保障应用与集群安全及Kubernetes日志管理
1. 使用Falco检测异常
1.1 列出Falco Pod
使用以下命令列出Falco Pod:
$ kubectl get pods | grep falco-daemonset
示例输出:
falco-daemonset-5785b 1/1 Running 0 9m52s
falco-daemonset-brjs7 1/1 Running 0 9m52s
falco-daemonset-mqcjq 1/1 Running 0 9m52s
falco-daemonset-pdx45 1/1 Running 0 9m52s
1.2 查看Falco Pod日志
$ kubectl exec -it falco-daemonset-94p8w bash
$ kubectl logs falco-daemonset-94p8w
日志示例:
05:41:59.9275580001: Error Unauthorized process (cat /var/www/html/ping.php) running in (5f1b6d304f99) k8s.ns=falcotest k8s.pod=ping-74db