Kubescape: Kubernetes posture scanning from the CLI to the cluster operator
Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.
At a glance
- What is it?
- Kubescape is an Apache-2.0 Go tool from ARMO, now a CNCF incubating project, that scans clusters, YAML and images against NSA-CISA, MITRE ATT&CK and CIS frameworks. It is easy to install and quick to run, but its framework coverage is opinionated and its fixes are not always safe to apply blind.
- Who is it for?
- Adopt Kubescape if you want a single Go binary that scores cluster posture against NSA-CISA, MITRE ATT&CK and CIS benchmarks, and if you are willing to treat its auto-fix output as a patch to review rather than to apply. Do not adopt it as your only image scanner or as a runtime detection layer; the README points at Grype and Inspektor Gadget for those jobs, and the CLI is a point-in-time checker.
- Can I use it commercially?
- Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository received new commits within the last day.
- What is it written in?
- Mainly Go, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The gap Kubescape fills between manifest linting and runtime detection
Most Kubernetes teams end up with three unrelated tools: a linter for YAML, an image scanner in CI, and something watching the cluster at runtime. Kubescape targets the middle of that stack. The README describes it as a platform that provides "hardening, posture management, and runtime security capabilities", and the feature table lists misconfiguration scanning against NSA-CISA, MITRE ATT&CK and CIS Benchmarks as the first entry. That is the core job: take a cluster, a directory of manifests, or a Helm chart, and report which controls fail.
The audience is platform and security engineers who already run Kubernetes and need a compliance-shaped answer rather than a list of lint warnings. The framework names matter here. NSA-CISA and MITRE ATT&CK are recognizable to auditors and to anyone writing a security review, which is why the CLI output is organised as control-plane status, access control risks, workload misconfigurations, network policy gaps, and compliance scores. If your requirement is "show me our posture against a named benchmark", this maps to it directly. If your requirement is "tell me when a pod starts behaving oddly at 3am", it does not, and the README routes that to Inspektor Gadget instead.
How the scanner, the frameworks and the vendored admission policies fit together
The repository layout separates concerns in a way that is worth understanding before you file a bug. The binary entry point is main.go, with cmd/, core/, pkg/, rules/ and downloader/ alongside it. The downloader/ directory is the tell: Kubescape does not ship every framework and control definition inside the binary. It fetches artifacts, and the README exposes that as an explicit command, kubescape download, described as being for "offline/air-gapped use". That design choice explains both the fast install and the failure mode where a locked-down network produces a scan that cannot resolve its controls.
The admission-control path is different. The Makefile shows a target called sync-vap that vendors a CEL admission library under core/pkg/opaprocessor/cel/vapdata, pinned to CEL_LIBRARY_VERSION := v0.15 and embedded into the binary so //go:embed can bake it in. The comment in the Makefile is unusually candid about why the digests are pinned by hand: the upstream release publishes no checksum manifest or signature, so an unverified download would bake whatever the release serves into every build. Three SHA256 values are listed for kubescape-validating-admission-policies.yaml, basic-control-configuration.yaml and policy-configuration-definition.yaml. That is a real supply-chain control, and it is also a maintenance burden, since bumping the CEL library version means running make sync-vap-digests, checking the values, and pasting them in the same commit.
Image scanning is delegated. The go.mod requires github.com/anchore/grype and github.com/anchore/syft, and the README credits Grype for CVE detection and Copacetic for patching, which is why the image side of Kubescape behaves like Grype with a Kubernetes-shaped front end.
Installing Kubescape and running a first scan
The README's quick start is a one-line install script for Linux and macOS. It pipes a remote shell script into bash, which is convenient and also the reason some teams will prefer a package manager instead.
curl -s https://raw.githubusercontent.com/kubescape/kubescape/master/install.sh | /bin/bashIf you would rather not pipe a remote script into a shell, the README lists Homebrew, Krew, Arch, Ubuntu, NixOS, Chocolatey and Scoop. For a kubectl-centric workflow, the Krew route keeps the tool next to your other plugins.
kubectl krew install kubescapeWith the binary on your PATH, the first useful command is a scan of the cluster your kubeconfig points at. No arguments are needed.
kubescape scanThe README says this produces a posture overview covering control plane security status, access control risks, workload misconfigurations, network policy gaps, and compliance scores for MITRE and NSA. Before you trust the numbers, run the list command so you know which frameworks the build you installed actually carries.
kubescape listScanning a directory of manifests instead of a live cluster is the same verb with a path, which is the form that fits a CI job where no cluster is reachable.
kubescape scan /path/to/manifests/Image scanning uses a subcommand and takes a normal image reference.
kubescape scan image nginx:latestOn Windows the README gives a PowerShell equivalent rather than the bash script.
iwr -useb https://raw.githubusercontent.com/kubescape/kubescape/master/install.ps1 | iexAuto-fix and image patching are the parts to treat with suspicion
The CLI table lists kubescape fix as being able to "auto-fix misconfigurations in manifest files, or print fixes for a cluster scan", and kubescape patch as patching container images to fix vulnerabilities. Those two commands carry more risk than the scan they follow, and the README does not document rollback for either.
A misconfiguration fix is a rewrite of a manifest or of a live object. The scanner's judgement about what is misconfigured is derived from the same framework definitions that produced the finding, so if a control is a poor fit for your workload, the fix inherits that poor fit and applies it. There is an examples/exceptions/ directory in the repository, which suggests the project expects users to carve out exceptions rather than accept every fix, but the README itself does not walk through that workflow. Treat fix as a generator of suggested patches to review, not as a remediation step in an unattended pipeline.
