as JSON to Alloy and Loki alongside your logs, with namespace, pod, and labels attached, ready to correlate in Grafana.
RBAC is enforced at the API level, network policy is enforced at the kernel level, and every workload certificate is issued and rotated automatically.
Tetragon enforces process, network, and file-access policy at the kernel level in real time — not just logging violations after the fact.
Cilium enforces network policy and encrypts pod-to-pod traffic with eBPF — no service mesh, no sidecars, no added latency.
cert-manager issues and rotates every workload certificate from your own CA — no manual renewals, no expired certs taking down production.
No SSH, no systemd, no package managers on nodes. A read-only root filesystem means nothing to patch and nowhere for an attacker to persist.
Tetragon captures eBPF security events, Alloy collects logs and metrics into Prometheus and Loki, and Cilium's WireGuard-encrypted dataplane reports every flow through Hubble. Ruckos ingests all of it, correlates the signals, and creates dashboards in Grafana to pin key insights during outages or incidents. Tetragon user-space agent automatically marries raw kernel events with Kubernetes metadata.
The same signal feeding Ruckos is what a real intrusion produces. Continuously validated against adversary emulation and purple-team frameworks, here's what each stage of a Kubernetes attack chain looks like once it hits the stack.