Services

Tetragon

Deployment and operation of Tetragon on EKS and Linux hosts: policy management in Git, event pipelines, storage integration, agent monitoring and upgrades.

Scope

Deployment and operation of Tetragon for process, file and network observability, and optionally enforcement, on Amazon EKS clusters and standalone Linux hosts.

Area Included
Installation Helm chart or host package, per-cluster values, Terraform for supporting resources
Policy TracingPolicy repository, CI validation, canary-then-fleet rollout, rollback
Access control Kubernetes RBAC on TracingPolicy resources
Events Export configuration, allowlists, filtering, enrichment with cluster and account identity
Delivery Routing to ClickHouse, Elasticsearch, OpenSearch, S3 or an existing SIEM
Agent health Prometheus metrics, dashboards, alerts on drops and lag
Lifecycle Upgrade procedure, kernel and node-group compatibility checks

Requirements

  • Linux nodes with a kernel that supports the required BPF features. Compatibility is checked per node group during assessment with tetra probe config.
  • Ability to deploy a privileged DaemonSet.
  • A destination for events, or a decision on which to use.
  • For fleet work, a GitOps or CI mechanism that can apply per-cluster configuration.

Event handling

Tetragon exports a high volume of events. The default position is to filter at the agent, keep raw telemetry in low-cost storage with short retention, and forward only high-confidence detections to alerting. Retention is set per event class. Ordinary exec events and policy matches usually need different lifetimes.

Phases

Phase Output
Assessment Cluster and kernel inventory, event volume estimate, target architecture document
Pilot One non-production cluster running Tetragon, baseline policies and the event pipeline
Rollout Fleet deployment in waves, with per-wave performance measurements
Handoff Documentation, runbooks, upgrade procedure, walkthrough

Each phase has fixed scope and price, agreed after the assessment.

Out of scope

Alert triage and 24/7 monitoring. Palm Sec builds and hands over the platform and does not operate it as a managed service.

What you get

  • Terraform and Helm for Tetragon across your EKS clusters and accounts
  • A TracingPolicy repository with review, rollout and rollback workflow
  • Event pipeline with cluster, account and namespace enrichment
  • Storage and query layer in ClickHouse, Elasticsearch or your existing SIEM
  • Prometheus metrics, dashboards and alerting on the agent itself
  • Upgrade procedure and operational runbooks

Related engineering notes