Runtime Monitoring and LoggingΒΆ

OverviewΒΆ

The Bunker-Centric Architecture reference implementation provides two complementary runtime observation paths for the Open World:

  • Logging path, relying on Fluent Bit to collect operational and audit logs generated by applications, services, system components, containers, and custom diagnostic sources.

  • Monitoring path, relying on Falco to observe runtime behavior and generate security events when suspicious or policy-relevant activity is detected.

Both monitoring components collect data in the Open World, but unlike Fluent Bit, Falco uses a split architecture for security:

  • Fluent Bit runs entirely in Open World: it collects, parses, and forwards logs to Bunker OS via Turmux RPC.

  • Falco is split between domains: the kernel module runs in Open World to collect kernel events, while the userspace daemon, rule evaluation, and alert handling run in the trusted Bunker OS. This separation ensures that sensitive rule evaluation and response policy decisions cannot be compromised by an attacker with access to Open World.

The generated records and security events are then forwarded to the Bunker OS, where they are stored, managed, and evaluated against the configured response policies.

This separation allows the system to collect observations from an untrusted or potentially exposed domain while performing all security-sensitive decision-making on the trusted side.

Component RolesΒΆ

Runtime observation in the Bunker-Centric Architecture uses two complementary components deployed across the trusted and untrusted domains:

Fluent Bit (Open World) is a lightweight logs, metrics, and traces processor and forwarder. It is used to collect records from applications, services, system components, containers, and custom diagnostic sources, then parse, enrich, and forward those records to the Bunker Logger Service running in Bunker OS. This matches Fluent Bit’s role as a high-performance collector and forwarder for telemetry data.

Falco (Split Architecture) is a runtime security tool with a split deployment model: the kernel module runs in Open World to observe runtime activity and collect Linux kernel events, while the userspace daemon and rule evaluation engine run in Bunker OS to process events, generate alerts, and enforce response policies. This architecture keeps low-level event collection close to the monitored workloads while ensuring that all security-sensitive decision-making occurs on the trusted side, preventing an attacker with Open World access from tampering with rules or suppressing alerts.

Together, Fluent Bit and Falco provide complementary visibility: Fluent Bit focuses on collecting and forwarding operational, diagnostic, and audit logs, while Falco focuses on detecting runtime security events and anomalous behavior through trusted evaluation of kernel events.

Architecture SummaryΒΆ

Open World (untrusted)
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Applications, services, network endpoints, diagnostics     β”‚
β”‚                                                            β”‚
β”‚  Fluent Bit                                                β”‚
β”‚  β”œβ”€ Collects system, application and custom logs           β”‚
β”‚  β”œβ”€ Parses and enriches records                            β”‚
β”‚  └─ Sends records to the Bunker Logger Service             β”‚
β”‚                                                            β”‚
β”‚  Falco Driver                                              β”‚
β”‚  └─ Observes runtime activity through syscall events       β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                             β”‚
                     VSOCK / RPC channel
                             β”‚
Bunker OS (trusted)          β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ RPC Router and Core Services                               β”‚
β”‚                                                            β”‚
β”‚  Logger Service                                            β”‚
β”‚  └─ Stores Open World logs                                 β”‚
β”‚                                                            β”‚
β”‚  Falco Runtime                                             β”‚
|  β”œβ”€ Evaluates events against security rules                β”‚
β”‚  β”œβ”€ Stores Falco security events                           β”‚
β”‚  └─ Classifies events and evaluates response policies      β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Safeguard and Recovery ActionsΒΆ

The monitoring path can be connected to safeguard or recovery actions managed from the trusted side.

When a Falco event is received, the Bunker OS evaluates the configured response policy according to the event severity, rule, source, and product-specific configuration. Depending on the policy, the event may be stored only, reported to higher-level management functions, or used to trigger a recovery action.

In the current implementation, Falco events with priority WARNING or higher trigger a hypervisor call to reboot the Open World.

Detailed DocumentationΒΆ