Falco is now available as an Amazon EKS add-on
Blog post from Sysdig
Falco, a CNCF graduated runtime security project, is now available as an AWS-validated Amazon EKS add-on, simplifying runtime security deployment for Amazon Elastic Kubernetes Service (EKS) users. This integration allows for single-command installation, automatic updates, and seamless AWS service integration, enhancing cloud-native security by monitoring system calls at the kernel level to detect threats in real-time. The add-on ensures consistent deployment across multiple EKS clusters, avoiding configuration drift, while also providing automated lifecycle management. Users can customize Falco rules using ConfigMaps to tailor security policies according to their workload patterns, and security events can be integrated with Amazon CloudWatch for monitoring. The project invites community participation through its open-source nature, allowing contributions to rule sets and community interaction via Slack and GitHub.