Uploaded August 2026 | Updated September 2026, 3 weeks ago
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Shanghai, China (8-9 September, 2026) and Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
Detecting Compromised CI With eBPF and Cilium Tetragon - Liz Rice, Isovalent at Cisco
CI/CD pipelines are a prime target for attackers. Recent incidents, such as the Trivy workflow compromise, show how CI can be abused to execute untrusted code and exfiltrate sensitive data.
Tetragon, the eBPF-based runtime security component of the Cilium project, is widely used to protect Kubernetes workloads. This talk shows how it can also be applied to CI environments such as GitHub Actions to detect compromised jobs and prevent data exfiltration.
After a brief introduction to how Tetragon leverages eBPF, this talk demonstrates its use in GitHub Actions, providing runtime signals that reveal malicious behavior. You’ll see concrete examples of policies that observe process and network activity to detect unexpected outbound connections and identify compromised jobs in real time.
Attendees will learn practical techniques to use Tetragon to detect and prevent malicious behavior in ephemeral CI environments.
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Shanghai, China (8-9 September, 2026) and Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
Detecting Compromised CI With eBPF and Cilium Tetragon - Liz Rice, Isovalent at Cisco
CI/CD pipelines are a prime target for attackers. Recent incidents, such as the Trivy workflow compromise, show how CI can be abused to execute untrusted code and exfiltrate sensitive data.
Tetragon, the eBPF-based runtime security component of the Cilium project, is widely used to protect Kubernetes workloads. This talk shows how it can also be applied to CI environments such as GitHub Actions to detect compromised jobs and prevent data exfiltration.
After a brief introduction to how Tetragon leverages eBPF, this talk demonstrates its use in GitHub Actions, providing runtime signals that reveal malicious behavior. You’ll see concrete examples of policies that observe process and network activity to detect unexpected outbound connections and identify compromised jobs in real time.
Attendees will learn practical techniques to use Tetragon to detect and prevent malicious behavior in ephemeral CI environments.










