No description
  • Python 66.2%
  • HTML 32.1%
  • Shell 0.6%
  • JavaScript 0.4%
  • CSS 0.3%
  • Other 0.4%
Find a file
Mark Hahl 928a046871 Allow hostname-only Falco hosts
Relax ingest validation so Falco events are accepted when they carry a usable hostname, even without Kubernetes pod/container identity. This keeps the Kubernetes path for workload metadata while allowing bare-metal hosts to appear in alerts, nodes, dashboard, and silences. Updated worker and host inventory logic, and added tests covering hostname-only events and rejection of unknown or missing hostnames.
2026-09-10 10:02:18 +10:00
.impeccable/critique Kubernetes-only scopes and node inventory 2026-09-09 14:33:34 +10:00
assets Revamp UI: theming, icons, and silences 2026-09-10 08:38:20 +10:00
docs Kubernetes-only scopes and node inventory 2026-09-09 14:33:34 +10:00
k8s Add K8s rollout, clusters & DB settings 2026-09-08 18:05:45 +10:00
migrations Kubernetes-only scopes and node inventory 2026-09-09 14:33:34 +10:00
scripts Create reset.sh 2026-09-09 09:03:09 +10:00
src/pica Allow hostname-only Falco hosts 2026-09-10 10:02:18 +10:00
tests Allow hostname-only Falco hosts 2026-09-10 10:02:18 +10:00
.dockerignore Harden compose deploy and worker Redis timeouts 2026-09-08 02:50:45 +00:00
.env.example Add token deletion and kubeconfig UX fixes 2026-09-09 07:53:46 +10:00
.gitignore Add Linux agent onboarding UI and token management 2026-09-09 10:26:34 +10:00
compose.yaml Add token deletion and kubeconfig UX fixes 2026-09-09 07:53:46 +10:00
Containerfile Fix Tailwind CSS scan so daisyUI templates render 2026-09-08 03:36:38 +00:00
entrypoint.sh Harden compose deploy and worker Redis timeouts 2026-09-08 02:50:45 +00:00
package-lock.json Revamp UI: theming, icons, and silences 2026-09-10 08:38:20 +10:00
package.json Revamp UI: theming, icons, and silences 2026-09-10 08:38:20 +10:00
PLAN.md initial commit 2026-09-08 10:32:53 +10:00
pyproject.toml Add Kubernetes integration for Falco rules rollout 2026-09-08 17:14:42 +10:00
README.md Allow hostname-only Falco hosts 2026-09-10 10:02:18 +10:00

Pica

Falco alert and ruleset manager. See PLAN.md for the full plan.

Local development

Requires Python 3.11+, Node.js, Podman.

python3 -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"

npm install
npm run build:css

cp .env.example .env   # adjust tokens and URLs
flask --app pica db upgrade
flask --app pica run

Run tests with pytest.

Non-Kubernetes hosts

Falco on plain Linux hosts needs only a hostname to be accepted: mint an ingest token with a bare-metal cluster label (e.g. baremetal-edge), point the Falco webhook at POST /api/v1/events with that Bearer [REDACTED] and the host appears in Alerts, Nodes, Dashboard, and Silences. Events without a usable hostname are rejected. Managed ruleset rollout stays on the Kubernetes path; bare-metal rollout reuses the companion-agent track in PLAN.md.

Management commands:

flask --app pica prune                          # delete data older than RETENTION_DAYS
flask --app pica seed [--alerts N] [--reset]  # load example data (dev/demo)

Full stack with Podman

./scripts/up.sh       # podman compose up --build -d
./scripts/rebuild.sh  # no-cache rebuild, then recreate
./scripts/down.sh     # podman compose down

Pass extra compose flags through, e.g. ./scripts/down.sh -v to drop volumes.

The web UI listens on http://localhost:8001 (host 8001 → container 8000, so it does not collide with other local stacks on 8000). From another machine use http://<server-ip>:8001. On firewalld hosts allow the port:

sudo firewall-cmd --permanent --add-port=8001/tcp
sudo firewall-cmd --reload

The entrypoint applies flask db upgrade before starting gunicorn.