- and add sidekick memory limit - Add macros to exclude trivy, postgres, minio, vault from rules - Disable Container Drift Detection (too noisy) - Remove /etc/passwd from sensitive file access (normal lookups) - Add 256Mi memory limit to falcosidekick (was using 1.1GB)