← docsSecurity

/scanning-kubernetes-manifests-with-kubesec

Assess Kubernetes manifests with Kubesec to detect insecure pod/workload configurations an.

Assess Kubernetes manifests with Kubesec to detect insecure pod/workload configurations and enforce policy thresholds before deployment.

Category

Security

Execution

7 steps, sequential + gated

Goal

Assess Kubernetes manifests with Kubesec to detect insecure pod/workload configurations and enforce policy thresholds before deployment.

Scope

Applies to

  • +Scan Kubernetes manifests with Kubesec
  • +Block insecure K8s manifests in CI
  • +Validate pod security controls before deploy

Does not cover

  • −Trivial changes outside the workflow domain

Triggers

"Scan Kubernetes manifests with Kubesec""Block insecure K8s manifests in CI""Validate pod security controls before deploy""Add static manifest security gate"

Inputs

  • →Context: environment/system affected
  • →Scope: change boundary
  • →Constraints: policy or hard rules

Invariants

  • 01Every scanned resource must emit an explicit score and advisory list.
  • 02Gate policy must be deterministic and documented.
  • 03Critical insecure patterns (privileged, host PID/network, dangerous capabilities) are non-negotiable blockers.
  • 04Results must be retained for review and remediation tracking.

Procedure

  1. Step 1Step 1 — **Prepare scan environment**
  2. Step 2Step 2 — **Define scoring and fail policy**
  3. Step 3Step 3 — **Scan manifests**
  4. Step 4Step 4 — **Evaluate key control categories**
  5. Step 5Step 5 — **Enforce CI/CD gate**
  6. Step 6Step 6 — **Optional admission enforcement**
  7. Step 7Step 7 — **Report and remediation**

Outputs

  • ▸Kubesec scan report for all manifest targets.
  • ▸Gate decision summary with score threshold outcome.
  • ▸Findings list mapped to manifest resources and remediation actions.
  • ▸Optional admission policy integration notes.

Review Gate

  • [ ]All manifest targets are scanned with auditable output.
  • [ ]Critical policy violations trigger blocking outcome.
  • [ ]Score/advisory thresholds are clearly enforced.
  • [ ]Findings include direct remediation guidance.
  • [ ]Pipeline/admission integration behavior is documented.