organize deployment configuration
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Successful in 1m6s

This commit is contained in:
2026-08-15 13:17:46 -04:00
parent 12f3276465
commit fc53e16dd4
18 changed files with 26 additions and 13 deletions
@@ -0,0 +1,17 @@
# Falco Operator settings. Falco instances and their artifacts are managed by
# the CRs under deployments/falco/operator-resources.
replicaCount: 1
# Keep ArgoCD tracking labels on the operator itself, not on resources created
# by the operator from Falco, Config, Plugin, or Rulesfile resources.
excludedLabels:
- argocd.argoproj.io/instance
- argocd.argoproj.io/tracking-id
resources:
requests:
cpu: 10m
memory: 64Mi
limits:
cpu: 500m
memory: 128Mi
@@ -0,0 +1,14 @@
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Plugin
metadata:
name: container
namespace: falco
annotations:
argocd.argoproj.io/sync-wave: "1"
spec:
ociArtifact:
image:
repository: falcosecurity/plugins/plugin/container
tag: latest
registry:
name: ghcr.io
@@ -0,0 +1,42 @@
# Custom runtime detections for the portfolio baseline.
# These rules supplement the default Falco rules and are intentionally scoped
# to container activity for a clear admission-to-runtime demonstration.
- list: sensitive_container_paths
items: [/etc/passwd, /etc/shadow, /etc/sudoers, /etc/ssh/sshd_config]
- macro: container_activity
condition: container.id != host
- rule: Shell spawned in container
desc: A shell process was started inside a running container.
condition: evt.type in (execve, execveat) and container_activity and proc.name in (bash, sh, ash, zsh, ksh, fish)
output: >-
Shell spawned in container
(user=%user.name user_uid=%user.uid shell=%proc.name command=%proc.cmdline
container_id=%container.id container_image=%container.image.repository
container_name=%container.name k8s_ns=%k8s.ns.name k8s_pod=%k8s.pod.name)
priority: WARNING
tags: [container, process, baseline]
- rule: Sensitive file modified in container
desc: A process attempted to write a sensitive host-like file from a container.
condition: evt.type in (open, openat, openat2) and evt.is_open_write=true and container_activity and fd.name in (sensitive_container_paths)
output: >-
Sensitive file modified in container
(user=%user.name command=%proc.cmdline file=%fd.name
container_id=%container.id container_image=%container.image.repository
k8s_ns=%k8s.ns.name k8s_pod=%k8s.pod.name)
priority: ERROR
tags: [container, filesystem, persistence, baseline]
- rule: Unexpected outbound connection from container
desc: A container opened a connection to a non-loopback address.
condition: evt.type=connect and container_activity and not fd.sip in (127.0.0.1, 0.0.0.0)
output: >-
Outbound connection from container
(user=%user.name command=%proc.cmdline connection=%fd.name
container_id=%container.id container_image=%container.image.repository
k8s_ns=%k8s.ns.name k8s_pod=%k8s.pod.name)
priority: NOTICE
tags: [container, network, baseline]
@@ -0,0 +1,11 @@
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Rulesfile
metadata:
name: custom-rules
namespace: falco
annotations:
argocd.argoproj.io/sync-wave: "2"
spec:
priority: 60
configMapRef:
name: falco-custom-rules
@@ -0,0 +1,12 @@
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Config
metadata:
name: falco-output
namespace: falco
annotations:
argocd.argoproj.io/sync-wave: "1"
spec:
priority: 50
config:
json_output: true
json_include_output_property: true
@@ -0,0 +1,9 @@
apiVersion: instance.falcosecurity.dev/v1alpha1
kind: Falco
metadata:
name: falco
namespace: falco
annotations:
# Apply the instance after the Operator chart has installed its CRDs.
argocd.argoproj.io/sync-wave: "1"
spec: {}
@@ -0,0 +1,17 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: falco
resources:
- namespace.yaml
- falco-instance.yaml
- falco-config.yaml
- container-plugin.yaml
- custom-rulesfile.yaml
configMapGenerator:
- name: falco-custom-rules
files:
- rules.yaml=custom-rules.yaml
generatorOptions:
disableNameSuffixHash: true
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: falco