Installation

May 18, 2026 · View on GitHub

The Falco Operator can be installed in two ways: via the official Helm chart (recommended) or by applying the bundled YAML manifest.

Contents

Prerequisites

  • Kubernetes 1.29+ — The Artifact Operator runs as a native sidecar container, which requires Kubernetes 1.29 or later.
  • kubectl — Installed and configured to access your cluster.
  • Cluster admin privileges — Required for installing CRDs and ClusterRoles.
  • Helm 3.x — Only required for the Helm installation method.

Install with Helm

The Helm chart is the recommended way to install the Falco Operator. It packages CRDs, RBAC, and the operator Deployment, and exposes configuration through values.yaml.

Adding the falcosecurity repository

Add the falcosecurity charts repository:

helm repo add falcosecurity https://falcosecurity.github.io/charts
helm repo update

Install

Install the chart with default values and release name falco-operator:

helm install falco-operator falcosecurity/falco-operator \
  --namespace falco-operator \
  --create-namespace

After a few seconds, verify the operator is running:

kubectl get pods -n falco-operator
kubectl wait pods --for=condition=Ready --all -n falco-operator

Configuration

The chart exposes all common knobs (image, replicas, RBAC, probes, resources, tolerations, affinity, extra args, extra env, etc.) through values.yaml. See the full list in the chart README or the values.yaml file.

Override values with --set or a values file:

helm install falco-operator falcosecurity/falco-operator \
  --namespace falco-operator \
  --create-namespace \
  --set image.tag=0.2.1
helm install falco-operator falcosecurity/falco-operator \
  --namespace falco-operator \
  --create-namespace \
  -f my-values.yaml

Upgrade

Pull the latest chart metadata, then upgrade the release:

helm repo update
helm upgrade falco-operator falcosecurity/falco-operator --namespace falco-operator

To upgrade to a specific chart version:

helm upgrade falco-operator falcosecurity/falco-operator \
  --namespace falco-operator \
  --version <chart-version>

Important: Before upgrading, always check the CHANGELOG, the chart CHANGELOG, and the migration guide for your target version. Minor releases may still include breaking API changes that require updating your custom resources before or after the upgrade.

Uninstall

Remove resources in the correct order — artifact CRs first (so the Artifact Operator sidecar can process finalizer cleanup), then instance CRs, then the operator release:

# 1. Remove artifact resources first
kubectl delete rulesfiles --all --all-namespaces
kubectl delete plugins --all --all-namespaces
kubectl delete configs --all --all-namespaces

# 2. Remove instance resources
kubectl delete components --all --all-namespaces
kubectl delete falco --all --all-namespaces

# 3. Uninstall the Helm release
helm uninstall falco-operator --namespace falco-operator

# 4. Remove the operator namespace
kubectl delete namespace falco-operator

Important: Deleting Falco instances before artifacts will terminate the Artifact Operator sidecar, leaving artifact finalizers unresolved. Always delete artifact resources first.

Note on CRDs: Helm does not delete CRDs that are installed from a chart's crds/ directory. If you want to fully remove the operator's API surface from the cluster, delete the CRDs manually after helm uninstall:

kubectl delete crd \
  falcos.instance.falcosecurity.dev \
  components.instance.falcosecurity.dev \
  configs.artifact.falcosecurity.dev \
  plugins.artifact.falcosecurity.dev \
  rulesfiles.artifact.falcosecurity.dev

Install with YAML manifest

The YAML manifest is a single-file installer generated from the same Helm chart. Use it when Helm is not available or when you want to manage the operator with plain kubectl apply.

Install

Create the operator namespace, then apply the single-manifest installer:

kubectl create namespace falco-operator

VERSION=latest
if [ "$VERSION" = "latest" ]; then
  kubectl apply --server-side -f https://github.com/falcosecurity/falco-operator/releases/latest/download/install.yaml
else
  kubectl apply --server-side -f https://github.com/falcosecurity/falco-operator/releases/download/${VERSION}/install.yaml
fi

What gets created

The installer deploys the following resources into the falco-operator namespace:

ResourceNameDescription
CRDfalcos.instance.falcosecurity.devFalco instance management
CRDcomponents.instance.falcosecurity.devCompanion component management
CRDconfigs.artifact.falcosecurity.devConfiguration management
CRDplugins.artifact.falcosecurity.devPlugin management
CRDrulesfiles.artifact.falcosecurity.devRules management
ServiceAccountfalco-operatorOperator identity
ClusterRolefalco-operator-roleRequired permissions
ClusterRoleBindingfalco-operator-rolebindingPermission binding
Deploymentfalco-operatorThe operator itself

Verify installation

kubectl get pods -n falco-operator
kubectl wait pods --for=condition=Ready --all -n falco-operator

Upgrade

To upgrade to a new version, re-apply the installer manifest:

VERSION=latest
if [ "$VERSION" = "latest" ]; then
  kubectl apply --server-side -f https://github.com/falcosecurity/falco-operator/releases/latest/download/install.yaml
else
  kubectl apply --server-side -f https://github.com/falcosecurity/falco-operator/releases/download/${VERSION}/install.yaml
fi

Important: Before upgrading, always check the CHANGELOG and the migration guide for your target version. Minor releases may still include breaking API changes that require updating your custom resources before or after the upgrade.

Uninstall

Remove resources in the correct order — artifact CRs first (so the Artifact Operator sidecar can process finalizer cleanup), then instance CRs, then the operator:

# 1. Remove artifact resources first
kubectl delete rulesfiles --all --all-namespaces
kubectl delete plugins --all --all-namespaces
kubectl delete configs --all --all-namespaces

# 2. Remove instance resources
kubectl delete components --all --all-namespaces
kubectl delete falco --all --all-namespaces

# 3. Remove the operator and CRDs
kubectl delete -f https://github.com/falcosecurity/falco-operator/releases/latest/download/install.yaml

# 4. Remove the operator namespace
kubectl delete namespace falco-operator

Important: Deleting Falco instances before artifacts will terminate the Artifact Operator sidecar, leaving artifact finalizers unresolved. Always delete artifact resources first.

Required Permissions

The operator requires the following RBAC permissions:

API GroupResourcesVerbs
"" (core)pods, nodes, configmaps, secrets, serviceaccounts, services, endpoints, namespaces, replicationcontrollersget, list, watch, create, update, patch, delete
"" (core), events.k8s.ioeventscreate, patch, update
appsdaemonsets, deployments, replicasetsget, list, watch, create, update, patch, delete
rbac.authorization.k8s.ioroles, rolebindings, clusterroles, clusterrolebindingsget, list, watch, create, update, patch, delete
discovery.k8s.ioendpointslicesget, list, watch
instance.falcosecurity.devfalcos, falcos/status, falcos/finalizers, components, components/status, components/finalizersget, list, watch, create, update, patch, delete
artifact.falcosecurity.devconfigs, configs/status, configs/finalizers, plugins, plugins/status, plugins/finalizers, rulesfiles, rulesfiles/status, rulesfiles/finalizersget, list, watch, create, update, patch, delete

Next Steps