Image patching has a similar shape. Patching a base image produces a new image with a new digest, which means anything pinned by digest, any signature verification, and any admission policy that checks image provenance needs to be re-evaluated. The README names Copacetic as the patching engine and does not describe how the patched image is signed or attested. If your supply chain depends on signatures, that gap is where you will spend your time.
Kubescape versus Trivy, Kyverno and the other tools people compare it to
The comparison people reach for most often is Trivy. The two overlap on image scanning: Kubescape embeds Grype and Syft for CVE detection, while Trivy carries its own scanner and its own vulnerability database. The practical difference is that Trivy's centre of gravity is the artifact, and Kubescape's is the cluster's configuration posture against named benchmarks. If you already run Trivy in CI for images, adding Kubescape does not duplicate that work so much as add a framework-scored view of the cluster itself.
Against Kyverno, the difference is enforcement versus assessment. Kyverno is an admission controller whose primary job is to accept or reject resources against policies you write. Kubescape's admission path uses Validating Admission Policies, and the README lists admission control as one feature among several rather than the product's purpose. A team that wants policy-as-code enforcement with a mature authoring workflow is better served by Kyverno; a team that wants to know how it scores before writing any policy is better served by Kubescape's scan.
Against kube-bench, the split is scope. kube-bench checks a node or cluster against the CIS Kubernetes Benchmark specifically. Kubescape covers CIS as one of several frameworks, alongside NSA-CISA and MITRE ATT&CK, and extends to manifests and images. If CIS is your only requirement, kube-bench is the narrower and more predictable tool. If you need to report against more than one framework, the single scan is the argument for Kubescape.
Runtime detection is the comparison to get right. Falco and NeuVector watch behaviour in a running cluster. Kubescape's runtime capability is described as eBPF-based monitoring via Inspektor Gadget, which is a dependency rather than something Kubescape implements itself. Choosing Kubescape for runtime security means choosing Inspektor Gadget's detection model as well.
Licence, maintenance and the cost of keeping frameworks current
Kubescape is Apache-2.0, which is permissive and includes an explicit patent grant. The repository also carries a SECURITY.md and a SECURITY-INSIGHTS.yml, and the README badges reference OpenSSF Best Practices and OpenSSF Scorecard, so there is a documented security-reporting process. Apache-2.0 places no copyleft obligation on your own code, but it also gives no warranty, and the framework content Kubescape downloads is a separate artifact whose licence and provenance the README does not discuss. If you redistribute a scan report or the downloaded framework definitions inside a commercial product, that is worth checking rather than assuming.
The project is not archived, and the last push was on 2026-09-21, with v4.0.14 released on 2026-09-09. That is a fast release cadence, which cuts both ways. You get current framework definitions and current dependency versions, including the Grype and Syft pins in go.mod. You also inherit churn: the module path is github.com/kubescape/kubescape/v4, so a major-version bump changes import paths for anyone building against it, and the CEL admission library is pinned to v0.15 with hand-maintained digests that must be refreshed deliberately. Budget for someone owning that upgrade, because the Makefile comment makes clear the project will not do it for you automatically.
Editorial conclusion
Adopt Kubescape if you want a single Go binary that scores cluster posture against NSA-CISA, MITRE ATT&CK and CIS benchmarks, and if you are willing to treat its auto-fix output as a patch to review rather than to apply. Do not adopt it as your only image scanner or as a runtime detection layer; the README points at Grype and Inspektor Gadget for those jobs, and the CLI is a point-in-time checker. Before rolling it into CI, run kubescape list to see which frameworks the pinned build actually ships, and check whether your cluster's admission policies will accept the Validating Admission Policies the operator installs.
Frequently asked questions
How do I install Kubescape?
The README's quick start uses a one-line install script for Linux and macOS, and also lists Homebrew, Krew, Arch, Ubuntu, NixOS, Chocolatey and Scoop, plus a PowerShell script for Windows. Krew is the option that keeps it alongside your other kubectl plugins.
What is Kubescape?
It is an open-source Kubernetes security platform created by ARMO and a CNCF incubating project, licensed Apache-2.0 and written in Go. The README describes it as covering hardening, posture management and runtime security across the development and deployment lifecycle.
What does Kubescape do?
Its main job is misconfiguration scanning of clusters, YAML files and Helm charts against NSA-CISA, MITRE ATT&CK and CIS Benchmarks. It also scans container images for CVEs using Grype, can patch images with Copacetic, and can auto-fix misconfigurations in manifests.
How does Kubescape compare with kube-bench?
kube-bench checks a cluster against the CIS Kubernetes Benchmark specifically, while Kubescape covers CIS as one of several frameworks alongside NSA-CISA and MITRE ATT&CK. Kubescape also extends to manifests and container images.
How does Kubescape compare with Falco?
Falco watches behaviour in a running cluster, while Kubescape's runtime capability is described in the README as eBPF-based monitoring via Inspektor Gadget. Kubescape's own emphasis is misconfiguration scanning against named frameworks.
How does Kubescape compare with the Trivy Operator?
Kubescape embeds Grype and Syft for image CVE detection and scans clusters, manifests and Helm charts against NSA-CISA, MITRE ATT&CK and CIS. The README does not compare it with the Trivy Operator, so the difference in in-cluster operating model is not documented here.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/kubescape-kubescape)