vmware / vmware/photon

Problem With Deploying Defend 4 Container from Elastic due to missing kernel option

Open
#1,636 5 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
C
Stars
3.2k
Forks
692
PR merge metrics
No merged PRs in 30d

Description

Describe the bug

Hi,

We are currently enrolling Elastic Defend for Containers on our Vmware Tanzu Kubernetes env. running photonOS.

This however isnt working because the CONFIG_BPF_LSM option isnt set in the kernel. Is it possible for you guys to deploy this by default? If no, what would be the best way to do this ourselves and is there a chance this would mess up our envirionment.

Kind regards,
P.

Reproduction steps
  1. Have Vmware Tanzu Kubernetes with PothonOS
  2. Install defend for containers
  3. watch it not working
    ...
Expected behavior
  1. Have Vmware Tanzu Kubernetes with PothonOS
  2. Install defend for containers
  3. watch it work
    ...
Additional context

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No source file or test is named. Start by reviewing PhotonOS kernel configuration and the CONFIG_BPF_LSM setting, then check how the kernel is built for VMware Tanzu Kubernetes and whether enabling it affects supported environments. Done means documenting or implementing a supported default, with validation that Elastic Defend for Containers can enroll successfully.

Written by the indexing model from the issue text.

Assessment

Tech stack
c, linux
Domain
operating-systems
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.