Isovalent Enterprise for Tetragon Released
November 02, 2023

Isovalent announced the general availability of Isovalent Enterprise for Tetragon, extending the existing open source Cilium Tetragon project that provides kernel-level programmability for runtime Kubernetes security use cases.

Cilium Tetragon, the open source project within the Cloud Native Computing Foundation (CNCF) and sub-project of Cilium, has reached a significant milestone with the OSS 1.0 release. Just like Cilium gave platform teams a standard interface and greatly evolved performance in Kubernetes networking, Tetragon harnesses the power of eBPF to define how security and operations teams instrument Kubernetes runtime security--with lower overhead, higher performance, and a richer stream of data closer to the kernel and beyond the limited telemetry purview of security scanners.

Tetragon is an eBPF-based security observability and runtime enforcement platform designed to give security and operations teams richer telemetry data for runtime security, while eliminating the performance overhead of proprietary security vendors' agents. Isovalent extends the open source project with enterprise features that further security teams visibility into L7 networking events (HTTP, DNS, TLS/SSL handshake analysis), granular control over Tetragon security policies and workflows, improved in-kernel smart collection for lower CPU & memory overhead, and more. In benchmarking comparisons, Tetragon's kernel-based runtime telemetry collection resulted in near baseline overhead and minimal resource utilization across core security and observability use cases, read the benchmarking results and more.

Tetragon is built around eBPF and in-kernel filtering and aggregation logic, providing deep visibility without traditional agents or application changes. It gives platform and security teams a powerful observability layer that can introspect the entire system ranging from low-level kernel visibility to track file accesses, network activity, or capability changes, all the way up into the application layers covering aspects such as function calls into vulnerable libraries, tracing process execution, or understanding HTTP requests made.

Tetragon is able to enforce security policies across the operating system in a real time preventive manner instead of reacting to events asynchronously. Tetragon has the ability to specify allow lists for access control at several layers. Security policies can be injected via Kubernetes (CRDs), a JSON API, or systems such as Open Policy Agent (OPA).

"As Cilium standardized the Kubernetes networking experience across cloud providers and infrastructure, with Tetragon we're seeking to give platform and security teams the same experience for runtime security," said Thomas Graf, Cilium Creator and CTO and co-founder at Isovalent. "And by bringing Kubernetes security observability and enforcement closer to the kernel, we're giving you deeper visibility and control combined with incredible performance gains compared to existing technologies."

With Tetragon, every file, system interaction, network interaction, escalation of privileges, every process ever executed or network port opened is observable to security teams. This degree of granularity made possible by the eBPF and Cilium-based close-to-the-kernel lineage gives platform teams the right combination of extracting only what they need, while defining filters and aggregations based on high level signals.

With its origins as a security primitive inside of Cilium, Tetragon also gives platform teams the advantage of combining network and runtime visibility. By using Cilium as the networking layer to connect workloads across cloud, on-prem and edge, and deploying Tetragon for runtime security--platform teams get a single Kubernetes-optimized operating model for their entire infrastructure, complete with a distributed firewall.

Share this

Industry News

April 25, 2024

JFrog announced a new machine learning (ML) lifecycle integration between JFrog Artifactory and MLflow, an open source software platform originally developed by Databricks.

April 25, 2024

Copado announced the general availability of Test Copilot, the AI-powered test creation assistant.

April 25, 2024

SmartBear has added no-code test automation powered by GenAI to its Zephyr Scale, the solution that delivers scalable, performant test management inside Jira.

April 24, 2024

Opsera announced that two new patents have been issued for its Unified DevOps Platform, now totaling nine patents issued for the cloud-native DevOps Platform.

April 23, 2024

mabl announced the addition of mobile application testing to its platform.

April 23, 2024

Spectro Cloud announced the achievement of a new Amazon Web Services (AWS) Competency designation.

April 22, 2024

GitLab announced the general availability of GitLab Duo Chat.

April 18, 2024

SmartBear announced a new version of its API design and documentation tool, SwaggerHub, integrating Stoplight’s API open source tools.

April 18, 2024

Red Hat announced updates to Red Hat Trusted Software Supply Chain.

April 18, 2024

Tricentis announced the latest update to the company’s AI offerings with the launch of Tricentis Copilot, a suite of solutions leveraging generative AI to enhance productivity throughout the entire testing lifecycle.

April 17, 2024

CIQ launched fully supported, upstream stable kernels for Rocky Linux via the CIQ Enterprise Linux Platform, providing enhanced performance, hardware compatibility and security.

April 17, 2024

Redgate launched an enterprise version of its database monitoring tool, providing a range of new features to address the challenges of scale and complexity faced by larger organizations.

April 17, 2024

Snyk announced the expansion of its current partnership with Google Cloud to advance secure code generated by Google Cloud’s generative-AI-powered collaborator service, Gemini Code Assist.

April 16, 2024

Kong announced the commercial availability of Kong Konnect Dedicated Cloud Gateways on Amazon Web Services (AWS).

April 16, 2024

Pegasystems announced the general availability of Pega Infinity ’24.1™.