4/ Kernel hardening, sorted by what it actually costs you:
A. Free housekeeping (`kernel.dmesg_restrict=1`, `fs.suid_dumpable=0`)
B. Nearly free: prune and lock kernel modules
C. Costs visibility: `ptrace`, eBPF
D. Costs performance
E. Costs real money: SMT, `io_uring`