No introduction found. Create it?
Install with:
helm repo add falco oci://ghcr.io/falcosecurity/charts/falco
helm install falco falco/falco -f values.yamlSee examples from other people.
| Name | Repo | Stars | Version | Timestamp |
|---|---|---|---|---|
| falco | oscaromeu/home-ops | 34 | 9.2.0 | 3 days ago |
| falco | xunholy/k8s-gitops | 641 | 9.2.0 | 6 months ago |
See the most popular values for this chart:
| Key | Types |
|---|---|
| boolean | |
| number | |
| boolean | |
| number | |
| boolean | |
| string | |
| boolean | |
falcosidekick.webui.ingress.hosts[].host (1) falco.${DOMAIN} | string |
| string | |
| string | |
falcosidekick.webui.ingress.tls[].hosts[] (1) - falco.${DOMAIN} | string |
falcosidekick.webui.ingress.tls[].secretName (1) falco-${DOMAIN/./-}-tls | string |
falcosidekick.config.alertmanager.hostport (3) http://vmalertmanager-victoria-metrics.observability.svc.cluster.local:9093 | string |
falcosidekick.config.alertmanager.endpoint (2) /api/v2/alerts | string |
falcosidekick.config.alertmanager.customseveritymap (1) emergency:critical,alert:critical,critical:critical,error:warning,warning:warning,notice:info,informational:info,debug:info | string |
falcosidekick.config.alertmanager.extralabels (1) category:security,component:falco | string |
| string | |
falcosidekick.config.customfields (1) cluster:main | string |
| boolean | |
| string | |
| string | |
| string | |
| boolean | |
| boolean | |
| boolean | |
| boolean | |
driver.kind (4) modern_ebpf | string |
| boolean | |
| boolean | |
| boolean | |
collectors.containerd.socket (1) /run/containerd/containerd.sock | string |
| boolean | |
| boolean | |
| boolean | |
| boolean | |
| boolean | |
collectors.containerEngine.engines.containerd.sockets[] (1) - /run/k3s/containerd/containerd.sock | string |
| boolean | |
| boolean | |
| boolean | |
| boolean | |
| boolean | |
| boolean | |
| boolean | |
| boolean | |
| boolean | |
| boolean | |
| string | |
| boolean | |
| string | |
falco.priority (1) notice | string |
falco.syscall_event_drops.actions[] (1) - log | string |
| number | |
| number | |
| boolean | |
| boolean | |
| string | |
| boolean | |
| boolean | |
| string | |
| string | |
| string | |
| boolean | |
| string | |
| string | |
| string | |
| string | |
controller.kind (1) daemonset | string |
customRules."kube-vip.yaml" (1) - rule: Packet socket created in container
exceptions:
- name: kube_vip_arp
fields:
- k8s.ns.name
- container.image.repository
- container.name
- proc.name
- proc.exepath
- evt.arg.type
- evt.arg.proto
comps: [=, =, =, =, =, =, =]
values:
- - kube-system
- ghcr.io/kube-vip/kube-vip
- kube-vip
- kube-vip
- /kube-vip
- 2
- 1544
override:
exceptions: append | string |
customRules."overrides.yaml" (1) - rule: Drop and execute new binary in container
override:
exceptions: append
exceptions:
- name: cni_plugins
fields: [proc.exepath]
comps: [startswith]
values:
- [/opt/cni/bin/]
- name: ci_namespaces
fields: [k8s.ns.name]
comps: [in]
values:
- [[actions-runner-system, development]]
# Patches its bundled chromedriver into /app on every start, so
# the binary is always newer than the image layer.
- name: flaresolverr_chromedriver
fields: [container.image.repository, proc.exepath]
comps: [=, =]
values:
- [ghcr.io/flaresolverr/flaresolverr, /app/chromedriver]
# Wazuh's own file-integrity monitoring reads /etc/shadow inside its
# container -- that is the product working, not credential theft.
- rule: Read sensitive file untrusted
override:
exceptions: append
exceptions:
- name: wazuh_fim
fields: [container.image.repository, proc.name]
comps: [=, in]
values:
- [docker.io/wazuh/wazuh-manager, [wazuh-syscheckd, wazuh-modulesd]] | string |
ebpf.enabled (1) true | boolean |
| boolean | |
| boolean | |
falcoctl.config.artifact.allowedTypes[] (1) - rulesfile | string |
falcoctl.config.artifact.follow.refs[] (1) - falco-rules:4 | string |
falcoctl.config.artifact.install.refs[] (1) - falco-rules:4 | string |
tty (1) true | boolean |