mirror of
https://github.com/falcosecurity/falco.git
synced 2025-07-17 08:11:32 +00:00
Merge pull request #55 from draios/run-falco-in-docker
Run falco by default in containers.
This commit is contained in:
commit
d1fb172bff
@ -177,7 +177,7 @@ Falco can then be run with:
|
|||||||
|
|
||||||
```
|
```
|
||||||
docker pull sysdig/falco
|
docker pull sysdig/falco
|
||||||
docker run -i -t --name falco --privileged -v /var/run/docker.sock:/host/var/run/docker.sock -v /dev:/host/dev -v /proc:/host/proc:ro -v /boot:/host/boot:ro -v /lib/modules:/host/lib/modules:ro -v /usr:/host/usr:ro sysdig/falco falco
|
docker run -i -t --name falco --privileged -v /var/run/docker.sock:/host/var/run/docker.sock -v /dev:/host/dev -v /proc:/host/proc:ro -v /boot:/host/boot:ro -v /lib/modules:/host/lib/modules:ro -v /usr:/host/usr:ro sysdig/falco
|
||||||
```
|
```
|
||||||
|
|
||||||
##### Container install (CoreOS)
|
##### Container install (CoreOS)
|
||||||
@ -206,7 +206,7 @@ Falco is intended to be run as a service. But for experimentation and designing/
|
|||||||
|
|
||||||
#### Running Falco in a container
|
#### Running Falco in a container
|
||||||
|
|
||||||
`docker run -i -t --name falco --privileged -v /var/run/docker.sock:/host/var/run/docker.sock -v /dev:/host/dev -v /proc:/host/proc:ro -v /boot:/host/boot:ro -v /lib/modules:/host/lib/modules:ro -v /usr:/host/usr:ro sysdig/falco falco`
|
`docker run -i -t --name falco --privileged -v /var/run/docker.sock:/host/var/run/docker.sock -v /dev:/host/dev -v /proc:/host/proc:ro -v /boot:/host/boot:ro -v /lib/modules:/host/lib/modules:ro -v /usr:/host/usr:ro sysdig/falco`
|
||||||
|
|
||||||
#### Running Falco manually
|
#### Running Falco manually
|
||||||
|
|
||||||
|
@ -46,4 +46,4 @@ COPY ./docker-entrypoint.sh /
|
|||||||
|
|
||||||
ENTRYPOINT ["/docker-entrypoint.sh"]
|
ENTRYPOINT ["/docker-entrypoint.sh"]
|
||||||
|
|
||||||
CMD ["bash"]
|
CMD ["/usr/bin/falco"]
|
||||||
|
@ -46,4 +46,4 @@ COPY ./docker-entrypoint.sh /
|
|||||||
|
|
||||||
ENTRYPOINT ["/docker-entrypoint.sh"]
|
ENTRYPOINT ["/docker-entrypoint.sh"]
|
||||||
|
|
||||||
CMD ["bash"]
|
CMD ["/usr/bin/falco"]
|
||||||
|
@ -6,7 +6,7 @@ json_output: false
|
|||||||
|
|
||||||
# Send information logs to stderr and/or syslog Note these are *not* security
|
# Send information logs to stderr and/or syslog Note these are *not* security
|
||||||
# notification logs! These are just Falco lifecycle (and possibly error) logs.
|
# notification logs! These are just Falco lifecycle (and possibly error) logs.
|
||||||
log_stderr: false
|
log_stderr: true
|
||||||
log_syslog: true
|
log_syslog: true
|
||||||
|
|
||||||
|
|
||||||
@ -21,5 +21,5 @@ file_output:
|
|||||||
filename: ./events.txt
|
filename: ./events.txt
|
||||||
|
|
||||||
stdout_output:
|
stdout_output:
|
||||||
enabled: false
|
enabled: true
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user