Commit 6570cf8
Runtime Package Prioritization: document enablement prerequisites and event volume tuning (#39354)
* Runtime Package Prioritization: document enablement prerequisites and event volume tuning
Adds the kernel, host PID namespace, and PodSecurity prerequisites, plus
enrichment interval tuning guidance for large fleets.
Co-Authored-By: Claude <noreply@anthropic.com>
* Soften system-probe memory guidance and add a verification step
Replaces the fixed memory recommendation with monitoring guidance, and
adds a verification step to each setup page.
Co-Authored-By: Claude <noreply@anthropic.com>
* Link kernel support instead of restating a version
Points at the Workload Protection distribution list rather than naming a
kernel version on three pages.
Co-Authored-By: Claude <noreply@anthropic.com>
* Correct claims that did not hold up against Agent source
- Drops the hostPID and --pid host requirements: the real dependency is the
host /proc mount, and hostPID is baseline Agent configuration.
- States that the setting starts system-probe, which is the actual change to
a node's footprint.
- Corrects the verification step: the Agent status output has no SBOM section,
the sbom check appears under Collector.
- Corrects the enrichment interval trade-off: first observations bypass the
interval, so only repeat observations are throttled.
- Drops the claim that system-probe memory grows with image count; its caches
are fixed size.
Co-Authored-By: Claude <noreply@anthropic.com>
* Cut repeated version and Workload Protection notes, add Docker tuning
The version requirement and the Workload Protection statement each appeared
three or four times per page, and described pre-7.79 behavior the pages tell
readers not to use. Each now appears once. Adds the enrichment interval
guidance to the Docker page for parity.
Co-Authored-By: Claude <noreply@anthropic.com>
* Name the supported package managers in the scope line
"Operating system packages" was open to interpretation. States apt/dpkg,
yum/dnf/rpm, and apk, and that application libraries and unmanaged binaries
receive no runtime signals.
Co-Authored-By: Claude <noreply@anthropic.com>
* Trim wording to match the style of neighboring setup pages
Cuts mechanism explanations, the Agent status check that reported nothing
about this feature, and redundant qualifiers. Verification now leads with
the product outcome, matching the Verify sections on other setup pages.
Co-Authored-By: Claude <noreply@anthropic.com>
* State only what the feature supports, and align the RPE page
Drops two sentences that claimed more than needed. Adds the same scope
statement to the Runtime Prioritization Engine page and aligns its Agent
version guidance with the setup pages.
Co-Authored-By: Claude <noreply@anthropic.com>
* Remove the enrichment interval tuning guidance
The default is appropriate at customer scale, raising the interval reduces
signal freshness, and the effect is not observable from the Agent. Keeps the
system-probe memory note.
Co-Authored-By: Claude <noreply@anthropic.com>
* Keep only the requirements, the version risk, and the scope
Requirements now lists actual requirements. Restores the pre-7.79 Workload
Protection caveat as a single note, states signal scope once, and drops the
procfs, system-probe, and memory lines the proven enablement path never needed.
Co-Authored-By: Claude <noreply@anthropic.com>
* Remove the pre-7.79 Workload Protection note
The pages require 7.79.0 or later, so the note described a configuration
readers are not being pointed to. Removing it avoids suggesting the legacy
path is current.
Co-Authored-By: Claude <noreply@anthropic.com>
* Apply review feedback
- Add the missing period to the version bullet on the Docker and Linux pages.
- Split the runtime signals sentence on the engine page.
- Make the Agent version formatting consistent under Get started.
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>1 parent e3c7d29 commit 6570cf8
4 files changed
Lines changed: 21 additions & 17 deletions
File tree
- hugo/content/en/security/cloud_security_management
- setup/agent
- triage_and_prioritize
Lines changed: 6 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
70 | 70 | | |
71 | 71 | | |
72 | 72 | | |
73 | | - | |
74 | | - | |
75 | | - | |
| 73 | + | |
| 74 | + | |
76 | 75 | | |
77 | | - | |
| 76 | + | |
78 | 77 | | |
79 | 78 | | |
80 | 79 | | |
| |||
88 | 87 | | |
89 | 88 | | |
90 | 89 | | |
91 | | - | |
| 90 | + | |
92 | 91 | | |
93 | 92 | | |
94 | 93 | | |
95 | 94 | | |
96 | 95 | | |
97 | 96 | | |
98 | | - | |
| 97 | + | |
| 98 | + | |
Lines changed: 6 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
166 | 166 | | |
167 | 167 | | |
168 | 168 | | |
169 | | - | |
| 169 | + | |
170 | 170 | | |
171 | 171 | | |
172 | 172 | | |
| |||
206 | 206 | | |
207 | 207 | | |
208 | 208 | | |
209 | | - | |
210 | | - | |
| 209 | + | |
211 | 210 | | |
212 | | - | |
| 211 | + | |
213 | 212 | | |
214 | 213 | | |
215 | 214 | | |
| |||
276 | 275 | | |
277 | 276 | | |
278 | 277 | | |
| 278 | + | |
| 279 | + | |
279 | 280 | | |
280 | 281 | | |
281 | 282 | | |
| |||
286 | 287 | | |
287 | 288 | | |
288 | 289 | | |
| 290 | + | |
Lines changed: 7 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
51 | 51 | | |
52 | 52 | | |
53 | 53 | | |
54 | | - | |
| 54 | + | |
55 | 55 | | |
56 | 56 | | |
57 | 57 | | |
| |||
100 | 100 | | |
101 | 101 | | |
102 | 102 | | |
103 | | - | |
104 | | - | |
105 | | - | |
| 103 | + | |
| 104 | + | |
106 | 105 | | |
107 | | - | |
| 106 | + | |
108 | 107 | | |
109 | 108 | | |
110 | 109 | | |
| |||
121 | 120 | | |
122 | 121 | | |
123 | 122 | | |
| 123 | + | |
| 124 | + | |
124 | 125 | | |
125 | 126 | | |
126 | 127 | | |
| |||
146 | 147 | | |
147 | 148 | | |
148 | 149 | | |
| 150 | + | |
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
55 | 55 | | |
56 | 56 | | |
57 | 57 | | |
58 | | - | |
| 58 | + | |
59 | 59 | | |
60 | 60 | | |
61 | 61 | | |
| |||
75 | 75 | | |
76 | 76 | | |
77 | 77 | | |
78 | | - | |
| 78 | + | |
79 | 79 | | |
80 | 80 | | |
81 | 81 | | |
| |||
0 commit comments