Views:
Note
Note
  • Container Security Helm version 2.3.14 added support for the modern Berkeley Packet Filter (BPF), also known as eBPF CO-RE (Compile Once, Run Everywhere). This allows Container Security to support any Linux kernel version 5.8 or later, as long as the BTF types are exposed.
  • If you are using runtime scanning in an ECS instance, you must use a kernel whose version is 5.8 or later.
The following is a non-exclusive list of the kernel version flavors supported by Container Security.
Platform
Version
Linux kernel version
Flavor
Amazon Linux
Amazon Linux 2
4.14.x
 
5.4.x
 
5.10.x
 
5.15.x and later
 
Amazon Linux 2023
6.1.x and later
 
Bottlerocket
 
5.10.x and later
 
Red Hat Enterprise Linux CoreOS (RHCOS)
RHEL 8.x
4.18.x
 
RHEL 9.x
5.14.x and later
 
Ubuntu
Ubuntu 18
4.15.x
generic
5.4.x and later
generic
5.4.x and later
Azure
5.4.x and later
AWS
5.4.x and later
GKE
Ubuntu 20
5.4.x
generic
5.4.x
Azure
5.4.x
AWS
5.4.x
GKE
5.11.x
generic
5.11.x
Azure
5.11.x
AWS
5.13.x
AWS
5.13.x
Azure
5.13.x
GKE
5.13.x
generic
5.15.x and later
AWS
5.15.x and later
Azure
5.15.x and later
GKE
5.15.x and later
generic
Debian
Debian 10
5.10.x
 
Debian 11
5.10.x and later
 
Debian 12
6.1.x and later
 
SUSE Linux
SUSE 15
5.3.x
 
5.14.x and later
 
Garden Linux OS
Garden Linux 934 and later
5.15.x
 
6.1.x and later
 
Flatcar Container Linux
Stable channel 2765.2.0
5.10.19 and later
 
LTS channel 3033.3.0
5.10.109 and later
 
Talos Linux
1.3.0 and later
5.15.83 Talos and later
 
AlmaLinux
AlmaLinux 9
5.10.x and later