Skip to content

Can runAsUser: 0 and Privileged Mode Be Removed in eBPF Mode for falcon-node-sensor? #315

Answered by redhatrises
r3motecontrol asked this question in Q&A
Discussion options

You must be logged in to vote

Hello @r3motecontrol

I moved this to a discussion as it makes more sense as Q&A.

To answer your question, yes. Switching from a kernel module to an eBPF program doesn't change that. For security reasons, many parts of eBPF functionality require root permissions and privileges ; otherwise, anyone could have carte blanche access to your system. So, all the permissions that you see are still required.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@r3motecontrol
Comment options

Answer selected by r3motecontrol
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #314 on September 20, 2024 16:34.