mirror of
https://github.com/falcosecurity/falco.git
synced 2025-09-03 15:46:33 +00:00
Merge pull request #55 from draios/run-falco-in-docker
Run falco by default in containers.
This commit is contained in:
@@ -177,7 +177,7 @@ Falco can then be run with:
|
|||||||
|
|
||||||
```
|
```
|
||||||
docker pull sysdig/falco
|
docker pull sysdig/falco
|
||||||
docker run -i -t --name falco --privileged -v /var/run/docker.sock:/host/var/run/docker.sock -v /dev:/host/dev -v /proc:/host/proc:ro -v /boot:/host/boot:ro -v /lib/modules:/host/lib/modules:ro -v /usr:/host/usr:ro sysdig/falco falco
|
docker run -i -t --name falco --privileged -v /var/run/docker.sock:/host/var/run/docker.sock -v /dev:/host/dev -v /proc:/host/proc:ro -v /boot:/host/boot:ro -v /lib/modules:/host/lib/modules:ro -v /usr:/host/usr:ro sysdig/falco
|
||||||
```
|
```
|
||||||
|
|
||||||
##### Container install (CoreOS)
|
##### Container install (CoreOS)
|
||||||
@@ -206,7 +206,7 @@ Falco is intended to be run as a service. But for experimentation and designing/
|
|||||||
|
|
||||||
#### Running Falco in a container
|
#### Running Falco in a container
|
||||||
|
|
||||||
`docker run -i -t --name falco --privileged -v /var/run/docker.sock:/host/var/run/docker.sock -v /dev:/host/dev -v /proc:/host/proc:ro -v /boot:/host/boot:ro -v /lib/modules:/host/lib/modules:ro -v /usr:/host/usr:ro sysdig/falco falco`
|
`docker run -i -t --name falco --privileged -v /var/run/docker.sock:/host/var/run/docker.sock -v /dev:/host/dev -v /proc:/host/proc:ro -v /boot:/host/boot:ro -v /lib/modules:/host/lib/modules:ro -v /usr:/host/usr:ro sysdig/falco`
|
||||||
|
|
||||||
#### Running Falco manually
|
#### Running Falco manually
|
||||||
|
|
||||||
|
@@ -46,4 +46,4 @@ COPY ./docker-entrypoint.sh /
|
|||||||
|
|
||||||
ENTRYPOINT ["/docker-entrypoint.sh"]
|
ENTRYPOINT ["/docker-entrypoint.sh"]
|
||||||
|
|
||||||
CMD ["bash"]
|
CMD ["/usr/bin/falco"]
|
||||||
|
@@ -46,4 +46,4 @@ COPY ./docker-entrypoint.sh /
|
|||||||
|
|
||||||
ENTRYPOINT ["/docker-entrypoint.sh"]
|
ENTRYPOINT ["/docker-entrypoint.sh"]
|
||||||
|
|
||||||
CMD ["bash"]
|
CMD ["/usr/bin/falco"]
|
||||||
|
@@ -6,7 +6,7 @@ json_output: false
|
|||||||
|
|
||||||
# Send information logs to stderr and/or syslog Note these are *not* security
|
# Send information logs to stderr and/or syslog Note these are *not* security
|
||||||
# notification logs! These are just Falco lifecycle (and possibly error) logs.
|
# notification logs! These are just Falco lifecycle (and possibly error) logs.
|
||||||
log_stderr: false
|
log_stderr: true
|
||||||
log_syslog: true
|
log_syslog: true
|
||||||
|
|
||||||
|
|
||||||
@@ -21,5 +21,5 @@ file_output:
|
|||||||
filename: ./events.txt
|
filename: ./events.txt
|
||||||
|
|
||||||
stdout_output:
|
stdout_output:
|
||||||
enabled: false
|
enabled: true
|
||||||
|
|
||||||
|
Reference in New Issue
Block a user