Runtime Monitoring and LoggingΒΆ
OverviewΒΆ
The Bunker-Centric Architecture reference implementation provides two complementary runtime observation paths for the Open World:
Logging path, relying on Fluent Bit to collect operational and audit logs generated by applications, services, system components, containers, and custom diagnostic sources.
Monitoring path, relying on Falco to observe runtime behavior and generate security events when suspicious or policy-relevant activity is detected.
Both monitoring components collect data in the Open World, but unlike Fluent Bit, Falco uses a split architecture for security:
Fluent Bit runs entirely in Open World: it collects, parses, and forwards logs to Bunker OS via Turmux RPC.
Falco is split between domains: the kernel module runs in Open World to collect kernel events, while the userspace daemon, rule evaluation, and alert handling run in the trusted Bunker OS. This separation ensures that sensitive rule evaluation and response policy decisions cannot be compromised by an attacker with access to Open World.
The generated records and security events are then forwarded to the Bunker OS, where they are stored, managed, and evaluated against the configured response policies.
This separation allows the system to collect observations from an untrusted or potentially exposed domain while performing all security-sensitive decision-making on the trusted side.
Component RolesΒΆ
Runtime observation in the Bunker-Centric Architecture uses two complementary components deployed across the trusted and untrusted domains:
Fluent Bit (Open World) is a lightweight logs, metrics, and traces processor and forwarder. It is used to collect records from applications, services, system components, containers, and custom diagnostic sources, then parse, enrich, and forward those records to the Bunker Logger Service running in Bunker OS. This matches Fluent Bitβs role as a high-performance collector and forwarder for telemetry data.
Falco (Split Architecture) is a runtime security tool with a split deployment model: the kernel module runs in Open World to observe runtime activity and collect Linux kernel events, while the userspace daemon and rule evaluation engine run in Bunker OS to process events, generate alerts, and enforce response policies. This architecture keeps low-level event collection close to the monitored workloads while ensuring that all security-sensitive decision-making occurs on the trusted side, preventing an attacker with Open World access from tampering with rules or suppressing alerts.
Together, Fluent Bit and Falco provide complementary visibility: Fluent Bit focuses on collecting and forwarding operational, diagnostic, and audit logs, while Falco focuses on detecting runtime security events and anomalous behavior through trusted evaluation of kernel events.
Architecture SummaryΒΆ
Open World (untrusted)
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Applications, services, network endpoints, diagnostics β
β β
β Fluent Bit β
β ββ Collects system, application and custom logs β
β ββ Parses and enriches records β
β ββ Sends records to the Bunker Logger Service β
β β
β Falco Driver β
β ββ Observes runtime activity through syscall events β
ββββββββββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββ
β
VSOCK / RPC channel
β
Bunker OS (trusted) β
ββββββββββββββββββββββββββββββ΄ββββββββββββββββββββββββββββββββ
β RPC Router and Core Services β
β β
β Logger Service β
β ββ Stores Open World logs β
β β
β Falco Runtime β
| ββ Evaluates events against security rules β
β ββ Stores Falco security events β
β ββ Classifies events and evaluates response policies β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Safeguard and Recovery ActionsΒΆ
The monitoring path can be connected to safeguard or recovery actions managed from the trusted side.
When a Falco event is received, the Bunker OS evaluates the configured response policy according to the event severity, rule, source, and product-specific configuration. Depending on the policy, the event may be stored only, reported to higher-level management functions, or used to trigger a recovery action.
In the current implementation, Falco events with priority WARNING or higher trigger a hypervisor call to reboot the Open World.