
Hari 54: OPA Mati, Pod Nakal Lolos, Falco Masih Menangkap
Simulasi chaos: admission control (OPA) dimatikan, pod nakal lolos masuk. Tapi Falco tetap menangkap pod privileged. Ada script drift-check untuk menutup gap-nya.

Hari 52: K8s Escape, Falco Blind, Banjir 1000 Alert Palsu
Simulasi red team: keluar dari container Kubernetes, baca kredensial node. Falco diam total. Saat diperbaiki, malah banjir alert palsu. Ini ceritanya.

Hari 48: Intelligent Alert Routing — Falco CRITICAL Alerts ke Slack
Falco CRITICAL alerts otomatis terkirim ke Slack #security-alerts via Python webhook receiver. DNS fix: host.k3d.internal → host.docker.internal. End-to-end test sukses.

Hari 42: Webhook Alerting — Falco to Python Receiver
n8n Docker pull timed out → pivot ke Python webhook receiver. Falcosidekick webhook output enabled. End-to-end: attack → Falco → Falcosidekick → webhook → IF routing CRITICAL to Slack path. 3 alerts received.

Hari 41: Falco Attack Sim — 6 Alerts, Defense in Depth
Attack simulation: shell, sensitive file, network tool, K8s API. Distroless blocks shell exec. 3/4 custom Falco rules fired (6 alerts). NetworkPolicy blocks egress. All 5 defense layers proven working.

Hari 40: Falco Custom Rules — SecureBank Detection
4 custom Falco rules untuk SecureBank: shell detection, sensitive file read, network tool, K8s API access. Helm values.yaml untuk reproducible upgrades. 29 rules total, schema validation OK.
Page 1 of 2 • 7 articles