/scanning-kubernetes-manifests-with-kubesec
Assess Kubernetes manifests with Kubesec to detect insecure pod/workload configurations an.
Assess Kubernetes manifests with Kubesec to detect insecure pod/workload configurations and enforce policy thresholds before deployment.
Category
Security
Execution
7 steps, sequential + gated
Goal
Assess Kubernetes manifests with Kubesec to detect insecure pod/workload configurations and enforce policy thresholds before deployment.
Scope
Applies to
- +Scan Kubernetes manifests with Kubesec
- +Block insecure K8s manifests in CI
- +Validate pod security controls before deploy
Does not cover
- −Trivial changes outside the workflow domain
Triggers
"Scan Kubernetes manifests with Kubesec""Block insecure K8s manifests in CI""Validate pod security controls before deploy""Add static manifest security gate"
Inputs
- →Context: environment/system affected
- →Scope: change boundary
- →Constraints: policy or hard rules
Invariants
- 01Every scanned resource must emit an explicit score and advisory list.
- 02Gate policy must be deterministic and documented.
- 03Critical insecure patterns (privileged, host PID/network, dangerous capabilities) are non-negotiable blockers.
- 04Results must be retained for review and remediation tracking.
Procedure
- Step 1Step 1 — **Prepare scan environment**
- Step 2Step 2 — **Define scoring and fail policy**
- Step 3Step 3 — **Scan manifests**
- Step 4Step 4 — **Evaluate key control categories**
- Step 5Step 5 — **Enforce CI/CD gate**
- Step 6Step 6 — **Optional admission enforcement**
- Step 7Step 7 — **Report and remediation**
Outputs
- ▸Kubesec scan report for all manifest targets.
- ▸Gate decision summary with score threshold outcome.
- ▸Findings list mapped to manifest resources and remediation actions.
- ▸Optional admission policy integration notes.
Review Gate
- [ ]All manifest targets are scanned with auditable output.
- [ ]Critical policy violations trigger blocking outcome.
- [ ]Score/advisory thresholds are clearly enforced.
- [ ]Findings include direct remediation guidance.
- [ ]Pipeline/admission integration behavior is documented.