I started like this!
apiVersion: v2
name: falco
description: A Helm chart of falco for Kubernetes
dependencies:
- name: falco
version: 3.1.0
repository: https://falcosecurity.github.io/charts
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.0.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "3.1.0"
serviceAccount:
# -- Specifies whether a service account should be created.
create: true
# -- Annotations to add to the service account.
annotations: {}
# -- The name of the service account to use.
# If not set and create is true, a name is generated using the fullname template
name: ""
falco:
docker:
enabled: false
falco:
json_output: true
json_include_output_property: true
log_syslog: false
log_level: info
http_output:
enabled: false
url: http://falcosidekick.stakater-falco:2801/ #TODO: fix this!
scc:
create: false
falcosidekick:
enabled: true
webui:
enabled: true
config:
alertmanager:
hostport: http://alertmanager-main.openshift-monitoring.svc:9094 # TODO! Its hard coded
minimumpriority: debug
mutualtls: ""
checkcert: false # Will have to check if the cert issue is still there; for now use this!
And final scc looks like this