Your Kubernetes cluster is running. Is it secure? Kubescape answers that question by scanning against established security frameworks: NSA hardening guide, MITRE ATT&CK, CIS Benchmarks, and more.
Quick Scan
# Install
curl -s https://raw.githubusercontent.com/kubescape/kubescape/master/install.sh | bash
# Scan the cluster
kubescape scan
# Results
Controls: 85 (Passed: 62, Failed: 18, Skipped: 5)
Risk score: 32%
Failed controls:
CRITICAL: C-0086 - Ensure that pods run as non-root
HIGH: C-0034 - Ensure network policies are configured
HIGH: C-0057 - Privileged containers detected
MEDIUM: C-0018 - Ensure CPU limits are setFramework Scans
# NSA Kubernetes Hardening Guide
kubescape scan framework nsa
# MITRE ATT&CK
kubescape scan framework mitre
# CIS Kubernetes Benchmark
kubescape scan framework cis-v1.23-t1.0.1
# All frameworks
kubescape scan framework allMaster this topic with hands-on labs
Go beyond reading ā build real projects in sandboxed environments with expert video guidance.
Browse Courses āScan Specific Resources
# Scan a namespace
kubescape scan --include-namespaces production
# Scan a specific workload
kubescape scan workload deployment/order-api -n production
# Scan YAML before deploying
kubescape scan *.yamlCommon Failures and Fixes
Pods Running as Root
FAILED: C-0086 - Ensure that pods run as non-root
Affected: deployment/order-api (production)Fix:
spec:
containers:
- name: order-api
securityContext:
runAsNonRoot: true
runAsUser: 1000
allowPrivilegeEscalation: false
readOnlyRootFilesystem: trueMissing Network Policies
FAILED: C-0034 - Ensure network policies are configured
Affected: namespace/production (no NetworkPolicy found)Fix:
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny
namespace: production
spec:
podSelector: {}
policyTypes:
- Ingress
- EgressNo Resource Limits
FAILED: C-0018 - Ensure CPU/memory limits are set
Affected: deployment/order-api (production)Fix:
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 512MiCI/CD Integration
GitHub Actions
jobs:
security-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Kubescape scan
uses: kubescape/github-action@main
with:
files: "k8s/*.yaml"
frameworks: "nsa,mitre"
severityThreshold: high
failedThreshold: 0Fail the build if any HIGH or CRITICAL issues are found in Kubernetes manifests.
Scan in Cluster
helm install kubescape kubescape/kubescape-operator \
--namespace kubescape --create-namespaceThe operator runs continuous scans and reports results as Kubernetes resources:
kubectl get workloadconfigurationscans -A
kubectl get vulnerabilitymanifests -AGet weekly IT automation tips
Docker, Ansible, Terraform, MLOps ā curated insights delivered to your inbox. No spam.
Subscribe Free āOutput Formats
# JSON for CI parsing
kubescape scan --format json -o results.json
# SARIF for GitHub Security tab
kubescape scan --format sarif -o results.sarif
# HTML report
kubescape scan --format html -o report.html
# Prometheus metrics
kubescape scan --submit --account=<account-id>Exceptions
Not every control applies to every workload:
# kubescape-exceptions.yaml
apiVersion: kubescape.io/v1
kind: ExceptionPolicy
metadata:
name: allow-kube-system-privileged
spec:
exceptions:
- name: "kube-system privileged"
policyType: posturePolicy
actions: ["alertOnly"]
resources:
- designators:
- attributes:
namespace: kube-system
posturePolicies:
- controlID: C-0057 # Privileged containerskube-system components legitimately need elevated privileges. Document exceptions, do not silence them.
Kubescape vs Alternatives
| Tool | Cluster scan | YAML scan | Vulnerability scan | Compliance frameworks |
|---|---|---|---|---|
| Kubescape | ā | ā | ā | NSA, MITRE, CIS |
| kube-bench | ā | ā | ā | CIS only |
| Trivy | ā | ā | ā | NSA, PSS |
| Polaris | ā | ā | ā | Custom |
Kubescape covers the broadest range of frameworks with the simplest CLI.
---
Ready to go deeper? Master Kubernetes security with hands-on courses at CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials ā start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Talos Linux for Kubernetes
Talos Linux is a minimal, immutable OS designed exclusively for running Kubernetes. Learn why it exists, how it works, and when to use it instead of Ubuntu.
Falco Runtime Security Kubernetes
Falco detects runtime threats in Kubernetes using eBPF. Learn how to set up Falco for container security monitoring, write custom rules, and integrate.
OPA Gatekeeper Kubernetes Policies
OPA Gatekeeper enforces custom policies in Kubernetes at admission time. Learn how to write ConstraintTemplates, enforce security standards, and prevent.
Kubevirt VMs on Kubernetes Guide
KubeVirt runs virtual machines alongside containers on Kubernetes. Learn how to deploy VMs as pods, migrate legacy workloads, and manage hybrid container-VM.
Kustomize Kubernetes Configuration
Kustomize customizes Kubernetes manifests without templates using overlays and patches. Learn how to manage multiple environments, merge configurations.
Kyverno Kubernetes Policy Engine
Kyverno validates, mutates, and generates Kubernetes resources using YAML policies instead of Rego. Learn how to enforce security standards, set defaults.
Explore topics
Browse more articles on the topics covered here.