AWS guardduty: Replace EC2 runtime monitoring OS/kernel support table with link
Summary
Removed the inline table of verified OS distributions and kernel versions (plus footnotes on Graviton, CONFIG_DEBUG_INFO_BTF, and RLIMIT_MEMLOCK) and replaced it with a link to a dedicated supported CPU/OS/kernel page.
Security assessment
This is a documentation restructuring that moves support matrix content to another page; it does not address a vulnerability or add new security guidance.
Evidence
+For the verified CPU architectures, OS distributions, and kernel versions, see [Supported CPU architectures, operating systems, and kernel versions](./prereq-runtime-monitoring-cpu-os-kernel-support.html).
Diff
diff --git a/guardduty/latest/ug/prereq-runtime-monitoring-ec2-support.md b/guardduty/latest/ug/prereq-runtime-monitoring-ec2-support.md index 5194556a6..173b331a7 100644 --- a//guardduty/latest/ug/prereq-runtime-monitoring-ec2-support.md +++ b//guardduty/latest/ug/prereq-runtime-monitoring-ec2-support.md @@ -40,25 +40 @@ The architecture of your OS distribution might impact how the GuardDuty security - * Kernel support includes `eBPF`, `Tracepoints` and `Kprobe`. For CPU architectures, Runtime Monitoring supports AMD64 (`x64`) and ARM64 (Graviton2 and above)1. - -The following table shows the OS distribution that has been verified to support the GuardDuty security agent for Amazon EC2 instances. - -OS distribution2 | Kernel version3 ----|--- -Amazon Linux 2 | 5.44, 5.104, 5.15 -Amazon Linux 2023 | 5.44, 5.104, 5.15, 6.1, 6.5, 6.8, 6.12 -Ubuntu 20.04, 22.04, 24.04, 26.04 | 5.44, 5.104, 5.15, 6.1, 6.5, 6.8, 6.13, 6.14, 7.0 -Debian 11, 12, 13 | 5.44, 5.104, 5.15, 6.1, 6.5, 6.8, 6.12 -RedHat 9.4, 10.2 | 5.14, 6.12 -Fedora 34, 40, 41, 43, 44 | 5.11, 5.17, 6.8, 6.12, 7.1 -CentOS Stream 9, 10 | 5.14, 6.12 -Oracle Linux 8.9, 9.3 | 5.15 -Rocky Linux 9.5, 10.1 | 5.14, 6.12 -Alma Linux 9, 10 | 5.14, 6.12 -SUSE Linux Enterprise Server 16 | 6.12 - - 1. Runtime Monitoring for Amazon EC2 resources doesn't support the first generation Graviton instance such as A1 instance types. - - 2. Support for various operating systems - GuardDuty has verified Runtime Monitoring support for the operating distribution listed in the preceding table. While the GuardDuty security agent may run on operating systems not listed in the preceding table, the GuardDuty team cannot guarantee the expected security value. - - 3. For any kernel version, you must set the `CONFIG_DEBUG_INFO_BTF` flag to `y` (meaning _true_). This is required so that the GuardDuty security agent can run as expected. - - 4. For kernel versions 5.10 and earlier, the GuardDuty security agent uses locked memory in RAM (`RLIMIT_MEMLOCK`) to function as expected. If your system's `RLIMIT_MEMLOCK` value is set too low, GuardDuty recommends setting both hard and soft limits to at least 32 MB. For information about verifying and modifying the default `RLIMIT_MEMLOCK` value, see Viewing and updating RLIMIT_MEMLOCK values. +For the verified CPU architectures, OS distributions, and kernel versions, see [Supported CPU architectures, operating systems, and kernel versions](./prereq-runtime-monitoring-cpu-os-kernel-support.html).