Project reference ↗

Deployment checks cannot show everything a container does after it starts. Tetragon observes process and system activity using eBPF, a Linux mechanism for running controlled programs in the kernel, and relates that activity to workloads. It can help security teams investigate runtime behavior and enforce selected policies. Because those policies may stop activity, begin by validating observation and scope. The required kernel features, node access and event-data handling are part of the deployment decision.

Chart ownership

Tetragon's official Kubernetes guide distributes the tetragon chart through the Cilium project repository, https://helm.cilium.io. The chart deploys node-level components; review the values and host access they request. Installing Tetragon is a separate decision from selecting Cilium as the cluster network.

Before adoption

Confirm the selected release's kernel, BTF and node operating-system requirements. Assess event volume, collection cost and sensitive process data before exporting events. Begin with observability and validate the scope of each policy before enabling actions that can stop workloads. Document namespace filters: the installation guide notes that kube-system events are filtered by default. Recheck coverage after changing those filters.

Follow the Kubernetes installation guide and installation and security documentation.

Sources & further reading

  1. Tetragon Kubernetes Helm installation
  2. Tetragon installation and security guidance

Spotted something that needs another look?

Help improve this page →