Loading…
June 26-27, 2024 | Seattle, WA
View More Details | Registration Information

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for CloudNativeSecurityCon North America 2024 to participate in these sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Pacific Daylight Time (PDT), UTC -7. To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

The schedule is subject to change.
Thursday June 27, 2024 4:40pm - 5:15pm PDT
433
You can do so much with eBPF, with so little code. You can easily and cheaply get insights on connectivity, networking, security and performance. One drawback is that these eBPF probes require elevated permissions, in order to be loaded and to perform their job. But what permissions exactly? Can we avoid ‘privileged:true’ in the Kubernetes securityContext, and in what situations? This talk focuses on exploring the mapping between the Linux security capabilities, which can be configured in the Kubernetes securityContext, and eBPF capabilities. We discuss some of the learnings on when even CAP_SYS_ADMIN is not enough and how to avoid the dreaded ‘privileged: true’. We go into detail on the fine boundaries of what capabilities some common eBPF features require and where the lines are drawn. We explore when the CAP_BPF capability is enough, and what additional privileges are required for what types of instrumentation to avoid CAP_SYS_ADMIN.
Speakers
avatar for Nikola Grcevski

Nikola Grcevski

Principal Software Engineer, Grafana Labs
Nikola Grcevski has worked as a software engineer for more than 20 years, mostly in the field of compilers, managed runtimes and performance optimization. Most recently he's working on low level application instrumentation with eBPF at Grafana Labs.
Thursday June 27, 2024 4:40pm - 5:15pm PDT
433
  Observability + Detections + Response
Feedback form is now closed.

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link