Overview
A DevSecOps platform deployment that automates the provisioning of an Amazon EKS cluster with a custom VPC and deploys Falco—the CNCF runtime security project—for real-time kernel-level behavioral threat detection.
Security events and policy anomalies are automatically aggregated by Falcosidekick and dispatched to notification channels (such as Telegram webhooks and the Falcosidekick Web UI).
- GitHub Repository: https://github.com/Roslaan001/eks-with-falco
Architectural Highlights
- Automated Cluster Topology: Provisions the underlying AWS VPC (public and private subnets across multiple AZs) and EKS managed node group using clean Terraform modules.
- Kernel Runtime Auditing: Integrates Falco daemonsets monitoring system calls (
sys_enter,sys_exit) via eBPF probes to catch unauthorized privilege escalation, unexpected terminal shells in pods, or outbound network tampering. - Event Aggregation & Alert Routing: Uses Falcosidekick Helm releases to route high/critical security alerts directly to team channels in real time with an optional web dashboard.