Runtime and cluster security · Tetragon
Want to see every process, file and connection on every node?
Tetragon watches process execution, file access and network activity from the kernel with eBPF. We deploy it across your clusters and hosts, write and test the policies, get the events somewhere useful, and hand it to your team.
Ask a real Tetragon recording
Ten minutes of process and file events from a k3s cluster running WordPress, MySQL and Redis, stored in ClickHouse.
A Tetragon pilot takes an afternoon. A fleet is the real work.
What a pilot proves
- Helm install on one cluster
- Default policies
- Events in a terminal or a log file
- One kernel version
What production needs
- Every cluster and host, rolled out in waves
- Policies reviewed, tested and versioned
- Events filtered, enriched and stored
- Upgrades that survive kernel and node-group changes
Most of the effort is in the second column. That is the part we build.
Container security bill growing with your node count?
Per-node agent pricing means every new cluster is a procurement conversation. Tetragon is open source, so what you pay for is the engineering to run it well and the storage for what it sees.
- Compare what your current agent actually tells you with what Tetragon can see.
- Run both side by side on a pilot cluster.
- Decide from real events, not a feature matrix.
Keep the commercial tool if it earns its place. Many teams run both.
Policies change what runs in the kernel. Treat them like code.
A TracingPolicy decides what the kernel reports, and optionally what it blocks. Editing one on a live cluster is a production change, and a bad one can flood your pipeline or stop a workload.
- Every policy is reviewed and tested in CI before it ships.
- Changes go to a canary cluster first, then the fleet.
- Rollback is one revert, and RBAC limits who can apply policies at all.
What we build
Fleet deployment
Helm and Terraform per cluster, rolled out through your GitOps tool in waves, with per-cluster values and a tested rollback.
Policy repository
TracingPolicies in Git with review, CI validation, canary rollout and rollback, and RBAC on who can change them.
Filtering at the agent
Export allowlists and filters so noisy events are dropped on the node, not paid for downstream.
Enrichment
Every event carries cluster, account, namespace and workload identity, so an alert says where it came from.
Delivery
Events routed to ClickHouse, Elasticsearch, OpenSearch, S3 or your existing SIEM, with buffering that survives an outage.
Enforcement, when ready
Blocking policies are enabled only after they have run in monitor mode and we have seen what they would have stopped.
Agent health
Prometheus metrics, dashboards and alerts for dropped events, lag and nodes that stop reporting.
Kernel compatibility
Each node group checked before an upgrade, so a new AMI or kernel does not quietly turn a sensor off.
Hosts outside Kubernetes
The same policies and pipeline on plain Linux hosts such as EC2, installed from packages.
Example policies we write
- Shells spawned by web servers
- Execution from /tmp and other writable paths
- Writes to /etc and binary directories
- Reads of credential and key files
- Outbound connections from unexpected processes
- Privilege changes and setuid binaries
- Kernel module loads
- Namespace changes that suggest a container escape
What we need from you
- Linux nodes with a kernel that supports the BPF features the policies use
- Permission to run a privileged DaemonSet
- A GitOps or CI path that can apply per-cluster configuration
- Somewhere for events to go, or a decision on where
Kernel support is checked per node group during the assessment.
How it runs
- 1
Assess
Cluster and kernel inventory, an event volume estimate and a target architecture.
- 2
Pilot
One non-production cluster with Tetragon, baseline policies and the event pipeline working end to end.
- 3
Roll out
Fleet deployment in waves, with performance measured on each wave.
- 4
Hand off
Documentation, runbooks, the upgrade procedure and a walkthrough with your team.
We build and hand over the platform. We don't triage your alerts or run it as a managed service.
Tetragon is a Cilium project of the Cloud Native Computing Foundation. Palm Sec is not affiliated with or endorsed by the Tetragon project, Isovalent, Cisco or the CNCF.