Kubernetes Security Scanning: The 4 Tools You Actually Need

Опубликовано: 05 Август 2026
на канале: Rawkode Academy
4,333
16

When it comes to Kubernetes tooling, the landscape is noisy and doesn't always have your back. Finding the right tools can be ... somewhat painful.

In this video, we cut through the noise and set up a standardised stack for day two security operations. These tools are the industry standard to secure the platform and the workloads running on top of it.

The Security Stack Covered:

KubeBench (Aqua Security): Checks your cluster against the CIS benchmarks—the global rulebook for hardening Kubernetes.
KubeHunter: Acts as a "red team" actively probing your cluster for open ports and backdoors.
Sonobuoy: The official CNCF conformance tool to ensure your API behaves correctly and guarantees interoperability.
Syft & Grype (Anchore): Generates an SBOM and scans your container images for vulnerabilities (CVEs) like log4j.

Finally, I’ll show you how to automate this entire stack using Spectro Cloud Palette to turn these scans into a simple toggle box operation.

Links:
Spectro Cloud: https://www.spectrocloud.com/

00:00 - Intro: Keeping your cluster secure Day 2 and beyond
00:46 - The problem with the CNCF Landscape (Too much noise)
02:02 - The Security Stack: Selecting the right tools
02:21 - Tool 1: KubeBench (CIS Benchmarks & Hygiene)
03:34 - Tool 2: KubeHunter (Red Teaming/Offensive)
04:19 - Tool 3: Sonobuoy (Conformance & Interoperability)
05:40 - Tool 4: Syft & Grype (Supply Chain & SBOMs)
07:29 - Demo: Running scans manually with CLI & Manifests
10:16 - Analyzing KubeHunter results
11:20 - Generating an SBOM with Syft
13:28 - Demo: Automating security scans with Palette
14:30 - Reviewing the automated reports (PDF/CSV)
16:25 - API Access & Exporting Audit Data