eBPF-native security

Zero Trust

Cilium enforces network policy and encrypts every flow with WireGuard. Hubble shows you what the kernel saw. Tetragon stops the process before it finishes the syscall. No agents, no sidecars.

Hubble flow · dns · http · drop
Pod user space
kernel boundary
Linux kernel
Tetragon process_exec
Tetragon file open
Cilium network policy
Cilium WireGuard
Wire encrypted
eBPF

Programs that run
inside the kernel

eBPF lets small, verified programs attach to kernel hook points — syscalls, sockets, the network path — and make decisions there. No kernel module to load, no agent in every pod, no proxy to hop through. Everything on this page is built on it.

Runs where the event happens

Policy is evaluated at the hook point — the socket, the syscall, the packet — so the decision is made before the action completes, not reported after.

Verified before it loads

The kernel verifier proves every program terminates and stays in bounds before it attaches. A bad program is rejected; it cannot crash the node.

No sidecars, no iptables

Ruckos ships a pure nftables + eBPF kernel. Cilium replaces kube-proxy entirely, so there is no iptables chain to walk and no per-pod proxy to pay for.

Kubernetes-aware

Raw kernel events are joined to pod, namespace, and label metadata in user space, so every policy and every event speaks Kubernetes, not PIDs and IPs.

Cilium

The network
is the policy engine

Cilium is the only networking layer on the cluster. It routes pods, replaces kube-proxy, terminates Gateway API traffic, and enforces identity-based network policy — all from eBPF programs attached to the datapath.

Identity-based policy

Policy is written against labels and namespaces, not IPs. A pod's identity travels with every packet, so rules keep working when pods reschedule.

WireGuard everywhere

Pod-to-pod traffic between nodes is encrypted with WireGuard in the kernel. No certificates to manage for transport, no mesh to operate.

kube-proxy replacement

Service load balancing happens in eBPF at the socket layer. Fewer hops, no conntrack tables to overflow, and L2 announcements for bare-metal service IPs.

Gateway API ingress

Cilium's Envoy handles Gateway API routes and TLS termination, so north-south traffic is governed by the same policy engine as east-west.

Hubble

See every flow
the kernel saw

Hubble reads flow data straight from Cilium's eBPF datapath. Every connection, DNS lookup, HTTP request, and policy drop is visible with the pod identity attached — without a packet capture or a sidecar.

Service map

The Hubble UI draws who talks to whom, live, from observed flows. Verify a policy before you enforce it; see what breaks the moment it is applied.

Drop visibility

Every packet Cilium drops is recorded with the policy that dropped it. Debug a denied connection in seconds instead of tailing kernel logs.

DNS and HTTP aware

Flows are decoded at L7 where it matters: DNS names, HTTP methods, paths, and status codes — so you see requests, not just tuples.

Metrics into Prometheus

Hubble exports flow, drop, TCP, ICMP, DNS, and HTTP metrics to the same Prometheus and Grafana stack the rest of the platform uses.

Tetragon

Stop it
before it finishes

Tetragon attaches eBPF programs to process, file, and network syscalls. It can observe them, or it can kill the process in the kernel before the syscall returns. The agent that marries those events to Kubernetes metadata runs once per node, not once per pod.

Process execution

Every exec on every node is recorded with its full ancestry, arguments, and the pod it ran in. A shell spawning in a production container is an event, not a mystery.

File access

Watch or block reads and writes to sensitive paths — secrets, service account tokens, binaries — with a policy, not a filesystem rewrite.

Kernel-level enforcement

A TracingPolicy can send SIGKILL from inside the kernel. The offending process never gets its syscall result back — there is no race to lose.

Events to your stack

Events stream as JSON to Alloy and Loki alongside your logs, with namespace, pod, and labels attached, ready to correlate in Grafana.

Security

Zero Trust
from the kernel up

RBAC is enforced at the API level, network policy is enforced at the kernel level, and every workload certificate is issued and rotated automatically.

eBPF policy enforcement

Tetragon enforces process, network, and file-access policy at the kernel level in real time — not just logging violations after the fact.

Zero-trust networking

Cilium enforces network policy and encrypts pod-to-pod traffic with eBPF — no service mesh, no sidecars, no added latency.

Automated certificate lifecycle

cert-manager issues and rotates every workload certificate from your own CA — no manual renewals, no expired certs taking down production.

Immutable attack surface

No SSH, no systemd, no package managers on nodes. A read-only root filesystem means nothing to patch and nowhere for an attacker to persist.

Ruckos

Telemetry converges
Ruckos analyzes

Tetragon captures eBPF security events, Alloy collects logs and metrics into Prometheus and Loki, and Cilium's WireGuard-encrypted dataplane reports every flow through Hubble. Ruckos ingests all of it, correlates the signals, and creates dashboards in Grafana to pin key insights during outages or incidents. Tetragon user-space agent automatically marries raw kernel events with Kubernetes metadata.

What Ruckos correlates from that telemetry

The same signal feeding Ruckos is what a real intrusion produces. Continuously validated against adversary emulation and purple-team frameworks, here's what each stage of a Kubernetes attack chain looks like once it hits the stack.

Initial access to a vulnerable pod

Tetragon · anomalous process exec

Service account token theft

Tetragon · token file access

Secret extraction

Tetragon · Secret API reads

RBAC enumeration

Loki · API audit log spikes

Privilege escalation to cluster-admin

Tetragon · privileged syscalls

Lateral movement across namespaces

Hubble · cross-namespace flow

Direct access to the Kubernetes API

Hubble · flow to apiserver

Cloud credential harvesting

Tetragon · metadata endpoint access

Persistence via malicious workloads

GitOps · ArgoCD drift alert

Data exfiltration

Cilium · egress policy + flow anomaly
Continuously validated against
Peirates Stratus Red Team Atomic Red Team MITRE Caldera Kubernetes Goat