AWS guardduty: Restructure EKS Runtime Monitoring prerequisites; add kernel 5.4 ARM64 DNS note
Summary
Replaces the inline OS/kernel/CPU support table with a link to a new dedicated page, adds a note that kernel 5.4 on ARM64 (aarch64) cannot generate DNS-related Runtime Monitoring findings, adds a new GuardDuty security agent add-on version row (v1.17.1), and renames a section heading.
Security assessment
The change documents a known limitation of the GuardDuty Runtime Monitoring agent (no DNS event findings on kernel 5.4 ARM64) and reorganizes prerequisite/support information. It is security-relevant documentation of detection coverage gaps but does not address a specific vulnerability or incident.
Evidence
+Presently, with kernel version `5.4` in ARM64(`aarch64`), GuardDuty can't generate [GuardDuty Runtime Monitoring finding types](./findings-runtime-monitoring.html) that are related to [Domain Name System (DNS) events](./runtime-monitoring-collected-events.html#eks-runtime-dns-events).
Diff
diff --git a/guardduty/latest/ug/prereq-runtime-monitoring-eks-support.md b/guardduty/latest/ug/prereq-runtime-monitoring-eks-support.md index 479c51463..fb159eb50 100644 --- a//guardduty/latest/ug/prereq-runtime-monitoring-eks-support.md +++ b//guardduty/latest/ug/prereq-runtime-monitoring-eks-support.md @@ -27,27 +27 @@ The platform that you use may impact how GuardDuty security agent supports Guard -The OS distribution, kernel version, and CPU architecture affect the support provided by the GuardDuty security agent. Kernel support includes `eBPF`, `Tracepoints` and `Kprobe`. For CPU architectures, Runtime Monitoring supports AMD64 (`x64`) and ARM64(Graviton2 and above)1. - -The following table shows the verified configuration for deploying the GuardDuty security agent and configuring EKS Runtime Monitoring. - -OS distribution**2** | Kernel version**3** | Supported Kubernetes version ----|---|--- -Bottlerocket | 5.4, 5.10, 5.15, 6.14 | v1.23 - v1.36 -Ubuntu | 5.4, 5.10, 5.15, 6.1, 6.15, 6.16, 6.17, 6.184 | v1.21 - v1.36 -Amazon Linux 2 | 5.4, 5.10, 5.15, 6.14 | v1.21 - v1.36 -Amazon Linux 2023 _5_ | 5.4, 5.10, 5.15, 6.1, 6.8, 6.124 | v1.21 - v1.36 -RedHat 9.4 | 5.144 | v1.21 - v1.36 -Fedora 34 | 5.11, 5.17 | v1.21 - v1.36 -Fedora 40 | 6.8 | v1.28 - v1.36 -Fedora 41 | 6.12 | v1.28 - v1.36 -CentOS Stream 9 | 5.14 | v1.21 - v1.36 - - 1. Runtime Monitoring for Amazon EKS clusters doesn't support the first generation Graviton instance such as A1 instance types. - - 2. Support for various operating systems - GuardDuty has verified Runtime Monitoring support for the operating distribution listed in the preceding table. While the GuardDuty security agent may run on operating systems not listed in the preceding table, the GuardDuty team cannot guarantee the expected security value. - - 3. For any kernel version, you must set the `CONFIG_DEBUG_INFO_BTF` flag to `y` (meaning _true_). This is required so that the GuardDuty security agent can run as expected. - - 4. Presently, with Kernel version `6.1`, GuardDuty can't generate [GuardDuty Runtime Monitoring finding types](./findings-runtime-monitoring.html) that are related to [Domain Name System (DNS) events](./runtime-monitoring-collected-events.html#eks-runtime-dns-events). - - 5. Runtime Monitoring supports AL2023 with the release of the GuardDuty security agent v1.6.0 and above. For more information, see [GuardDuty security agent versions for Amazon EKS resources](./runtime-monitoring-agent-release-history.html#eks-runtime-monitoring-agent-release-history). - - +For the verified CPU architectures, OS distributions, and kernel versions, see [Supported CPU architectures, operating systems, and kernel versions](./prereq-runtime-monitoring-cpu-os-kernel-support.html). @@ -54,0 +29 @@ CentOS Stream 9 | 5.14 | v1.21 - v1.36 +Presently, with kernel version `5.4` in ARM64(`aarch64`), GuardDuty can't generate [GuardDuty Runtime Monitoring finding types](./findings-runtime-monitoring.html) that are related to [Domain Name System (DNS) events](./runtime-monitoring-collected-events.html#eks-runtime-dns-events). @@ -61,0 +37 @@ Amazon EKS add-on GuardDuty security agent version | Kubernetes version +v1.17.1 (latest - v1.17.1-eksbuild.2) | 1.31 - 1.36 @@ -106 +82 @@ For Fargate (ECS only) cluster -Enabling Runtime Monitoring +Supported CPU architectures, operating systems, and kernel versions