add falco operator plugin and custom rules
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Failing after 3m11s

This commit is contained in:
2026-08-10 21:22:55 -04:00
parent caedb9ab8d
commit 15570310ed
4 changed files with 74 additions and 0 deletions
@@ -0,0 +1,14 @@
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Plugin
metadata:
name: container
namespace: falco
annotations:
argocd.argoproj.io/sync-wave: "1"
spec:
ociArtifact:
image:
repository: falcosecurity/plugins/plugin/container
tag: latest
registry:
name: ghcr.io
@@ -0,0 +1,39 @@
# Custom runtime detections for the portfolio baseline.
# These rules supplement the default Falco rules and are intentionally scoped
# to container activity for a clear admission-to-runtime demonstration.
- list: sensitive_container_paths
items: [/etc/passwd, /etc/shadow, /etc/sudoers, /etc/ssh/sshd_config]
- rule: Shell spawned in container
desc: A shell process was started inside a running container.
condition: spawned_process and container and proc.name in (bash, sh, ash, zsh, ksh, fish)
output: >-
Shell spawned in container
(user=%user.name user_uid=%user.uid shell=%proc.name command=%proc.cmdline
container_id=%container.id container_image=%container.image.repository
container_name=%container.name k8s_ns=%k8s.ns.name k8s_pod=%k8s.pod.name)
priority: WARNING
tags: [container, process, baseline]
- rule: Sensitive file modified in container
desc: A process attempted to write a sensitive host-like file from a container.
condition: open_write and container and fd.name in (sensitive_container_paths)
output: >-
Sensitive file modified in container
(user=%user.name command=%proc.cmdline file=%fd.name
container_id=%container.id container_image=%container.image.repository
k8s_ns=%k8s.ns.name k8s_pod=%k8s.pod.name)
priority: ERROR
tags: [container, filesystem, persistence, baseline]
- rule: Unexpected outbound connection from container
desc: A container opened a connection to a non-loopback address.
condition: evt.type=connect and container and not fd.sip in (127.0.0.1, 0.0.0.0)
output: >-
Outbound connection from container
(user=%user.name command=%proc.cmdline connection=%fd.name
container_id=%container.id container_image=%container.image.repository
k8s_ns=%k8s.ns.name k8s_pod=%k8s.pod.name)
priority: NOTICE
tags: [container, network, baseline]
@@ -0,0 +1,11 @@
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Rulesfile
metadata:
name: custom-rules
namespace: falco
annotations:
argocd.argoproj.io/sync-wave: "2"
spec:
priority: 60
configMapRef:
name: falco-custom-rules
@@ -4,3 +4,13 @@ resources:
- namespace.yaml
- falco-instance.yaml
- falco-config.yaml
- container-plugin.yaml
- custom-rulesfile.yaml
configMapGenerator:
- name: falco-custom-rules
files:
- custom-rules.yaml
generatorOptions:
disableNameSuffixHash: true