mirror of
https://github.com/falcosecurity/falco.git
synced 2025-08-01 06:29:47 +00:00
Let cilium-cni change namespaces
Sample Falco alert: ``` Namespace change (setns) by unexpected program (user=root command=cilium-cni parent=cilium-cni host CID2 CID1 image=<NA>) ``` Signed-off-by: Mark Stemm <mark.stemm@gmail.com>
This commit is contained in:
parent
01c9d8ba31
commit
48a0f512fb
@ -1546,7 +1546,7 @@
|
||||
condition: >
|
||||
evt.type = setns
|
||||
and not proc.name in (docker_binaries, k8s_binaries, lxd_binaries, sysdigcloud_binaries,
|
||||
sysdig, nsenter, calico, oci-umount, network_plugin_binaries)
|
||||
sysdig, nsenter, calico, oci-umount, cilium-cni, network_plugin_binaries)
|
||||
and not proc.name in (user_known_change_thread_namespace_binaries)
|
||||
and not proc.name startswith "runc"
|
||||
and not proc.cmdline startswith "containerd"
|
||||
|
Loading…
Reference in New Issue
Block a user