Hands-on Lab·Certified Kubernetes Security Specialist
Falco Runtime Detection and Resource Limits
A syscall-level detector is the only thing that sees what happens INSIDE a container. This guide installs one, proves the kernel side works, and then reports honestly what it did on hardware this size.
Monitoring and Runtime Guide 35 of 40 Advanced
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 16 min
- Reviewed25 August 2026
Written against the versions above. Falco 0.41.3 with the modern eBPF engine on a 7.0 kernel with BTF. No alert output appears on this page, because none was produced.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA7001 | 192.168.0.51 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA7001-NODE01 | 192.168.0.52 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 17 - the prevention side of the same syscalls.
-
What a syscall detector needs from the kernel
-
What it asks for in return
-
What actually happened on a node this size
-
The part you are actually asked to write
-
Putting it back, and what to do instead