VOOZH about

URL: https://thenewstack.io/kubescape-a-cncf-sandbox-platform-for-all-kubernetes-security/

⇱ Kubescape: A CNCF Sandbox Platform for All Kubernetes Security - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2023-01-12 09:00:38
Kubescape: A CNCF Sandbox Platform for All Kubernetes Security
CI/CD / Kubernetes / Software Development

Kubescape: A CNCF Sandbox Platform for All Kubernetes Security

Kubescape integrates with the necessary tools your DevOps teams need, such as software-bill-of-materials (SBOM), signature scanning and policy controls.
Jan 12th, 2023 9:00am by B. Cameron Gain
👁 Featued image for: Kubescape: A CNCF Sandbox Platform for All Kubernetes Security

Kubescape’s official acceptance this week by the Cloud Native Computing Foundation (CNCF) as a sandbox project represents the beginning stage in the journey to offer a comprehensive open source security platform for Kubernetes projects, the project’s creators from ARMO say.

According to Kubescape’s documentation, the open source Kubernetes security platform covers the gamut of the lifecycle of applications and their updates for Kubernetes applications. This includes IDE, CI/CD pipelines and clusters for risk analysis, security, compliance and misconfiguration scanning.

The key operative words are “platform” and “Kubernetes.” The platform part means that Kubescape is not just another security tool with very specific functionalities for Kubernetes among legions of alternatives. The Kubernetes part is essential because this means that the platform is for Kubernetes only.

Kubescape is used to integrate with the long checklist of the necessary tools your DevOps teams would like to add for use with the platform, such as for software-bill-of-materials (SBOM), signature scanning and policy controls. It begins running its scans at the very beginning left end of the production cycle and extends across CI/CD and throughout the deployment and cluster-management process.

Used to find and fix misconfigurations and vulnerabilities across such: frameworks as NSA-CISA, MITRE ATT&CK and the CIS Benchmark, Kubescape scans YAML files, and Helm charts and clusters upon deployment. Kubescape can also be integrated with Jenkins, CircleCI, GitHub Actions, GitLab, IDEs (i.e. Visual Studio Code) Prometheus, Lens and Docker.

“We want to be the CNCF’s open source Kubernetes security platform; that’s my vision. We want to consolidate Kubernetes security into a single platform,” CEO and co-founder of Shauli Rozen of ARMO, told The New Stack. “I really think this is something that has been missing in this space.”

The concept of an open source, CNCF-donated security platform exclusively targeted for Kubernetes is appealing. But more remains to be seen as to how this open source project is adopted, Torsten Volk, an analyst for Enterprise Management Associates (EMA), told The New Stack.

👁 Image

ARMO also now offers ARMO Platform, as an additional security layer on top of Kubescape. It provides what the company calls a “ready-made” security platform for Kubernetes for SaaS or on-premises deployments. It can be deployed on hosted Kubernetes platforms including Amazon’s Elastic Kubernetes Service (EKS), Microsoft’s Azure Kubernetes Service (AKS), Google Kubernetes Engine (GKE), Red Hat OpenShift and others.

Cogs and Wheels

Kubescape largely relies on Open Policy Agent to verify Kubernetes objects against a library of posture controls. In Kubescape’s documentation, monitoring results are printed and can also be:

  • Exported to JSON or junit XML.
  • Rendered to HTML or PDF.
  • Submitted to a cloud service.

👁 Image

Meanwhile, the company plans to open source a number of proprietary features and open source Kubescape’s backend code during the coming quarters for KubeScape, Rozen told The New Stack. The features it plans to open source include widening the process of continuously monitoring the runtime elements and “making sure that they’re not being changed,” in the event of a memory attack, for example, he said.

Meanwhile, in order to win over developer, security and operation team members, Kubescape must be able to demonstrate it can seamlessly fit into their current way of working and enable all Kubernetes-related personas to benefit from security guardrails and best practices sourced from the Kubernetes community, Volk said.  “This could finally give companies a leg up in the eternal race against the bad guys,” Volk said.

There are two categories of customers that Kubescape user customers typically fall under. These include large organizations that made the shift to cloud native but continue to maintain investments in other types of infrastructures outside of the Kubernetes sphere. The other end of the spectrum consists of recently created organizations that maintain “very dedicated Kubernetes environments,” Rozen said.

The all-Kubernetes organizations, mainly consisting of small- to medium-sized companies, is our sweet spot to be honest at the moment,” Rozen said.

TRENDING STORIES
BC Gain is founder and principal analyst for ReveCom Media. His obsession with computers began when he hacked a Space Invaders console to play all day for 25 cents at the local video arcade in the early 1980s. He then...
Read more from B. Cameron Gain
SHARE THIS STORY
TRENDING STORIES
CNCF is a sponsor of The New Stack.
TNS owner Insight Partners is an investor in: Docker.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.