falcosecurity/falco-operator

Kubernetes Operator for Falco

Go

47

510 commits

updated Oct 6, 2026

See the code

README

Falco Operator

Falco Ecosystem Repository Incubating Last Release

licence

The Kubernetes-native way to deploy and manage Falco. The Falco Operator transforms Falco from a powerful security tool into a fully integrated Kubernetes security solution, making it more accessible and manageable for teams of all sizes.

Overview

The Falco Operator brings two components that work together:

  • Falco Operator: manages Falco instances, companion components, artifact metadata and the central OCI cache/server.
  • Artifact Operator: installs rules, plugins and configuration fragments as a regular sidecar container in each Falco pod.

Five user-managed Custom Resource Definitions provide a declarative API; a sixth records per-node artifact delivery:

CRDAPI GroupPurpose
Falcoinstance.falcosecurity.dev/v1alpha1Falco instance lifecycle
Componentinstance.falcosecurity.dev/v1alpha1Companion components (e.g., k8s-metacollector)
Rulesfileartifact.falcosecurity.dev/v1alpha1Detection rules (OCI, inline, ConfigMap)
Pluginartifact.falcosecurity.dev/v1alpha1Falco plugins from OCI registries
Configartifact.falcosecurity.dev/v1alpha1Configuration fragments (inline, ConfigMap)
ArtifactNodeartifact.falcosecurity.dev/v1alpha1Operator-managed per-node installation status

Architecture

Users install the Falco Operator Deployment. It resolves OCI artifacts and serves cached files to the Artifact Operator in each Falco pod. The sidecar also reads inline and ConfigMap sources, writes shared emptyDir volumes, and records installation state in ArtifactNode resources. Falco reads the installed files and reloads them on a best-effort basis.

For details, see the Architecture documentation.

Quick Start

Install the operator

Install with Helm (recommended):

helm repo add falcosecurity https://falcosecurity.github.io/charts
helm repo update
helm install falco-operator falcosecurity/falco-operator \
  --namespace falco-operator \
  --create-namespace
Alternative: install with YAML manifest
kubectl create namespace falco-operator

VERSION=latest
if [ "$VERSION" = "latest" ]; then
  kubectl apply --server-side -f https://github.com/falcosecurity/falco-operator/releases/latest/download/install.yaml
else
  kubectl apply --server-side -f https://github.com/falcosecurity/falco-operator/releases/download/${VERSION}/install.yaml
fi

For prerequisites, configuration, upgrade, and uninstall instructions for both methods, see the Installation guide.

Deploy Falco

cat <<EOF | kubectl apply -f -
apiVersion: instance.falcosecurity.dev/v1alpha1
kind: Falco
metadata:
  name: falco
spec: {}
EOF

Add detection rules

cat <<EOF | kubectl apply -f -
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Plugin
metadata:
  name: container
  labels:
    app.kubernetes.io/managed-by: falco-operator
spec:
  ociArtifact:
    image:
      repository: falcosecurity/plugins/plugin/container
      tag: latest
    registry:
      name: ghcr.io
---
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Rulesfile
metadata:
  name: falco-rules
spec:
  ociArtifact:
    image:
      repository: falcosecurity/rules/falco-rules
      tag: latest
    registry:
      name: ghcr.io
  priority: 50
EOF

Verify

kubectl get falco
kubectl get rulesfiles,plugins
kubectl logs -l app.kubernetes.io/name=falco -c falco --tail=10

For the complete walkthrough, see the Getting Started guide.

Documentation

DocumentDescription
InstallationPrerequisites, install (Helm or YAML manifest), upgrade, uninstall
Getting StartedStep-by-step deployment guide
ArchitectureComponents, interactions, design
CRD ReferenceFull reference for all Custom Resources
ConfigurationDefaults and customization
Version MatrixDefault Falco version per operator release
Migration GuideIndex of migration chapters
ContributingDevelopment, testing, PR guidelines

Key Features

  • Declarative management — Define Falco deployments, rules, plugins, and configuration as Kubernetes Custom Resources
  • Multiple deployment modes — DaemonSet for cluster-wide monitoring, Deployment for plugin-only workloads
  • Flexible artifact sources — OCI registries, inline YAML, and Kubernetes ConfigMaps
  • Priority-based ordering — Deterministic application of rules and configuration
  • Node targeting — Apply different artifacts to different nodes via label selectors
  • Reference protection — Finalizers prevent accidental deletion of referenced Secrets and ConfigMaps
  • Enhanced observability — Kubernetes events and status conditions across all controllers
  • Server-Side Apply — Conflict-free reconciliation with ownership tracking
  • Multi-instance support — Run multiple Falco instances in the same cluster
  • Full pod customization — Override any aspect of the Falco pod via podTemplateSpec

License

This project is licensed to you under the Apache 2.0 license.

falcosecurity/falco-operator

Kubernetes Operator for Falco

Go

47

510 commits

updated Oct 6, 2026

See the code

README

Falco Operator

Falco Ecosystem Repository Incubating Last Release

licence

The Kubernetes-native way to deploy and manage Falco. The Falco Operator transforms Falco from a powerful security tool into a fully integrated Kubernetes security solution, making it more accessible and manageable for teams of all sizes.

Overview

The Falco Operator brings two components that work together:

  • Falco Operator: manages Falco instances, companion components, artifact metadata and the central OCI cache/server.
  • Artifact Operator: installs rules, plugins and configuration fragments as a regular sidecar container in each Falco pod.

Five user-managed Custom Resource Definitions provide a declarative API; a sixth records per-node artifact delivery:

CRDAPI GroupPurpose
Falcoinstance.falcosecurity.dev/v1alpha1Falco instance lifecycle
Componentinstance.falcosecurity.dev/v1alpha1Companion components (e.g., k8s-metacollector)
Rulesfileartifact.falcosecurity.dev/v1alpha1Detection rules (OCI, inline, ConfigMap)
Pluginartifact.falcosecurity.dev/v1alpha1Falco plugins from OCI registries
Configartifact.falcosecurity.dev/v1alpha1Configuration fragments (inline, ConfigMap)
ArtifactNodeartifact.falcosecurity.dev/v1alpha1Operator-managed per-node installation status

Architecture

Users install the Falco Operator Deployment. It resolves OCI artifacts and serves cached files to the Artifact Operator in each Falco pod. The sidecar also reads inline and ConfigMap sources, writes shared emptyDir volumes, and records installation state in ArtifactNode resources. Falco reads the installed files and reloads them on a best-effort basis.

For details, see the Architecture documentation.

Quick Start

Install the operator

Install with Helm (recommended):

helm repo add falcosecurity https://falcosecurity.github.io/charts
helm repo update
helm install falco-operator falcosecurity/falco-operator \
  --namespace falco-operator \
  --create-namespace
Alternative: install with YAML manifest
kubectl create namespace falco-operator

VERSION=latest
if [ "$VERSION" = "latest" ]; then
  kubectl apply --server-side -f https://github.com/falcosecurity/falco-operator/releases/latest/download/install.yaml
else
  kubectl apply --server-side -f https://github.com/falcosecurity/falco-operator/releases/download/${VERSION}/install.yaml
fi

For prerequisites, configuration, upgrade, and uninstall instructions for both methods, see the Installation guide.

Deploy Falco

cat <<EOF | kubectl apply -f -
apiVersion: instance.falcosecurity.dev/v1alpha1
kind: Falco
metadata:
  name: falco
spec: {}
EOF

Add detection rules

cat <<EOF | kubectl apply -f -
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Plugin
metadata:
  name: container
  labels:
    app.kubernetes.io/managed-by: falco-operator
spec:
  ociArtifact:
    image:
      repository: falcosecurity/plugins/plugin/container
      tag: latest
    registry:
      name: ghcr.io
---
apiVersion: artifact.falcosecurity.dev/v1alpha1
kind: Rulesfile
metadata:
  name: falco-rules
spec:
  ociArtifact:
    image:
      repository: falcosecurity/rules/falco-rules
      tag: latest
    registry:
      name: ghcr.io
  priority: 50
EOF

Verify

kubectl get falco
kubectl get rulesfiles,plugins
kubectl logs -l app.kubernetes.io/name=falco -c falco --tail=10

For the complete walkthrough, see the Getting Started guide.

Documentation

DocumentDescription
InstallationPrerequisites, install (Helm or YAML manifest), upgrade, uninstall
Getting StartedStep-by-step deployment guide
ArchitectureComponents, interactions, design
CRD ReferenceFull reference for all Custom Resources
ConfigurationDefaults and customization
Version MatrixDefault Falco version per operator release
Migration GuideIndex of migration chapters
ContributingDevelopment, testing, PR guidelines

Key Features

  • Declarative management — Define Falco deployments, rules, plugins, and configuration as Kubernetes Custom Resources
  • Multiple deployment modes — DaemonSet for cluster-wide monitoring, Deployment for plugin-only workloads
  • Flexible artifact sources — OCI registries, inline YAML, and Kubernetes ConfigMaps
  • Priority-based ordering — Deterministic application of rules and configuration
  • Node targeting — Apply different artifacts to different nodes via label selectors
  • Reference protection — Finalizers prevent accidental deletion of referenced Secrets and ConfigMaps
  • Enhanced observability — Kubernetes events and status conditions across all controllers
  • Server-Side Apply — Conflict-free reconciliation with ownership tracking
  • Multi-instance support — Run multiple Falco instances in the same cluster
  • Full pod customization — Override any aspect of the Falco pod via podTemplateSpec

License

This project is licensed to you under the Apache 2.0 license.