How Clusters Fail Under Attack and How We Detect It at Runtime with eBPF Signals
Your pipeline is green. Every image scan passed, every policy check went through, the admission controller signed off. And your cluster still gets owned at runtime. This session follows Alex, a platform engineer whose build-time controls did everything right and still missed what mattered. We look at how clusters actually fail under attack: reverse shells opened from a running container, privilege escalation that never touches the API server, and process execution nobody wrote a policy for. Then we watch eBPF catch it. Using Tetragon, we run a live two-act demo: first detecting a reverse shell and a privilege escalation as they happen, then promoting those same detections into enforcement so the next attempt never completes. The takeaway is not that preventive controls are useless, it is that they are half the story. Runtime signals are what tell you the difference between a cluster that is secure and a cluster that has simply not been attacked yet.
Slides

Venue
Schuppen 52
A heritage-protected former cargo shed in the Port of Hamburg, built between 1908 and 1912, and now one of the city's largest event venues.