Serverless Agent Release Notes

Tip

For Installation and Upgrade steps, see AWS Fargate Serverless Agents.

1.0.1 April 15, 2021

Segmentation Fault Error Fixed

Fixed a problem that caused a segmentation fault error inside a Fargate task due to Sysdig instrumentation.

Container Definition Fields Now Support Complex Values

Added support for complex values inside Name and Image fields of the container definition. See also the ECS Task Definition docs from Amazon.

March 15, 2021: Serverless Agents Introduced

Sysdig Serverless Agent 1.0.0 for Fargate ECS

The "container-as-a-service" serverless environment calls for new agent models, and Sysdig provides them. Whereas in ECS, users still manage the underlying instances, with AWS Fargate the host is never visible and users simply run their workloads. And while this model is convenient, it can introduce risk as many people leave the containers unattended, without monitoring security events within that can exfiltrate secrets, compromise business data, impact performance, and increase their AWS costs. In addition, it is not possible to install a standard agent in an environment where you do not have access to a host.

For these reasons, Sysdig has introduced a new “serverless agent” model that can be deployed in these container-based cloud environments. The first implementation is for Fargate (ECS).

serverless_arch_2.png

Sysdig will be rolling out security features on the serverless agent over time. In v1.0.0, users will see:

  • Runtime Policies and Rules

  • Secure Events

To obtain secure event information and the associated Falco policies and rules in the Sysdig Secure UI from a Fargate environment, users install the serverless agent using a CloudFormation Template. Then log in to Sysdig Secure and review the events in the UI.

See also: AWS Fargate Serverless Agents and Serverless Agent Release Notes (for future updates).