Pahlevan documentation
Everything Pahlevan ships with, published here rather than only in the repository: how it learns a workload, what the policy fields mean, what the kernel needs, and what to do when enforcement is not doing what you expected.
Quick Start Guide
This guide will get Pahlevan running in your Kubernetes cluster in under 5 minutes.
Read →Architecture
Pahlevan splits a privileged per-node data plane from an unprivileged, leader-elected control plane. The agent owns everything that touches the kernel; the operator owns everything that...
Read →System Requirements
Pahlevan runs in the kernel, so what it can do on a given node is decided by that node's kernel, not by the chart you installed. This page states the floors that can be justified from the...
Read →Deployment Guide
This guide covers running Pahlevan in production: what actually gets deployed, how it is sized and configured, how enforcement is rolled out without taking a workload down, and how the...
Read →Policy reference
A PahlevanPolicy says which workloads Pahlevan governs, how long it watches them before it decides what normal looks like, and what the kernel does with an operation that falls outside that...
Read →API reference
Every field below exists in the CRD the API server serves, because this document is generated from the Go types rather than written alongside them.
Read →Packages and Releases
Pahlevan publishes three artifacts per release: a container image, a Helm chart, and a single-file Kubernetes manifest. Release notes live in CHANGELOG.md and on the GitHub releases page.
Read →Troubleshooting
This guide is organised by what you see, not by what the code is called. Each entry quotes the text the binaries actually produce, so searching your logs for the message in front of you...
Read →The optional dashboard
Everything Pahlevan learns is already reachable through kubectl get -o yaml, a Prometheus scrape, or a log line. In practice that means a learned profile is a YAML status block nobody reads...
Read →What Pahlevan does to a real workload
Every claim in this project's documentation is about kernel behavior, which is easy to assert and hard to check. This page is the check: a harness that runs a real web application under...
Read →The BPF LSM
Four of Pahlevan's eight eBPF programs attach to BPF LSM hooks, and those hooks are the only place the data plane can refuse a request before it takes effect. A BPF LSM program attaches...
Read →Generating a NetworkPolicy from what was observed
pahlevan netpol turns a learned network baseline into a networking.k8s.io/v1 NetworkPolicy you can review and apply.
Read →Pahlevan Documentation
Pahlevan is an eBPF Kubernetes security operator. It learns what a container actually does, then refuses everything else in the kernel, at the LSM hook, before the operation completes.
Read →Pahlevan on a live web application
A static file server ran for 50m0s under continuous traffic while Pahlevan observed it. Enforcement was then switched on and the workload was attacked. Nothing below is asserted: each line...
Read →