The Kubernetes-native way to deploy and manage Falco. The Falco Operator transforms Falco from a powerful security tool into a fully integrated Kubernetes security solution, making it more accessible and manageable for teams of all sizes.
The Falco Operator brings two components that work together:
- Falco Operator: manages Falco instances, companion components, artifact metadata and the central OCI cache/server.
- Artifact Operator: installs rules, plugins and configuration fragments as a regular sidecar container in each Falco pod.
Five user-managed Custom Resource Definitions provide a declarative API; a sixth records per-node artifact delivery:
| CRD | API Group | Purpose |
|---|---|---|
Falco |
instance.falcosecurity.dev/v1alpha1 |
Falco instance lifecycle |
Component |
instance.falcosecurity.dev/v1alpha1 |
Companion components (e.g., k8s-metacollector) |
Rulesfile |
artifact.falcosecurity.dev/v1alpha1 |
Detection rules (OCI, inline, ConfigMap) |
Plugin |
artifact.falcosecurity.dev/v1alpha1 |
Falco plugins from OCI registries |
Config |
artifact.falcosecurity.dev/v1alpha1 |
Configuration fragments (inline, ConfigMap) |
ArtifactNode |
artifact.falcosecurity.dev/v1alpha1 |
Operator-managed per-node installation status |
Users install the Falco Operator Deployment. It resolves OCI artifacts and serves cached files to the Artifact Operator in each Falco pod. The sidecar also reads inline and ConfigMap sources, writes shared emptyDir volumes, and records installation state in ArtifactNode resources. Falco reads the installed files and reloads them on a best-effort basis.
For details, see the Architecture documentation.
Install with Helm (recommended):
helm repo add falcosecurity https://falcosecurity.github.io/charts
helm repo update
helm install falco-operator falcosecurity/falco-operator \
--namespace falco-operator \
--create-namespaceAlternative: install with YAML manifest
kubectl create namespace falco-operator
VERSION=latest
if [ "$VERSION" = "latest" ]; then
kubectl apply --server-side -f https://github.com/falcosecurity/falco-operator/releases/latest/download/install.yaml
else
kubectl apply --server-side -f https://github.com/falcosecurity/falco-operator/releases/download/${VERSION}/install.yaml
fiFor prerequisites, configuration, upgrade, and uninstall instructions for both methods, see the Installation guide.
cat <<EOF | kubectl apply -f -
apiVersion: instance.falcosecurity.dev/v1alpha1
kind: Falco
metadata:
name: falco
spec: {}
EOFcat <<EOF | kubectl apply -f -
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Plugin
metadata:
name: container
labels:
app.kubernetes.io/managed-by: falco-operator
spec:
ociArtifact:
image:
repository: falcosecurity/plugins/plugin/container
tag: latest
registry:
name: ghcr.io
---
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Rulesfile
metadata:
name: falco-rules
spec:
ociArtifact:
image:
repository: falcosecurity/rules/falco-rules
tag: latest
registry:
name: ghcr.io
priority: 50
EOFkubectl get falco
kubectl get rulesfiles,plugins
kubectl logs -l app.kubernetes.io/name=falco -c falco --tail=10For the complete walkthrough, see the Getting Started guide.
| Document | Description |
|---|---|
| Installation | Prerequisites, install (Helm or YAML manifest), upgrade, uninstall |
| Getting Started | Step-by-step deployment guide |
| Architecture | Components, interactions, design |
| CRD Reference | Full reference for all Custom Resources |
| Configuration | Defaults and customization |
| Version Matrix | Default Falco version per operator release |
| Migration Guide | Index of migration chapters |
| Contributing | Development, testing, PR guidelines |
- Declarative management — Define Falco deployments, rules, plugins, and configuration as Kubernetes Custom Resources
- Multiple deployment modes — DaemonSet for cluster-wide monitoring, Deployment for plugin-only workloads
- Flexible artifact sources — OCI registries, inline YAML, and Kubernetes ConfigMaps
- Priority-based ordering — Deterministic application of rules and configuration
- Node targeting — Apply different artifacts to different nodes via label selectors
- Reference protection — Finalizers prevent accidental deletion of referenced Secrets and ConfigMaps
- Enhanced observability — Kubernetes events and status conditions across all controllers
- Server-Side Apply — Conflict-free reconciliation with ownership tracking
- Multi-instance support — Run multiple Falco instances in the same cluster
- Full pod customization — Override any aspect of the Falco pod via
podTemplateSpec
This project is licensed to you under the Apache 2.0 license.