Kubernetes Security

Cluster security posture, tied to its code.

ops0 scans running workloads for container vulnerabilities, tracks certificate expiry, checks config against policy, and links every finding back to the IaC project that owns it, across EKS, GKE, AKS, OKE, and self-managed clusters.

Container vulnerability scanning
Certificate expiry tracking
Policy checks
Findings linked to IaC

ops0 brings your clouds, runtime, infrastructure code, and workflows into one operating context. Kubernetes security posture covers container vulnerability scanning across running workloads, certificate expiry tracking, policy checks on configuration, and incident correlation to deploy history, then links every finding back to the IaC project that owns it, before it becomes an outage.

ops0.ai/use-cases/kubernetes-security
ops0 Kubernetes dashboard: connected clusters, namespaces, running workloads, and active alerts with workload and alert trends

Cluster findings pile up in scanners nobody owns. ops0 sends each one back to the code that owns it. 

Image scanningPolicy checksCertificate expiryLinked to IaC
From finding to owner
01 / 04 · Scan

Every running image, scanned.

Workloads across prod-eks are scanned for known vulnerabilities.

CHECKOUTPAYMENTSDATAcheckout-clusterteam: checkoutpayments-clusterteam: paymentsdata-clusterteam: dataPR #941PR #942PR #943
Going deeper

Runtime signal, on the same reviewed path.

Vulnerabilities

Container risk, next to cluster operations.

Container vulnerability scanning across running workloads.
Certificate expiration tracked before it becomes an outage.
Critical CVEs
2
checkout-prod-eks
Images scanned
146
across 3 clusters
Policy checks
18
2 failing
Certificates
1
expiring in 12 days
nginx:1.21 affected by a critical CVE
Imagenginx:1.21
Namespacecheckout
SeverityCritical
Under the hood

Security posture, tied to the code that owns it.

Vulnerability scanning
Every running workload, scanned.
nginx:1.21checkoutCritical
redis:6.2paymentsHigh
postgres:14dataCritical
envoy:1.24checkoutMedium

Severity ranked by whether the image is running and reachable, across EKS, GKE, AKS, and self-managed clusters.

Certificates
Expiry, tracked before it is an outage.
Certificate
expires in 12 days
Policy checks
Config, checked before it ships.
18checks, 2 failing
No privileged containers
Resource limits required
Incident correlation
Runtime failures, linked to deploy and IaC.
IncidentCrashLoopBackOff, checkout-prod-eks
Linked deployDeploy #482, 3 hours ago
Linked IaCterraform/checkout-cluster
Per-namespace cost
Spend, broken down for cleanup.
checkout+18%
payments
data
Orphaned resources
Over-requested and orphaned, surfaced for removal.
3 workloads over-requested3 orphans foundorphaned PVC, checkoutorphaned LoadBalancer, data

In practice

Review a Kubernetes finding, then verify the running workload.

Illustrative example: a Linux Deployment has no non-root requirement. Trace the pod to its owning manifest or Helm chart, review a compatible security context, and check the workload after the approved rollout.

  1. Capture the finding

    Record the cluster, namespace, workload, image, rule, and scan time. Inspect the current pod configuration and any container-level overrides.

  2. Review the owning configuration

    Confirm that the image supports a non-root user and that mounted files and writable paths have the right permissions. Choose a UID compatible with the application.

  3. Validate and approve the change

    Update the source manifest or chart, test it in an appropriate environment, and review the diff and policy checks through your team’s change process.

  4. Verify rollout and rescan

    Check Deployment readiness, pod events, and application health. Inspect the new pods, rerun the relevant configuration check, and attach the result to the original finding.

Illustrative Deployment pod-template fragment

Merge this fragment into the owning configuration after compatibility checks. UID 10001 is an example and must match the application’s requirements.

spec:
  template:
    spec:
      securityContext:
        runAsNonRoot: true
        runAsUser: 10001

A non-root setting addresses this configuration issue. Image vulnerabilities, network exposure, and other policy findings need their own remediation and verification.

Common questions

ops0 connects vulnerability findings, policy checks, cluster incidents, and resource context so teams can triage Kubernetes risk in one workflow.

Runtime findings should not
die in runtime tools.

ops0 keeps cluster issues connected to the reviewed workflow that can actually fix them, and Kiwi explains what happened in plain language.

Explore Kubernetes