Your container makes about 70 of Linux's 300-odd syscalls. Here's how kguardian works out which 70, and how it tells you when that answer goes stale.
Part 2 of seven. Parts 1 to 3 are the operator's tour, 4 to 7 open the hood on the eBPF. Part 1 covered the network side. Syscalls are harder, in an interesting way.
Why seccomp is worse than NetworkPolicy
A wrong NetworkPolicy degrades. A connection fails, something retries, you get a log line you can act on.
A wrong seccomp profile doesn't degrade. It's an allowlist evaluated in the kernel on every syscall, so SCMP_ACT_ERRNO on a syscall your runtime needed returns EPERM into a code path that has never seen EPERM. SCMP_ACT_KILL_PROCESS is blunter still. The failure is immediate, total, and usually reported as something unrelated.
So almost nobody ships one. You stay on RuntimeDefault, which is generic enough to cover every container ever built, or you strace it in staging and get a profile that's correct for whatever ra
Discussion
Start the conversation
Your voice can be the first to spark an engaging conversation.