Sysdig Author Falco Rule and Attach to Policy
Version 1.0.0
Create a custom Falco rule, then create a policy that references it.
1 workflow
2 source APIs
1 provider
View Spec
View on GitHub
Cloud SecurityContainersKubernetesRuntime SecuritySecurityVulnerability ManagementMonitoringObservabilityCSPMComplianceArazzoWorkflows
author-falco-rule-and-attach-policy
Create a Falco rule and wire it into an enforcing policy.
Creates a custom Falco rule, reads it back to confirm it persisted, and then creates a falco-type policy that references the rule by name.
3 steps
inputs: bearerToken, condition, output, policyName, priority, ruleName
outputs: policyId, ruleId
1
createRule
Create the custom Falco rule from the supplied condition.
2
verifyRule
Read the rule back by id to confirm it persisted.
3
createPolicy
Create a falco-type policy that references the new rule by name.
Every workflow here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for arazzo workflows
4 MCP tools reach this
find_arazzoBrowse and filter every workflow in the catalog.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools →
Call it yourself
curl for this page
This workflow
curl "https://apis.io/api/v1/arazzo/sysdig-author-falco-rule-and-attach-policy-workflow"
All arazzo workflows
curl "https://apis.io/api/v1/arazzo?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.
A second provider on the same verified email joins the account you already have.