Available in:  Ultimate/EE

Included in extensions:  Advanced Infrastructure Security

The module lifecycle stage: General Availability

The module has requirements for installation

The module allows you to run regular vulnerability scans of user images in runtime on known CVEs, including vulnerabilities from Astra Linux, RedOS, and ALT Linux databases. It is based on the Trivy project, using public vulnerability databases enriched with Astra Linux, ALT Linux, and RedOS data.

The module also performs cluster compliance analysis against the CIS Kubernetes Benchmark and other standards — see the full list in the compliance reports section.

Starting with version 0.6.0, the module uses its own built-in database to store scan results and cluster application behavior models instead of the cluster’s etcd. Use networked or local block devices or localpath for module data. Do not use a StorageClass backed by file-based network storage such as NFS, S3, or CephFS.

The apiServerStorageClass parameter sets the StorageClass for security-storage. The Trivy server cache uses storageClass.

Main features

  • Automatic CVE scanning of container images in labeled namespaces. By default reports are regenerated every 24 hours; the interval is set by scanPeriods.workloadRescanPeriod.
  • CIS Kubernetes Benchmark compliance analysis with results stored in ClusterComplianceReport.
  • SBOM generation for all scanned container images (SbomReport).
  • Optional node host filesystem scanning for OS-level vulnerabilities (NodeVulnerabilityReport).
  • Optional periodic scanning of images in external container registries (RegistryScanTarget).
  • Exposed secrets detection in container images (ExposedSecretReport).
  • Optional admission-time blocking of vulnerable images (denyVulnerableImages).
  • Optional runtime application and network map (nodeAgent, preview).
  • Prometheus metrics and Deckhouse Console for vulnerability scan results; CIS and other compliance results in ClusterComplianceReport.

Read more about scanning, VulnerabilityReport and SbomReport reports, blocking vulnerable images, and CVE databases in Vulnerability scanning. The full list of module settings is in Configuration.

Scanning scope

The module splits its scanners into two groups with different scopes.

Image scanning is opt-in. It runs only in namespaces that have the label security-scanning.deckhouse.io/enabled="", and it produces VulnerabilityReport, SbomReport, and ExposedSecretReport. If the cluster has no namespaces with this label, the default namespace is scanned. Once a namespace with the label appears in the cluster, scanning of the default namespace stops.

To turn scanning back on for the default namespace, set the label:

d8 k label namespace default security-scanning.deckhouse.io/enabled=""

Deckhouse updates the list of scanned namespaces and restarts the operator, after which the namespace enters the image scanning scope.

Configuration scanning needs no label and covers every namespace, so that ClusterComplianceReport is built over the whole cluster. It produces ConfigAuditReport, RbacAssessmentReport, and InfraAssessmentReport. The complianceReports.skipSystemResources parameter is set to true by default, and then ConfigAuditReport and RbacAssessmentReport are not created in the d8-*, kube-*, and default namespaces at all. InfraAssessmentReport is exempt from that exclusion, so the CIS Kubernetes Benchmark checks for control plane components keep working.

Because of this split, the operator log reports the install mode as AllNamespaces with an empty target namespace list, even when a single namespace is labeled. That line describes the scope of configuration scanning, not of image scanning.

Removing the label stops new image scans in the namespace, but the reports already created there are not deleted at once. VulnerabilityReport is removed when its lifetime expires, within one scanPeriods.workloadRescanPeriod (24h by default), and is not created again. ExposedSecretReport and SbomReport have no lifetime of their own and remain until their workload is deleted.

Conditions for starting scanning

A scan starts automatically when a report becomes older than scanPeriods.workloadRescanPeriod (default 24h), and when components that use new images are deployed in namespaces where scanning is enabled.

Where to view scan results

In Deckhouse Console:

  • System / System management / Security / Vulnerabilities / By workloads — a summary of vulnerabilities in images and cluster resources.

In cluster resources:

The aggregated security score is published as resources: ClusterSecurityScore for the cluster and SecurityScore in every user namespace. How it is calculated is described in the Security score section.