Articles

Best Practices Analysis & CVE Scanning with KubeScape

Sandaruwan Lakshitha

Sandaruwan Lakshitha

August 28, 2025 · Updated September 27, 2026 · 3 min read

SecurityCVEBest Practices
Best Practices Analysis & CVE Scanning with KubeScape

In short

Kubescape, an open-source CNCF project, scans Kubernetes clusters for misconfigurations, compliance gaps and image vulnerabilities, running in-cluster as an operator installed with Helm. Out of the box its results live in custom resources you query with kubectl, with no UI, no view across clusters and no alerting. Running it inside a broader platform adds those, and puts CVE and CIS posture next to the rest of your telemetry.

What is Kubescape?

Kubescape is an open-source security tool specifically designed to evaluate the security posture of Kubernetes clusters. It identifies vulnerabilities, misconfigurations, and compliance issues, offering detailed insights that empower teams to strengthen their environments against potential threats. As a CNCF incubating project, Kubescape is supported by a robust community of contributors, ensuring it stays at the forefront of Kubernetes security.

How to Install & Configure?

Installation

The Kubescape operator can be installed using Helm. Once installed, Kubescape runs as a set of microservices within a Kubernetes cluster. This setup enables continuous monitoring of the cluster’s status, including compliance and vulnerability management.

Run the installation command:

helm repo add kubescape https://kubescape.github.io/helm-charts/ ; helm repo update ; helm upgrade --install kubescape kubescape/kubescape-operator -n kubescape --create-namespace --set clusterName=`kubectl config current-context` --set capabilities.continuousScan=enable

Verify that the installation was successful:

$ kubectl get pods -n kubescape
kubescape     kubescape-548d6b4577-qshb5    1/1     Running   0           60m
kubescape     kubevuln-6779c9d74b-wfgqf     1/1     Running   0           60m
kubescape     operator-5d745b5b84-ts7zq     1/1     Running   0           60m
kubescape     storage-59567854fd-hg8n8      1/1     Running   0           60m

Here’s what each of these services does:

  • Kubescape - scanning cluster for misconfigurations
  • Kubevuln - scanning container images for vulnerabilities
  • Operator - scheduling scans
  • Storage - provides an aggregated API server to expose Kubescape scan data inside the cluster

To see list of added CRDs to your cluster, use the following command:

$ kubectl api-resources | grep kubescape
applicationactivities                                     spdx.softwarecomposition.kubescape.io/v1beta1   true         ApplicationActivity
applicationprofiles                                       spdx.softwarecomposition.kubescape.io/v1beta1   true         ApplicationProfile
configurationscansummaries                                spdx.softwarecomposition.kubescape.io/v1beta1   false        ConfigurationScanSummary
generatednetworkpolicies                                  spdx.softwarecomposition.kubescape.io/v1beta1   true         GeneratedNetworkPolicy
knownservers                                              spdx.softwarecomposition.kubescape.io/v1beta1   false        KnownServer
networkneighborses                                        spdx.softwarecomposition.kubescape.io/v1beta1   true         NetworkNeighbors
openvulnerabilityexchangecontainers                       spdx.softwarecomposition.kubescape.io/v1beta1   true         OpenVulnerabilityExchangeContainer
sbomsyftfiltereds                                         spdx.softwarecomposition.kubescape.io/v1beta1   true         SBOMSyftFiltered
sbomsyfts                                                 spdx.softwarecomposition.kubescape.io/v1beta1   true         SBOMSyft
vulnerabilitymanifests                                    spdx.softwarecomposition.kubescape.io/v1beta1   true         VulnerabilityManifest
vulnerabilitymanifestsummaries                            spdx.softwarecomposition.kubescape.io/v1beta1   true         VulnerabilityManifestSummary
vulnerabilitysummaries                                    spdx.softwarecomposition.kubescape.io/v1beta1   false        VulnerabilitySummary
workloadconfigurationscans                                spdx.softwarecomposition.kubescape.io/v1beta1   true         WorkloadConfigurationScan
workloadconfigurationscansummaries                        spdx.softwarecomposition.kubescape.io/v1beta1   true         WorkloadConfigurationScanSummary

Configuration

Here we discuss major configuration changes that need to be made to evaluate the security posture of cluster.

