54cda9027ab154afb50b3a60cae1df540b6a3eec
nginx-proxy's routine reverse-proxied traffic to gitea:3000 trips the "Redirect stdout/stdin to network connection" rule every 5-15 min via the same dup3 mechanic as the already-excluded sshd case - not a new attack pattern, just proxied web traffic volume. Scoped to gitea's own fixed internal port so a redirect on any other port from this previously-compromised container still alerts. Also caps falco's own json-file log at 50MB x5 files - it had grown to 1.1GB unbounded (mostly 15s-interval metrics snapshots), which was making `docker logs falco` unreliable for the exact triage step its own alert text points admins to. Claude-Session: https://claude.ai/code/session_01HZQK6jHmdTpFjFZM8FUnqA
docker-infrastructure
Languages
Shell
53.7%
Python
33.6%
JavaScript
9.7%
HTML
2.1%
DIGITAL Command Language
0.5%
Other
0.4%