Services
Tetragon
Deployment and operation of Tetragon on EKS and Linux hosts: policy management in Git, event pipelines, storage integration, agent monitoring and upgrades.
Scope
Deployment and operation of Tetragon for process, file and network observability, and optionally enforcement, on Amazon EKS clusters and standalone Linux hosts.
| Area | Included |
|---|---|
| Installation | Helm chart or host package, per-cluster values, Terraform for supporting resources |
| Policy | TracingPolicy repository, CI validation, canary-then-fleet rollout, rollback |
| Access control | Kubernetes RBAC on TracingPolicy resources |
| Events | Export configuration, allowlists, filtering, enrichment with cluster and account identity |
| Delivery | Routing to ClickHouse, Elasticsearch, OpenSearch, S3 or an existing SIEM |
| Agent health | Prometheus metrics, dashboards, alerts on drops and lag |
| Lifecycle | Upgrade procedure, kernel and node-group compatibility checks |
Requirements
- Linux nodes with a kernel that supports the required BPF features. Compatibility is checked per node group during assessment with
tetra probe config. - Ability to deploy a privileged DaemonSet.
- A destination for events, or a decision on which to use.
- For fleet work, a GitOps or CI mechanism that can apply per-cluster configuration.
Event handling
Tetragon exports a high volume of events. The default position is to filter at the agent, keep raw telemetry in low-cost storage with short retention, and forward only high-confidence detections to alerting. Retention is set per event class. Ordinary exec events and policy matches usually need different lifetimes.
Phases
| Phase | Output |
|---|---|
| Assessment | Cluster and kernel inventory, event volume estimate, target architecture document |
| Pilot | One non-production cluster running Tetragon, baseline policies and the event pipeline |
| Rollout | Fleet deployment in waves, with per-wave performance measurements |
| Handoff | Documentation, runbooks, upgrade procedure, walkthrough |
Each phase has fixed scope and price, agreed after the assessment.
Out of scope
Alert triage and 24/7 monitoring. Palm Sec builds and hands over the platform and does not operate it as a managed service.
What you get
- Terraform and Helm for Tetragon across your EKS clusters and accounts
- A TracingPolicy repository with review, rollout and rollback workflow
- Event pipeline with cluster, account and namespace enrichment
- Storage and query layer in ClickHouse, Elasticsearch or your existing SIEM
- Prometheus metrics, dashboards and alerting on the agent itself
- Upgrade procedure and operational runbooks