Technology · Ebook
KubeArmor: Runtime Security Enforcement for Cloud Workloads
by Shriira Press
KubeArmor is a cloud-native runtime security engine that restricts what a container, pod, or host can actually do while it runs — which processes execute, which files are accessed, and which network operations are permitted — enforced in the Linux kernel via AppArmor, SELinux, and BPF-LSM together with eBPF. This book begins with the problem runtime security solves and where it sits relative to scanning and admission control, then explains the kernel technologies KubeArmor builds on. It works through the daemonset, operator, controller, and relay architecture, the KubeArmorPolicy and KubeArmorHostPolicy custom resources, the visibility and telemetry pipeline, and the hardening and compliance tooling. The final chapter covers rolling out policies safely and adopting a least-permissive posture without breaking your applications.
Contents
- 1Preface
- 2Chapter 1 — Why Runtime Security Matters
- 3Chapter 2 — What KubeArmor Is
- 4Chapter 3 — The Kernel Foundation: LSMs and eBPF
- 5Chapter 4 — Architecture and Components
- 6Chapter 5 — The KubeArmorPolicy CRD
- 7Chapter 6 — Host Policies and Protecting VMs
- 8Chapter 7 — Observability and Telemetry
- 9Chapter 8 — Hardening, Recommendations, and Compliance
- 10Chapter 9 — KubeArmor in Practice
