- Python 66.2%
- HTML 32.1%
- Shell 0.6%
- JavaScript 0.4%
- CSS 0.3%
- Other 0.4%
Relax ingest validation so Falco events are accepted when they carry a usable hostname, even without Kubernetes pod/container identity. This keeps the Kubernetes path for workload metadata while allowing bare-metal hosts to appear in alerts, nodes, dashboard, and silences. Updated worker and host inventory logic, and added tests covering hostname-only events and rejection of unknown or missing hostnames. |
||
|---|---|---|
| .impeccable/critique | ||
| assets | ||
| docs | ||
| k8s | ||
| migrations | ||
| scripts | ||
| src/pica | ||
| tests | ||
| .dockerignore | ||
| .env.example | ||
| .gitignore | ||
| compose.yaml | ||
| Containerfile | ||
| entrypoint.sh | ||
| package-lock.json | ||
| package.json | ||
| PLAN.md | ||
| pyproject.toml | ||
| README.md | ||
Pica
Falco alert and ruleset manager. See PLAN.md for the full plan.
Local development
Requires Python 3.11+, Node.js, Podman.
python3 -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"
npm install
npm run build:css
cp .env.example .env # adjust tokens and URLs
flask --app pica db upgrade
flask --app pica run
Run tests with pytest.
Non-Kubernetes hosts
Falco on plain Linux hosts needs only a hostname to be accepted: mint an
ingest token with a bare-metal cluster label (e.g. baremetal-edge), point
the Falco webhook at POST /api/v1/events with that Bearer [REDACTED] and the host
appears in Alerts, Nodes, Dashboard, and Silences. Events without a usable
hostname are rejected. Managed ruleset rollout stays on the Kubernetes path;
bare-metal rollout reuses the companion-agent track in PLAN.md.
Management commands:
flask --app pica prune # delete data older than RETENTION_DAYS
flask --app pica seed [--alerts N] [--reset] # load example data (dev/demo)
Full stack with Podman
./scripts/up.sh # podman compose up --build -d
./scripts/rebuild.sh # no-cache rebuild, then recreate
./scripts/down.sh # podman compose down
Pass extra compose flags through, e.g. ./scripts/down.sh -v to drop volumes.
The web UI listens on http://localhost:8001 (host 8001 → container 8000,
so it does not collide with other local stacks on 8000). From another
machine use http://<server-ip>:8001. On firewalld hosts allow the port:
sudo firewall-cmd --permanent --add-port=8001/tcp
sudo firewall-cmd --reload
The entrypoint applies flask db upgrade before starting gunicorn.