
Hari 42: Webhook Alerting — Falco to Python Receiver
n8n Docker pull timed out → pivot ke Python webhook receiver. Falcosidekick webhook output enabled. End-to-end: attack → Falco → Falcosidekick → webhook → IF routing CRITICAL to Slack path. 3 alerts received.

Hari 41: Falco Attack Sim — 6 Alerts, Defense in Depth
Attack simulation: shell, sensitive file, network tool, K8s API. Distroless blocks shell exec. 3/4 custom Falco rules fired (6 alerts). NetworkPolicy blocks egress. All 5 defense layers proven working.

Hari 40: Falco Custom Rules — SecureBank Detection
4 custom Falco rules untuk SecureBank: shell detection, sensitive file read, network tool, K8s API access. Helm values.yaml untuk reproducible upgrades. 29 rules total, schema validation OK.

Hari 39: Falco Setup — Runtime Security Monitoring
Install Falco 0.44.1 via Helm dengan modern eBPF driver. 8 pods Running, 25 default rules, alerts firing. Falcosidekick + Web UI untuk alert forwarding. Runtime detection layer.

Hari 38: RBAC Auditing — Dedicated SA Least Privilege
Audit RBAC dengan krew (who-can, access-matrix). Buat dedicated ServiceAccount dengan least privilege Role: get configmap only. Kubesec score 11 ke 12, Checkov 101/0.

Hari 37: Network Policies — Default Deny + Whitelist
3 NetworkPolicy: default deny all ingress+egress, whitelist API dari kube-system, DNS egress. k3s flannel enforce! Cross-namespace access blocked, Checkov CKV2_K8S_6 PASS.
Page 2 of 10 • 59 articles