Kubernetes Security Orchestration, Automation & Response Bare-metal bootstrap — kubeadm + Cilium + Falco + Tetragon + Kyverno
k8s-soar provisions a complete security stack on bare-metal Linux servers from scratch:
- Ansible — OS prep, kubeadm cluster, Helm install
- Cilium — eBPF CNI, network policies, Hubble
- Falco — runtime threat detection (modern eBPF) + custom rules
- Tetragon — kernel-level enforcement policies
- Kyverno — admission policies-as-code
- SOAR responder — Detect → Isolate via falcosidekick webhook (enabled by default)
- Observability — Grafana + Prometheus + Loki for findings dashboards and alerts (enabled by default)
For Bare-Metal (From Scratch):
- Bare-metal or VM servers: Ubuntu 22.04+, kernel ≥ 5.10
- Ansible ≥ 2.14 on operator machine
- SSH + sudo access to all nodes
cd ansible
chmod +x setup.sh
./setup.shThis automatically provisions the cluster and security stack. Attack scenarios are not run — execute those manually when you are ready (see below).
Attack scenarios are now housed in a separate repository to maintain k8s-soar as a clean, deployable security solution.
Please refer to the k8s-soar-scenarios repository to run simulations and trigger the security stack.
Shuffle is automatically installed and configured alongside the security stack!
During installation, the script automatically:
- Created an admin account (
admin/admin_password123!). - Imported the default
playbooks/master-responder.jsonworkflow. - Hooked the workflow directly into Falco's webhook endpoint.
If you wish to view or modify your Playbooks, simply access the UI:
kubectl port-forward svc/shuffle-frontend -n shuffle 3001:3000Open http://localhost:3001 in your browser.
The observability stack is enabled by default so you can visualize Falco findings, explore alert history, and configure Grafana alerts.
| Component | Role |
|---|---|
| Prometheus | Scrapes Falco / falcosidekick metrics (ServiceMonitors) |
| Loki | Stores Falco JSON alerts (via falcosidekick + Promtail pod logs) |
| Grafana | k8s-soar — Falco Findings dashboard + provisioned Loki alert |
./scripts/port-forward-grafana.sh
# http://127.0.0.1:3000 — user admin, password k8s-soar (change in values.yaml)Do you need Loki? Prometheus gives you rates and counters; Loki is what makes full finding text searchable in Grafana (rule name, pod, namespace, output message). Promtail also captures responder/sidekick logs for SOAR correlation.
To disable observability:
# values.yaml
observability:
enabled: falseOr: K8S_SOAR_ENABLE_OBSERVABILITY=0 ./ansible/setup.sh
./ansible/setup.sh| Step | Automated by |
|---|---|
| OS + kubeadm cluster | Ansible |
| Cilium / Falco / Tetragon / Kyverno | Split Helm releases (ansible/setup.sh) |
| Grafana / Prometheus / Loki | Split Helm releases (monitoring namespace) |
| Falco custom rules | render-helm-values.sh overlay |
| Kyverno + Tetragon + quarantine policies | scripts/apply-policies.sh |
| SOAR responder + webhook | On by default; disable with enable_soar: false or K8S_SOAR_ENABLE_SOAR=0 |
| Grafana dashboards + Loki alerts | On by default; ./scripts/port-forward-grafana.sh |
| Observability stack | On by default; disable with observability.enabled: false or K8S_SOAR_ENABLE_OBSERVABILITY=0 |
| Attack scenario execution | k8s-soar-scenarios repository |
| Kyverno Enforce mode | Optional — policies ship in Audit mode |
| Inventory / server IPs | One-time manual edit |
To update policies without a full reinstall: kubectl apply -k policies/
./scripts/verify-stack.sh
kubectl get cpol -AMIT