Detecting Kubernetes Security Threats with Falco

  Рет қаралды 5,804

DevOps Toolkit

DevOps Toolkit

Күн бұрын

Пікірлер: 19
@DevOpsToolkit
@DevOpsToolkit 11 ай бұрын
What do you think of Falco? Is detection enough?
@bombaclotta
@bombaclotta 11 ай бұрын
Have you tried Tetragon from the eBPF high-flyers Isovalent?
@DevOpsToolkit
@DevOpsToolkit 11 ай бұрын
@bombaclotta I did and I'm working in a video about it.
@kevinyu9934
@kevinyu9934 11 ай бұрын
The Falco video finally comes!
@IvanRizzante
@IvanRizzante 11 ай бұрын
Thanks for the video! I totally agree, Falco drives me crazy. I hate the number of warnings you get with Falco, having to fine tune the rules and all the ceremonies that come with it, even if there are no competitors at the moment. Plus I still haven't found a customer that uses it yet! But you can't prevent without observing things so I guess we need to stick with Falco for now
@vanrayan
@vanrayan 11 ай бұрын
Key thing is ensuring image immutability at runtime for any workloads, be it VM, K8s, Containers [Docker/Podman etc.] or Serverless. Look at Aqua security CWPP, it not only detects but also has the ability to block it.
@edb75001
@edb75001 11 ай бұрын
Very nice! I've been looking for something like this for my Homelab. Will definitely check this out...
@kevinyu9934
@kevinyu9934 11 ай бұрын
Next, would you like to share your insights on Tetragon?
@DevOpsToolkit
@DevOpsToolkit 11 ай бұрын
Sure. Adding it to my TODO list... :)
@farzadmf
@farzadmf 11 ай бұрын
Thank you for the video. Not sure if it's intentional or not, but the link for the gist is not a link :)
@DevOpsToolkit
@DevOpsToolkit 11 ай бұрын
My bad... It's fixed now.
@100faouri
@100faouri 11 ай бұрын
It would be interesting to talk about gVisor after this video
@DevOpsToolkit
@DevOpsToolkit 11 ай бұрын
Adding it to my to-do list... 🙂
@MahomCloud
@MahomCloud 11 ай бұрын
Are there tools that do prevention on top of falco ?
@DevOpsToolkit
@DevOpsToolkit 11 ай бұрын
Forget them. Use kubearmor for prevention.
@vrabbi
@vrabbi 11 ай бұрын
I am a much bigger fan of kubearmor and find falco WAY TOO COMPLEX!!!!!
@DevOpsToolkit
@DevOpsToolkit 11 ай бұрын
They are different though. Falco gives you information while KubeArmor prevents processes from running. You can think of this video as a preamble to KubeArmor which is in my TODO list.
@vrabbi
@vrabbi 11 ай бұрын
@@DevOpsToolkit kubearmor can also run in alert only mode which is nice to have 1 tool for both
@DevOpsToolkit
@DevOpsToolkit 11 ай бұрын
That's true, but I find that part not to be as good as Falco. KubeArmor is focused on per-Pod basis which is great for prevention, but not necessarily for detection.
The Adventure  Continues Towards Security (You Choose! Ch. 3, Ep. 0)
2:37
AI for Kubernetes with ChatGPT and k8sgpt
23:32
DevOps Toolkit
Рет қаралды 19 М.
ПРИКОЛЫ НАД БРАТОМ #shorts
00:23
Паша Осадчий
Рет қаралды 5 МЛН
He bought this so I can drive too🥹😭 #tiktok #elsarca
00:22
Elsa Arca
Рет қаралды 60 МЛН
Nastya and balloon challenge
00:23
Nastya
Рет қаралды 55 МЛН
OpenFunction: The Best Way to Run Serverless Functions on Kubernetes?
36:54
Webinar: Kubernetes Runtime Security with Falco and Sysdig
36:19
CNCF [Cloud Native Computing Foundation]
Рет қаралды 9 М.
What is OpenTelemetry?
12:55
Highlight
Рет қаралды 6 М.
How To Secure Everything Without Making Everyone Suffer
27:02
DevOps Toolkit
Рет қаралды 10 М.
Kubernetes Testing Techniques with KUTTL
24:40
DevOps Toolkit
Рет қаралды 8 М.
Kubernetes Hacking: From Weak Applications to Cluster Control
36:22
Docker Security Essentials | How To Secure Docker Containers
53:32
HackerSploit
Рет қаралды 73 М.
TCP/IP for Programmers
3:03:31
Eli the Computer Guy
Рет қаралды 89 М.
Kubernetes Deployment Order and Dependencies Demystified
21:03
DevOps Toolkit
Рет қаралды 7 М.
ПРИКОЛЫ НАД БРАТОМ #shorts
00:23
Паша Осадчий
Рет қаралды 5 МЛН