Problem With Deploying Defend 4 Container from Elastic due to missing kernel option
Nobody has claimed this yet.
- Dominant language
- C
- Stars
- 3.2k
- Forks
- 692
- PR merge metrics
- No merged PRs in 30d
Description
Describe the bug
Hi,
We are currently enrolling Elastic Defend for Containers on our Vmware Tanzu Kubernetes env. running photonOS.
This however isnt working because the CONFIG_BPF_LSM option isnt set in the kernel. Is it possible for you guys to deploy this by default? If no, what would be the best way to do this ourselves and is there a chance this would mess up our envirionment.
Kind regards,
P.
Reproduction steps
- Have Vmware Tanzu Kubernetes with PothonOS
- Install defend for containers
- watch it not working
...
Expected behavior
- Have Vmware Tanzu Kubernetes with PothonOS
- Install defend for containers
- watch it work
...
Additional context
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No source file or test is named. Start by reviewing PhotonOS kernel configuration and the CONFIG_BPF_LSM setting, then check how the kernel is built for VMware Tanzu Kubernetes and whether enabling it affects supported environments. Done means documenting or implementing a supported default, with validation that Elastic Defend for Containers can enroll successfully.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c, linux
- Domain
- operating-systems
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100