Closed mpurusottamc closed 1 year ago
Not sure why the downloader is trying to get it from a different path but you could try to download it manually, put it into a new docker layer which contains the ebpf probe file at the path /root/.falco/4.0.0+driver/x86_64/falco_amazonlinux2_5.10.173-154.642.amzn2.x86_64_1.o
and add that layer on top of the existing falco driver loader image.
The above is not recommended for prod usage; just troubleshooting purposes
@tspearconquest The downloader is trying to get the right version https://download.falco.org/driver/39ae7d40496793cf3d3e7890c9bbdc202263836b/falco_amazonlinux2_5.10.173-154.642.amzn2.x86_64_1.o
But, that does not exist.
the 4.0.0+driver
version was more of a manual search that i did in the probes listing page.
If a probe does not exist for a particular version, how should that be resolved in production?
The falco team would need to release it or you would need to compile it yourself. It appears that falco did try to compile it but encountered expr: syntax error: unexpected argument '1'
so I will have to defer to them to troubleshoot this error, as I'm not in AWS and couldn't help to make a release (I'm a user here too :) ).
@Andreagit97 any suggestions?
As I wrote in #2488 , we only support updates to prebuilt drivers for latest 3 driver versions. Therefore you need to update your Falco installation to latest one (ie: the one that uses driver 4.0.0) to be able to fetch the prebuilt driver.
Thanks for your help @FedeDP. We will update and test it.
Describe the bug I am trying to install falco helm chart on an Amazon Linux machine and getting the below error.
How to reproduce it
Create a new EKS cluster with below scripts.
metadata: name: eks-local-testing-cluster region: us-east-2
nodeGroups:
name: ng-1 instanceType: t3.large desiredCapacity: 1 volumeSize: 50
name: ng-2 instanceType: t3.large desiredCapacity: 1 volumeSize: 50
Expected behaviour Was expecting the falco service to start without errors.
Environment Falco version: 0.32.0 System info: Cloud provider or hardware configuration: AWS OS: AL2_x86_64 Kernel: falco_amazonlinux2_5.10.173-154.642.amzn2.x86_64 Installation method: helm Helm chart version: 1.19.1
Additional Information I can see the ebpf probe file here - (https://download.falco.org/driver/site/index.html?lib=4.0.0%2Bdriver&target=amazonlinux2&arch=x86_64&kind=ebpf&search=falco_amazonlinux2_5.10.173-154.642.amzn2.x86_64_1.o)
Any suggestions would be much appreciated. Thanks a lot.