Skip to content

Latest commit

 

History

History
41 lines (26 loc) · 938 Bytes

File metadata and controls

41 lines (26 loc) · 938 Bytes

Runtime Policies With Falco

TODO: Intro

Setup

# TODO: kapp-controller

chmod +x manuscript/runtime-policies/falco.sh

./manuscript/runtime-policies/falco.sh

Do

kubectl --namespace production exec -it cncf-demo-controller-0 \
    -- sh -c "ls /"

kubectl --namespace falco logs \
    --selector app.kubernetes.io/name=falco --container falco \
    | grep cncf-demo-controller-0 | jq .

export POD=$(kubectl --namespace falco get pods \
    --selector "app.kubernetes.io/name=falco" --no-headers \
    --output custom-columns=":metadata.name" | head -1)

kubectl --namespace falco exec -it $POD -- sh

cat /etc/falco/falco_rules.yaml

exit

Continue The Adventure