K8s

Kubernetes security scanning

Scan 12 areas of a cluster — RBAC, pod security, network policy, secrets and workload configuration.

How you connect

Connect with a service account token and the cluster API URL. Supply a CA certificate if the API server uses a private authority.

What A1 Cloud Guard looks for

  • Pods running privileged or as root
  • Cluster-admin bound to a default service account
  • Namespaces with no NetworkPolicy at all
  • Secrets mounted broadly or stored unencrypted
  • Containers with no resource limits set

12 services covered

Choose any combination per scan — you are never forced to scan the whole estate.

  • Pods
  • RBAC
  • Network Policies
  • Secrets
  • ConfigMaps
  • Namespaces
  • Pod Security
  • Ingress
  • Services
  • DaemonSets
  • Deployments
  • Service Accounts

Scan your K8s estate

Connect a read-only credential and see the full report on the free plan.