The Kubernetes-native way to deploy and manage Falco. The Falco Operator transforms Falco from a powerful security tool into a fully integrated Kubernetes security solution, making it more accessible and manageable for teams of all sizes.
The Falco Operator brings two components that work together:
Five user-managed Custom Resource Definitions provide a declarative API; a sixth records per-node artifact delivery:
| CRD | API Group | Purpose |
|---|---|---|
Falco | instance.falcosecurity.dev/v1alpha1 | Falco instance lifecycle |
Component | instance.falcosecurity.dev/v1alpha1 | Companion components (e.g., k8s-metacollector) |
Rulesfile | artifact.falcosecurity.dev/v1alpha1 | Detection rules (OCI, inline, ConfigMap) |
Plugin | artifact.falcosecurity.dev/v1alpha1 | Falco plugins from OCI registries |
Config | artifact.falcosecurity.dev/v1alpha1 | Configuration fragments (inline, ConfigMap) |
ArtifactNode | artifact.falcosecurity.dev/v1alpha1 | Operator-managed per-node installation status |
Users install the Falco Operator Deployment. It resolves OCI artifacts and serves cached files to the Artifact Operator in each Falco pod. The sidecar also reads inline and ConfigMap sources, writes shared emptyDir volumes, and records installation state in ArtifactNode resources. Falco reads the installed files and reloads them on a best-effort basis.
For details, see the Architecture documentation.
Install with Helm (recommended):
helm repo add falcosecurity https://falcosecurity.github.io/charts
helm repo update
helm install falco-operator falcosecurity/falco-operator \
--namespace falco-operator \
--create-namespace
kubectl create namespace falco-operator
VERSION=latest
if [ "$VERSION" = "latest" ]; then
kubectl apply --server-side -f https://github.com/falcosecurity/falco-operator/releases/latest/download/install.yaml
else
kubectl apply --server-side -f https://github.com/falcosecurity/falco-operator/releases/download/${VERSION}/install.yaml
fi
For prerequisites, configuration, upgrade, and uninstall instructions for both methods, see the Installation guide.
cat <<EOF | kubectl apply -f -
apiVersion: instance.falcosecurity.dev/v1alpha1
kind: Falco
metadata:
name: falco
spec: {}
EOF
cat <<EOF | kubectl apply -f -
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Plugin
metadata:
name: container
labels:
app.kubernetes.io/managed-by: falco-operator
spec:
ociArtifact:
image:
repository: falcosecurity/plugins/plugin/container
tag: latest
registry:
name: ghcr.io
---
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Rulesfile
metadata:
name: falco-rules
spec:
ociArtifact:
image:
repository: falcosecurity/rules/falco-rules
tag: latest
registry:
name: ghcr.io
priority: 50
EOF
kubectl get falco
kubectl get rulesfiles,plugins
kubectl logs -l app.kubernetes.io/name=falco -c falco --tail=10
For the complete walkthrough, see the Getting Started guide.
| Document | Description |
|---|---|
| Installation | Prerequisites, install (Helm or YAML manifest), upgrade, uninstall |
| Getting Started | Step-by-step deployment guide |
| Architecture | Components, interactions, design |
| CRD Reference | Full reference for all Custom Resources |
| Configuration | Defaults and customization |
| Version Matrix | Default Falco version per operator release |
| Migration Guide | Index of migration chapters |
| Contributing | Development, testing, PR guidelines |
podTemplateSpecThis project is licensed to you under the Apache 2.0 license.
The Kubernetes-native way to deploy and manage Falco. The Falco Operator transforms Falco from a powerful security tool into a fully integrated Kubernetes security solution, making it more accessible and manageable for teams of all sizes.
The Falco Operator brings two components that work together:
Five user-managed Custom Resource Definitions provide a declarative API; a sixth records per-node artifact delivery:
| CRD | API Group | Purpose |
|---|---|---|
Falco | instance.falcosecurity.dev/v1alpha1 | Falco instance lifecycle |
Component | instance.falcosecurity.dev/v1alpha1 | Companion components (e.g., k8s-metacollector) |
Rulesfile | artifact.falcosecurity.dev/v1alpha1 | Detection rules (OCI, inline, ConfigMap) |
Plugin | artifact.falcosecurity.dev/v1alpha1 | Falco plugins from OCI registries |
Config | artifact.falcosecurity.dev/v1alpha1 | Configuration fragments (inline, ConfigMap) |
ArtifactNode | artifact.falcosecurity.dev/v1alpha1 | Operator-managed per-node installation status |
Users install the Falco Operator Deployment. It resolves OCI artifacts and serves cached files to the Artifact Operator in each Falco pod. The sidecar also reads inline and ConfigMap sources, writes shared emptyDir volumes, and records installation state in ArtifactNode resources. Falco reads the installed files and reloads them on a best-effort basis.
For details, see the Architecture documentation.
Install with Helm (recommended):
helm repo add falcosecurity https://falcosecurity.github.io/charts
helm repo update
helm install falco-operator falcosecurity/falco-operator \
--namespace falco-operator \
--create-namespace
kubectl create namespace falco-operator
VERSION=latest
if [ "$VERSION" = "latest" ]; then
kubectl apply --server-side -f https://github.com/falcosecurity/falco-operator/releases/latest/download/install.yaml
else
kubectl apply --server-side -f https://github.com/falcosecurity/falco-operator/releases/download/${VERSION}/install.yaml
fi
For prerequisites, configuration, upgrade, and uninstall instructions for both methods, see the Installation guide.
cat <<EOF | kubectl apply -f -
apiVersion: instance.falcosecurity.dev/v1alpha1
kind: Falco
metadata:
name: falco
spec: {}
EOF
cat <<EOF | kubectl apply -f -
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Plugin
metadata:
name: container
labels:
app.kubernetes.io/managed-by: falco-operator
spec:
ociArtifact:
image:
repository: falcosecurity/plugins/plugin/container
tag: latest
registry:
name: ghcr.io
---
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Rulesfile
metadata:
name: falco-rules
spec:
ociArtifact:
image:
repository: falcosecurity/rules/falco-rules
tag: latest
registry:
name: ghcr.io
priority: 50
EOF
kubectl get falco
kubectl get rulesfiles,plugins
kubectl logs -l app.kubernetes.io/name=falco -c falco --tail=10
For the complete walkthrough, see the Getting Started guide.
| Document | Description |
|---|---|
| Installation | Prerequisites, install (Helm or YAML manifest), upgrade, uninstall |
| Getting Started | Step-by-step deployment guide |
| Architecture | Components, interactions, design |
| CRD Reference | Full reference for all Custom Resources |
| Configuration | Defaults and customization |
| Version Matrix | Default Falco version per operator release |
| Migration Guide | Index of migration chapters |
| Contributing | Development, testing, PR guidelines |
podTemplateSpecThis project is licensed to you under the Apache 2.0 license.