Skip to main content

Containers & Kubernetes

Cloudaware can ingest vulnerabilities discovered in container images and running Kubernetes workloads, and map them back to services, namespaces, and owning teams.

Sources of Container and Kubernetes Findings

Typical sources include:

  • Container registry image scanners (e.g., ECR, ACR, GCR, or third‑party tools).
  • Kubernetes‑native or agent‑based scanners that assess running pods and nodes.
  • Security platforms such as Snyk, Tenable, or other CNAPP tools.

Cloudaware stores these findings as Cloudaware Vulnerability Scan records and links them to:

  • Container Image CIs.
  • Kubernetes Cluster, Namespace, and Workload CIs.
  • Underlying nodes (via Breeze Agent or cloud provider metadata).

Configuration Steps

  1. Onboard clusters and registries.
    • Discover Kubernetes clusters and nodes into CMDB.
    • Add container registries as CIs where appropriate.
  2. Connect scanners.
    • Enable registry‑based image scanning and/or runtime scanning in your CNAPP or container security tool.
    • Configure Cloudaware integrations to ingest vulnerability findings.
  3. Map to applications and teams.
    • Use labels, namespaces, and deployment metadata to map workloads to applications and OUs.
    • Ensure CMDB reflects these relationships so ownership and routing work as expected.

Usage Patterns

  • Monitor high‑risk images and workloads via dashboards filtered by namespace, cluster, or application.
  • Prioritize runtime‑exposed vulnerabilities (containers actually running in production) over unused images.
  • Coordinate fixes with application teams and platform teams; consider linking to CI/CD pipelines for automated rebuilds.

For core data model and record‑type details, see: