Skip to content

Deploying Policies

Deploying and Validating Custom Security Policies

Custom Falco rules are essential for addressing unique security requirements in Kubernetes environments, such as detecting application-specific anomalies or enforcing compliance with internal policies. This section guides you through deploying custom rules in production and validating their effectiveness through testing and monitoring.


Deploying Custom Falco Rules

1. Writing and Testing Rules Locally

Before deploying, test custom rules in a local environment to ensure they work as intended. Use the falco CLI to simulate events and validate rule behavior.

Example: Detecting suspicious container creation

# custom-rule.yaml
- rule: SuspiciousContainerCreation
  desc: Detect containers created with root privileges
  condition: container.create and container.user = "root"
  output: "Detected container created with root privileges: %container.name%"
  priority: medium
  tags: [k8s, container]

Testing the rule:

falco --rule custom-rule.yaml --test

2. Deploying to Kubernetes

Falco can be deployed via the Falco Operator or a standalone DaemonSet. For production, the Operator provides better lifecycle management.

Using the Falco Operator: 1. Apply the custom rule as a ConfigMap:

kubectl create configmap custom-rules --from-file=rules.yaml -n falco

  1. Update the FalcoConfig custom resource to include the rule:
    apiVersion: falco.org/v1beta2
    kind: FalcoConfig
    metadata:
      name: falco-config
      namespace: falco
    spec:
      rules:
        - name: SuspiciousContainerCreation
          content: |
            rule SuspiciousContainerCreation
              desc: Detect containers created with root privileges
              condition: container.create and container.user = "root"
              output: "Detected container created with root privileges: %container.name%"
              priority: medium
              tags: [k8s, container]
    

Using a DaemonSet: If using a standalone deployment, mount the rules file into the Falco container:

volumeMounts:
  - name: falco-rules
    mountPath: /etc/falco/rules.d
volumes:
  - name: falco-rules
    configMap:
      name: custom-rules

3. Post-Deployment Considerations

  • Resource limits: Ensure Falco pods have sufficient CPU/memory to avoid performance bottlenecks.
  • Rule versioning: Use Falco’s rule versioning to track changes and ensure compatibility with your Falco version.
  • Monitoring: Integrate Falco with Prometheus/Grafana or SIEM tools for centralized alerting.

Validating Effectiveness of Custom Rules

1. Simulation and Penetration Testing

Use tools like kubectl or kubetest to simulate attack vectors and verify rule detection.

Example: Testing root container creation

kubectl run attacker --image=busybox --restart=Never -it -- sh
# Inside the pod:
docker run --rm -it --user root busybox sh

Check Falco logs for alerts matching your custom rule.

2. Automated Testing with Falco’s Test Framework

Leverage Falco’s built-in testing tools to validate rules programmatically:

falco --test --rules custom-rule.yaml

3. Production Monitoring and Debugging

  • Falco logs: Use kubectl logs <falco-pod> to debug false positives/negatives.
  • Alert tuning: Adjust rule priorities and tags to refine alerting.
  • False positive reduction: Periodically review alerts and refine conditions (e.g., adding container.image filters).

Key takeaways

  • Test rules locally before deployment to avoid unintended behavior.
  • Deploy via Operator or DaemonSet based on your Kubernetes setup and operational needs.
  • Validate through simulation and monitoring to ensure rules align with real-world scenarios.
  • Iterate and refine rules based on feedback from production alerts and false positive analysis.