Skip to main content
All answers

Can CISGuard scan Kubernetes?

Yes. CISGuard implements the CIS Kubernetes Benchmark with coverage at the cluster (kube-apiserver, etcd, kubelet, scheduler), namespace (RBAC, network policies), and pod (security context, capabilities) levels. CISGuard ships the CIS Kubernetes, Azure AKS, Amazon EKS and Red Hat OpenShift benchmarks, plus Docker for the container runtime. Cloud-native workloads scan with the same tooling as traditional infrastructure.

The longer answer.

On self-managed clusters the benchmark covers the control plane (API server, etcd, controller manager, scheduler) and the kubelet on each node. On managed services such as AKS and EKS the provider runs part of the control plane, so the matching CIS benchmark covers the parts the customer controls.

Some Kubernetes checks inspect files on the nodes themselves. Those need the CISGuard agent on the cluster nodes; without it they are reported for review rather than guessed.

More questions on Deployment?

Our compliance engineers can show you exactly how CISGuard handles Deployment in a briefing scoped to your environment.