4d9d15417a01755f840f3fe89e40183af98e2b9d
No repeat intrusion - investigated all Falco alerts since deployment (2026-08-08 to 2026-08-16); the only crypto-miner rule hits were the original test alerts. The daily self-resolving Telegram alerts the user was seeing came from four known-benign sources: Obsidian's Electron self-re-exec pattern and s6-init sudoers setup (fires ~daily on container recreation), ttyd/Synchronet's telnet/pv/busybox-extras BBS tooling, and ollama's nvidia-ctk ldconfig-refresh hook (memfd_create by design). Added scoped exceptions for each via Falco's own rule extension points, same pattern as the earlier pg_isready/gitea fixes. Also fixed netdata's used_swap alarm, which recalculated from the instantaneous raw sample every 10s with only a 30s notification debounce - a brief swap spike was enough to page both Telegram and (via Netdata Cloud) email. Widened the up-delay to 5m so only sustained swap pressure notifies. Verified end-to-end via a fresh fake-xmrig test after redeploying Falco and reloading netdata: CRITICAL alarm fired and Telegram delivery succeeded.
docker-infrastructure
Languages
Shell
58.2%
Python
28%
JavaScript
10.5%
HTML
2.3%
DIGITAL Command Language
0.6%
Other
0.4%