kubearmor / KubeArmor

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (BPF-LSM, AppArmor).
https://kubearmor.io/
Apache License 2.0
1.45k stars 335 forks source link

BPF LSM Performance #1152

Open daemon1024 opened 1 year ago

daemon1024 commented 1 year ago

KubeArmor induces considerable impact with BPF LSM as enforcer. We need to work towards optimising it.

cc @DelusionalOptimist @Shreyas220 Can you include the data here?

DelusionalOptimist commented 1 year ago

https://github.com/kubearmor/KubeArmor/wiki/KubeArmor-Performance-Benchmarking-Data#bpf-lsm-benchmarking-data

DelusionalOptimist commented 6 months ago

The benchmarks done in v1.2.0 seem to have improved this. Good to close @daemon1024 ? Ref - https://github.com/kubearmor/KubeArmor/wiki/KubeArmor-Performance-Benchmarking-Data