Open cme-incom opened 1 month ago
This is another issue created about this "bug", wasn't able to reproduce til now https://github.com/falcosecurity/charts/issues/746
Which version of Falcosidekick are you running? The 2.29.0 or the latest (== master) ?
Describe the bug
After executing Aqua Security’s kube-bench, the Sidekick service fails and crashes. This issue occurs when the same Falco rule is triggered more than 15 times within a very short time window. Instead of handling the load gracefully, the service crashes.
How to reproduce it
Run Aqua Security’s kube-bench to perform security checks. Ensure that a specific Falco rule is triggered more than 15 times in a very short window.
Expected behaviour
The Sidekick service should handle multiple rule triggers without crashing. It should remain stable and not be terminated
Screenshots No screenshots available.
Environment
Falco version: Falco version: 0.38.2
OS:
Talos 1.6.5
Kernel:
6.6.32-talos
Installation method:
Helm Additional context
The rule triggered:
The error msg from the failed pod: