falcosecurity / falco

Cloud Native Runtime Security
https://falco.org
Apache License 2.0
7.23k stars 893 forks source link

Missing pre-built falco-driver kernel version 5.4.209-116.363 for EKS AMI #2184

Closed igoritos22 closed 1 year ago

igoritos22 commented 2 years ago

We run Falco across our environments using EKS. There is a need to upgrade ours EKS AMI to version v20220824 with the 5.4.209-116.363.amzn2 kernel version and the falco-driver is not present in the list of avaliable kernel falco-drivers.

We cannot update our environment until this driver was loaded. There is some prevision to the driver will be avaliable in list of falco's drivers?

alan-kea commented 2 years ago

Also waiting for this driver to become available

dwgillies-bluescape commented 2 years ago

We are also hoping for a pre-built driver in this version to become availablle :

* Looking for a falco module locally (kernel 5.4.209-116.363.amzn2.x86_64)

I have learned that the driver DOES EXIST if you are using the latest 2.0 version of Falco - it can download the driver from :

https://download.falco.org/?prefix=driver/2.0.0%2Bdriver/x86_64/

If you upgrade your version(s) of falco-exporter and falco to use the ":latest" label, it will start.

FedeDP commented 2 years ago

The driver is now there: https://download.falco.org/driver/2.0.0%2Bdriver/x86_64/falco_amazonlinux2_5.4.209-116.363.amzn2.x86_64_1.ko :rocket:

LucasMouraoFerreira commented 2 years ago

Arm64 pre-built driver (5.4.209-116.363.amzn2) still not available in https://download.falco.org/?prefix=driver/2.0.0%2Bdriver/aarch64/ Version 5.4.204-113.362.amzn2 is not available either 😥

FedeDP commented 2 years ago

Yep there was a bug in the Arm64 driverkit workflow that prevented Arm64 drivers from being built. It will be fixed asap!

renilthomas commented 1 year ago

Hi @FedeDP, there is a new kernel released: kernel-5.4.209-116.367.amzn2.x86_64 and we are waiting for the pre-built driver to be available. Thanks!

dwgillies-bluescape commented 1 year ago

@renilthomas This ticket is probably superseded by https://github.com/falcosecurity/falco/issues/2273. There is a new .368. version of the linux kernel that will be a necessary upgrade to patch some new nessus scan "high" vulnerability findings for fedramp clusters. You may want to recompile your kernel and then ask for .368. drivers to solve all your problems (at least until new vulnerabilities are found & patched ...)

FedeDP commented 1 year ago

Is this issue still alive? Or can we close this?

poiana commented 1 year ago

Issues go stale after 90d of inactivity.

Mark the issue as fresh with /remove-lifecycle stale.

Stale issues rot after an additional 30d of inactivity and eventually close.

If this issue is safe to close now please do so with /close.

Provide feedback via https://github.com/falcosecurity/community.

/lifecycle stale

poiana commented 1 year ago

Stale issues rot after 30d of inactivity.

Mark the issue as fresh with /remove-lifecycle rotten.

Rotten issues close after an additional 30d of inactivity.

If this issue is safe to close now please do so with /close.

Provide feedback via https://github.com/falcosecurity/community.

/lifecycle rotten

poiana commented 1 year ago

Rotten issues close after 30d of inactivity.

Reopen the issue with /reopen.

Mark the issue as fresh with /remove-lifecycle rotten.

Provide feedback via https://github.com/falcosecurity/community. /close

poiana commented 1 year ago

@poiana: Closing this issue.

In response to [this](https://github.com/falcosecurity/falco/issues/2184#issuecomment-1546484681): >Rotten issues close after 30d of inactivity. > >Reopen the issue with `/reopen`. > >Mark the issue as fresh with `/remove-lifecycle rotten`. > >Provide feedback via https://github.com/falcosecurity/community. >/close Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes/test-infra](https://github.com/kubernetes/test-infra/issues/new?title=Prow%20issue:) repository.