Scanning private registries

If you need to scan private image repositories then you can set imagePullSecrets through the helm. See this chart.

Enabling capabilities

High-level capabilities of the Kubescape Operator can be configured using the values.yaml

capabilities:
  # ====== configuration scanning related capabilities ======
  #
  # Default configuration scanning setup
  configurationScan: enable
  # Continuous Scanning continuously evaluates the security posture of your cluster.
  continuousScan: disable
  nodeScan: enable
  # ====== Image vulnerabilities scanning related capabilities ======
  #
  vulnerabilityScan: enable
  relevancy: enable
  # Generate VEX documents alongside the image vulnerabilities report (experimental)
  vexGeneration: disable

  # ====== Runtime related capabilities ======
  #
  runtimeObservability: enable
  networkPolicyService: enable
  runtimeDetection: disable
  malwareDetection: disable
  nodeProfileService: disable
  seccompProfileService: enable

  # ====== Other capabilities ======
  #
  # This is an experimental capability with an elevated security risk. Read the
  # matching docs before enabling.
  autoUpgrading: disable
  prometheusExporter: disable
  # seccompGenerator: disable

#extra capability - service discovery option
serviceScanConfig:
  enabled : false
  interval: 1h

Set scan scheduling frequency

  • To change the frequency of running workload configuration scans, you need to change the value of this parameter kubescapeScheduler.scanSchedule in helm.
  • To change the frequency of running vulnerability scans, you need to change the value of this parameter kubevulnScheduler.scanSchedule in helm.

**Note :**See the GitHub repository for the Kubescape operator to learn the full set of configuration parameters.

How to see Results?

All the compliance scanning & vulnerability scanning results will be available gradually as the scans are completed.

Compliance scanning

View Compliance summary report per namespace:

kubectl get configurationscansummaries

View Compliance summary report for each workload:

kubectl get workloadconfigurationscansummaries -A

View Compliance detailed report for each workload:

kubectl get workloadconfigurationscans -A

Image Vulnerabilities scanning

View Vulnerabilities summary report per namespace:

kubectl get vulnerabilitysummaries

View vulnerabilities summary report for each workload/image:

kubectl get vulnerabilitymanifestsummaries -A

View vulnerabilities detailed report for each workload/image:

kubectl get vulnerabilitymanifests -A

Challenges with Running Kubescape on Its Own

Kubescape does the scanning well, but on its own it leaves the operational side to you:

  • No UI. The operator writes results to the custom resources shown above. Reading them means kubectl get and kubectl describe, which is workable for one engineer checking one cluster, and hard to hand to anyone else.
  • One cluster at a time. Each cluster runs its own operator and stores its own results. There’s no built-in view of posture across clusters.
  • No alerting. Nothing tells you when a new critical CVE shows up in a running workload. You find out when someone next goes looking.
  • Security in isolation. Scan results live apart from your performance, cost, and incident data, so connecting a vulnerable image to the service it runs in, and to who owns it, is manual work.

Kubescape as Part of Randoli

Security Posture for Kubernetes in Randoli is powered by Kubescape, running in the same data plane that already collects your logs, traces, and metrics, so there’s no separate operator to install and maintain.

Randoli security dashboard showing CVE counts and CIS Benchmark scoring per workload

It covers the gaps above:

  • CVE scanning and CIS Benchmark scoring at the workload, namespace, and cluster level, with drill-down from cluster-wide exposure to the specific workload driving it.
  • Every cluster in one place, alongside APM and cost data rather than in a separate security dashboard.
  • Anomaly detection on critical CVEs. Randoli alerts on sudden spikes in critical or high-severity CVEs, through the same channels as the rest of your alerting (Slack, email, PagerDuty, Teams).
  • Local processing. Scanning happens in your environment. Only posture signals and alerts reach Randoli’s control plane, never raw vulnerability data.

Security is priced at $0.02 per host, per hour; see pricing for the full breakdown.

See how Randoli applies this in practice.