Falco Logs Suspicious Events on Your K8s and Servers

Falco Logs Suspicious Events on Your K8s and Servers

Author: Bret Fisher June 2, 2023 Duration: 1:08:31

Bret and his co-host, Matt, are joined by Jason Dellaluce and Luca Guerra from Sysdig to talk about Falco, a tool I recommend for production clusters and knowing about any bad behavior on your servers.

🙌 The Agentic DevOps Guild has launched! It's a training + community + mentorship program for engineers wanting to learn the latest CI/CD automation and dive into Agentic DevOps. Meetups are happening now, with new course videos dropping every few weeks. Join the Guild and become your team's leader in AI for infrastructure automation https://www.bretfisher.com/theguild 🍾

Falco is a security tool I've mentioned multiple times on this show, because I mostly think that a low level security focused logging product is something that every production server needs. The ability to log unexpected events and behaviors on your Linux host is powerful and necessary to be able to audit what's really happening on your infrastructure outside of your app itself.

Falco has been a CNCF incubating project for over four years, and I was immediately drawn to it in its early days, because it was container and Kubernetes aware and it could log and alert with default rules for everything, from someone starting a shell inside a container, to a bash history file being deleted, to a container trying to talk to the Kubernetes API.

This episode will be useful for those of you new to tools like Falco and for those familiar with its basics, but also wanting to learn about newer features and use cases, which I did some learning on myself in this episode.


Live recording of the complete show from April 6, 2023 is on YouTube (Ep. #210).

★Topics★
Falco website
Falco on CNCF


You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news!

Grab the best coupons for my Docker and Kubernetes courses.
Join my cloud native DevOps community on Discord.
Grab some merch at Bret's Loot Box
Homepage bretfisher.com


Creators & Guests
  • (00:00) - Intro
  • (04:41) - Introducing the guests
  • (07:42) - What is Falco? Why do we need it?
  • (10:17) - What can Falco monitor?
  • (19:28) - How are events logged?
  • (33:16) - Does Falco classify alerts by severity?

Bret Fisher hosts DevOps and Docker Talk: Cloud Native Interviews and Tooling alongside Nirmal Mehta, pulling conversations directly from their live audience sessions. This isn't a theoretical lecture series; it's grounded in the practical, often messy realities of building and running modern systems. Each episode digs into the specific tools and philosophies shaping infrastructure today, from the foundational elements like Docker and container orchestration with Kubernetes or Swarm to the broader cultural shifts of DevOps, SRE, and platform engineering. You'll hear discussions that span the entire software lifecycle, touching on the integration of security with DevSecOps, the automation promises of GitOps, and what "Cloud Native" truly means for development teams. The dialogue stays focused on actionable insights and real-world use cases, offering a genuine sense of what works and what doesn't in the field. For anyone navigating the container and cloud ecosystem, this podcast serves as a regular, insightful check-in with practitioners and experts, hosted by someone deeply embedded in the community. The natural, interview-driven format makes complex topics accessible, ensuring listeners come away with more than just buzzwords-they get context and clarity.
Author: Language: English Episodes: 100

DevOps and Docker Talk: Cloud Native Interviews and Tooling
Podcast Episodes
Managing Enterprise Kubernetes with Replicated [not-audio_url] [/not-audio_url]

Duration: 1:00:17
Bret is joined by Marc Campbell of Replicated to discuss the challenges of deploying their software on other people's Kubernetes.
Kubernetes Autoscaling with Karpenter [not-audio_url] [/not-audio_url]

Duration: 54:57
Bret is joined by Nirmal Mehta, a Principal Specialist Solution Architect at AWS, and a Docker Captain, to discuss Karpenter, an autoscaling solution that simplifies Kubernetes infrastructure by automating node scaling u…
Beyond DevOps DORA Metrics [not-audio_url] [/not-audio_url]

Duration: 1:12:11
Bret is joined by Laura Tacho, an engineering leadership coach, to discuss measuring your team's performance with DevOps metrics (DORA) and the new SPACE framework.
Argo CD Past & Future, with the Creators [not-audio_url] [/not-audio_url]

Duration: 1:12:30
Bret is joined by the co-creators of the Argo project and co-founders of Akuity - Hong Wang and Jesse Suen, to discuss the state of Argo and their new Akuity offering for Argo CD in the Cloud.
Infrastructure as Code, Patterns and Practices [not-audio_url] [/not-audio_url]

Duration: 50:15
Bret is joined by Rosemary Wang, a developer advocate at HashiCorp, to discuss her book: Infrastructure as Code, Patterns and Practices.
Applications-as-Code with Shipa [not-audio_url] [/not-audio_url]

Duration: 59:57
Bret is joined by Ravi Lachhman, Field CTO at Shipa, to discuss the basics of Shipa application and policy management.
Nomad Orchestration [not-audio_url] [/not-audio_url]

Duration: 54:10
Bret is joined by Erik Veld, Manager, Developer Advocacy at HashiCorp, the creators of Nomad.
GitOps with Pulumi [not-audio_url] [/not-audio_url]

Duration: 45:11
Bret is joined by David Flanagan, aka Rawkode Academy, from Pulumi to show off how Pulumi infrastructure-as-code can improve GitOps pipelines.