16-17 June
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for KubeCon + CloudNativeCon Japan 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Japan Standard Time (UTC+9:00)To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date." The schedule is subject to change and session seating is available on a first-come, first-served basis. 
Monday June 16, 2025 14:24 - 14:29 JST
When a process like /usr/bin/curl runs in a pod (e.g., xwing in the default namespace), Tetragon detects it like bellow:

🚀 process default/xwing /bin/bash -c "curl https://ebpf.io/applications/#tetragon"
🚀 process default/xwing /usr/bin/curl https://ebpf.io/applications/#tetragon
💥 exit default/xwing /usr/bin/curl https://ebpf.io/applications/#tetragon 60

But how does it map that process to its pod?

This Lightning Talk explores how Tetragon connects the Linux kernel to Kubernetes by enriching eBPF-detected process data with Kubernetes metadata. I’ll break down how it extracts cgroup information from task_struct in kernel space and maps it to pod details using the Kubernetes API.
avatar for Yuki Nakamura

Yuki Nakamura

Platform Engeneer, mapbox
- Master’s degree in Computer Science at the University of Tokyo - IBM - Mapbox Blog: https://yuki-nakamura.com/
Monday June 16, 2025 14:24 - 14:29 JST
Level 1 | Orion
  ⚡ Lightning Talks, Security

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link