Show HN: Kguardian – seccomp profiles and NetworkPolicies from eBPF traces Kguardian, a new open-source Kubernetes security tool, generates least-privilege NetworkPolicy, CiliumNetworkPolicy, and seccomp profiles from eBPF traces of pod traffic and syscalls rather than hand-authored rules. The tool uses an eBPF DaemonSet Controller to capture every TCP/UDP connection and syscall per node, a Broker that stores per-pod baselines in PostgreSQL, and a kubectl kguardian plugin that emits policy YAML for a pod, namespace, or cluster; it never applies policies itself, writing files to --output-dir for review. Kguardian also offers an AuditNetworkPolicy CRD that reports flows a policy would deny, cgroup v2 CPU/memory gauges with noisy-neighbour findings, and an optional LLM Bridge AI assistant for querying traffic and syscall data in natural language. Least-privilege Kubernetes security policies, generated from what your pods actually do Overview -overview · In action -in-action · Features -features · Architecture %EF%B8%8F-architecture · Quick Start -quick-start · Usage %EF%B8%8F-usage · AI Assistant -ai-assistant · Compatibility -compatibility · Performance -performance · Telemetry -telemetry · Contributing -contributing · License -license kguardian watches pod traffic and syscalls with eBPF, then writes Kubernetes NetworkPolicy , CiliumNetworkPolicy , and seccomp profiles from what it sees — no hand-authored rules. It's built for platform and security teams who want policy-as-code without writing rules by hand: the Controller an eBPF DaemonSet captures every TCP/UDP connection and syscall on each node, the Broker stores the per-pod baseline in PostgreSQL, and the kubectl kguardian plugin turns that baseline into least-privilege policy YAML for any pod, namespace, or the whole cluster. |