Show HN: Kguardian – seccomp profiles and NetworkPolicies from eBPF traceshttps://github.com/kguardian-dev/kguardian
At the place where I work, we use the runtime’s default seccomp profile. My colleague and I wanted to see which syscalls our pods actually make, so we decided to capture and audit them and then generate a workload-specific list of syscalls. We ended up building a feature in our security tool that does exactly that. Blog post: https://dev.to/maheshrayas/part-2-the-seccomp-profile-nobody... Comments URL: https://news.ycombinator.com/item?id=49905667 Points: 1 # Comments: 0