Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

release announcement of Falco AKS audit plugin #1447

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

IgorEulalio
Copy link
Contributor

What type of PR is this?

Uncomment one (or more) /kind <> lines:

/kind bug

/kind cleanup

/kind design

/kind user-interface

/kind content

/kind event

Any specific area of the project related to this PR?

Uncomment one (or more) /area <> lines:

/area blog

/area documentation

/area community

What this PR does / why we need it:

Which issue(s) this PR fixes:

Fixes #

Special notes for your reviewer:

Signed-off-by: Igor Eulalio <igor.eulalio@sysdig.com>
@poiana
Copy link

poiana commented Feb 7, 2025

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: IgorEulalio
Once this PR has been reviewed and has the lgtm label, please assign vjjmiras for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@poiana poiana requested review from mstemm and vjjmiras February 7, 2025 01:30
@poiana poiana added the size/L label Feb 7, 2025
@IgorEulalio IgorEulalio changed the title WIP: release announcement of Falco AKS audit plugin release announcement of Falco AKS audit plugin Feb 13, 2025
Copy link
Member

@leogr leogr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey @IgorEulalio

Great blog! Overal, SGTM. I've just left a few minor suggestions. See below.

🙏


## Configuring Falco to use AKS audit logs plugin

In your falco.yaml file, you must add the plugin configuration and later enable the plugin
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should add instructions on how to install the plugin first.

This may be as simple as downloading the plugin into the destination folder or just using falcoctl to install the plugin.

Comment on lines +52 to +58
Before starting Falco, configure the following environment variables:
```yaml
export BLOB_STORAGE_CONTAINER_NAME=${blob_storage_container_name}
export BLOB_STORAGE_CONNECTION_STRING=${blob_storage_connection_string}
export EVENTHUB_NAMESPACE_CONNECTION_STRING=${event_hub_namespace_connection_string}
export EVENTHUB_NAME=${event_hub_name}
```
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We generally discourage users from using environment variables to configure the plugin. It would be preferable to pass these values via the YALM configuration above.

- /etc/falco/falco_rules.local.yaml
- /etc/falco/falco_aks_audit.yaml

priority: debug
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we really need this? Why? 🤔


```yaml
10:52:03.348668000: Debug K8s Audit Event Detected: verb=create, user=aksService, groups=(system:masters,system:authenticated), target=<NA>
```
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we append a Let's meet section (or something like that) at the bottom?

The goal is to invite users to join the community.

# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants