« All posts

Kguardian: Generate Security Policies from eBPF Traces

Kguardian automates the generation of Kubernetes security policies using eBPF traces. It enables least-privilege policy creation without manual rule writing.

Kguardian monitors pod traffic and syscalls to generate security policies for Kubernetes. This tool enables platform and security teams to create least-privilege policies without hand-coding rules. By leveraging eBPF, it captures TCP/UDP connections and syscalls on each node to produce NetworkPolicy and seccomp profiles from observed behavior.

This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work