Tetragon

2essays ·All tags

Agent Safety22 min read

Kernel-Level Kill-Switch: eBPF Process Containment for Agents

When a compromised agent spawns npx or curl, user-space policy is too late. Enforce exec allowlists in the kernel with Tetragon — Panguard sees the tool call; eBPF sees what actually ran.

  • Ebpf
  • Tetragon
  • Agents
  • Security
  • Trust Boundaries
Agent Safety22 min read

Immutable Host Boundary: File Integrity Monitoring for Agents

Define filesystem no-go zones and block agent reads at the host policy layer — Tetragon and Wazuh FIM enforce an Immutable Host Boundary when an allowlisted, diet-constrained runtime still goes looking for secrets on disk.

  • Fim
  • Tetragon
  • Security
  • Agents
  • Trust Boundaries