Skip to content

About

Kubernetes Operator for Falco

Resources

Code of conduct

Contributing

Security policy

Stars

47 stars

Watchers

4 watching

Forks

Falco Operator

Falco Ecosystem Repository Incubating Last Release

licence

The Kubernetes-native way to deploy and manage Falco. The Falco Operator transforms Falco from a powerful security tool into a fully integrated Kubernetes security solution, making it more accessible and manageable for teams of all sizes.

Overview

The Falco Operator brings two components that work together:

  • Falco Operator: manages Falco instances, companion components, artifact metadata and the central OCI cache/server.
  • Artifact Operator: installs rules, plugins and configuration fragments as a regular sidecar container in each Falco pod.

Five user-managed Custom Resource Definitions provide a declarative API; a sixth records per-node artifact delivery:

CRD API Group Purpose
Falco instance.falcosecurity.dev/v1alpha1 Falco instance lifecycle
Component instance.falcosecurity.dev/v1alpha1 Companion components (e.g., k8s-metacollector)
Rulesfile artifact.falcosecurity.dev/v1alpha1 Detection rules (OCI, inline, ConfigMap)
Plugin artifact.falcosecurity.dev/v1alpha1 Falco plugins from OCI registries
Config artifact.falcosecurity.dev/v1alpha1 Configuration fragments (inline, ConfigMap)
ArtifactNode artifact.falcosecurity.dev/v1alpha1 Operator-managed per-node installation status

Architecture

Users install the Falco Operator Deployment. It resolves OCI artifacts and serves cached files to the Artifact Operator in each Falco pod. The sidecar also reads inline and ConfigMap sources, writes shared emptyDir volumes, and records installation state in ArtifactNode resources. Falco reads the installed files and reloads them on a best-effort basis.

For details, see the Architecture documentation.

Quick Start

Install the operator

Install with Helm (recommended):

helm repo add falcosecurity https://falcosecurity.github.io/charts
helm repo update
helm install falco-operator falcosecurity/falco-operator \
  --namespace falco-operator \
  --create-namespace
Alternative: install with YAML manifest
kubectl create namespace falco-operator

VERSION=latest
if [ "$VERSION" = "latest" ]; then
  kubectl apply --server-side -f https://github.com/falcosecurity/falco-operator/releases/latest/download/install.yaml
else
  kubectl apply --server-side -f https://github.com/falcosecurity/falco-operator/releases/download/${VERSION}/install.yaml
fi

For prerequisites, configuration, upgrade, and uninstall instructions for both methods, see the Installation guide.

Deploy Falco

cat <<EOF | kubectl apply -f -
apiVersion: instance.falcosecurity.dev/v1alpha1
kind: Falco
metadata:
  name: falco
spec: {}
EOF

Add detection rules

cat <<EOF | kubectl apply -f -
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Plugin
metadata:
  name: container
  labels:
    app.kubernetes.io/managed-by: falco-operator
spec:
  ociArtifact:
    image:
      repository: falcosecurity/plugins/plugin/container
      tag: latest
    registry:
      name: ghcr.io
---
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Rulesfile
metadata:
  name: falco-rules
spec:
  ociArtifact:
    image:
      repository: falcosecurity/rules/falco-rules
      tag: latest
    registry:
      name: ghcr.io
  priority: 50
EOF

Verify

kubectl get falco
kubectl get rulesfiles,plugins
kubectl logs -l app.kubernetes.io/name=falco -c falco --tail=10

For the complete walkthrough, see the Getting Started guide.

Documentation

Document Description
Installation Prerequisites, install (Helm or YAML manifest), upgrade, uninstall
Getting Started Step-by-step deployment guide
Architecture Components, interactions, design
CRD Reference Full reference for all Custom Resources
Configuration Defaults and customization
Version Matrix Default Falco version per operator release
Migration Guide Index of migration chapters
Contributing Development, testing, PR guidelines

Key Features

  • Declarative management — Define Falco deployments, rules, plugins, and configuration as Kubernetes Custom Resources
  • Multiple deployment modes — DaemonSet for cluster-wide monitoring, Deployment for plugin-only workloads
  • Flexible artifact sources — OCI registries, inline YAML, and Kubernetes ConfigMaps
  • Priority-based ordering — Deterministic application of rules and configuration
  • Node targeting — Apply different artifacts to different nodes via label selectors
  • Reference protection — Finalizers prevent accidental deletion of referenced Secrets and ConfigMaps
  • Enhanced observability — Kubernetes events and status conditions across all controllers
  • Server-Side Apply — Conflict-free reconciliation with ownership tracking
  • Multi-instance support — Run multiple Falco instances in the same cluster
  • Full pod customization — Override any aspect of the Falco pod via podTemplateSpec

License

This project is licensed to you under the Apache 2.0 license.

About

Kubernetes Operator for Falco

Resources

Code of conduct

Contributing

Security policy

Stars

47 stars

Watchers

4 watching

Forks

Releases

Packages

Used by

Contributors

Languages