The Kubernetes Security Profiles Operator
-
Updated
Jul 8, 2025 - C
The Kubernetes Security Profiles Operator
Agent Security Runtime
Process isolation for Linux using namespaces, resource limits, landlock and seccomp.
vArmor is a cloud native container sandbox system based on AppArmor/BPF/Seccomp. It also includes multiple built-in protection rules that are ready to use out of the box.
Enhanced observability and security framework built to fully prevent DNS exfiltration (C2, tunnelling) with no data loss, supporting killing C2 implants using TC, Netfilter, Sock, BPF_MAPs. Ring Buffers, Running eBPF inside linux kernel and Deep Learning in user space and threat events streaming for dynamic blacklisting of malicious domains.
Curated resources help you prepare for the CNCF/Linux Foundation CKS 2021 "Kubernetes Certified Security Specialist" Certification exam. Please provide feedback or requests by raising issues, or making a pull request. All feedback for improvements are welcome. thank you.
Provide powerful tools for seccomp analysis
Go library for installing a seccomp BPF system call filter.
minT(oolkit): Mint awesome, secure and production ready containers just the way you need them! Don't change anything in your container image and minify it by up to 30x (and for compiled languages even more) making it secure too! (free and open source)
Slim(toolkit): Don't change anything in your container image and minify it by up to 30x (and for compiled languages even more) making it secure too! (free and open source)
Sandstorm is a self-hostable web productivity suite. It's implemented as a security-hardened web app package manager.
Control plane for system processes
🔍 Seccomp profiling and function-level tracing tool.
A minimalist HTTP canary honeypot server written in Go.
The first open-source eBPF sandbox for Python (macOS/Linux): Secure libraries, block RCE, and enforce precise syscall control. Dive into module & package-level security now.
Add a description, image, and links to the seccomp topic page so that developers can more easily learn about it.
To associate your repository with the seccomp topic, visit your repo's landing page and select "manage topics."