A one-time security scan becomes outdated as applications and cluster settings change. Kubescape Operator runs recurring checks inside Kubernetes, looking for configuration problems and known vulnerabilities in application images. It makes findings available as cluster resources and can connect them to an external service for follow-up. It is useful when a team needs a continuing inventory of issues and a process for assigning fixes, rather than a report that is read once and forgotten.
Chart ownership
The Kubescape project documents the kubescape-operator chart from https://kubescape.github.io/helm-charts/. Its installation guide specifies Helm or Argo CD as supported installation paths. Chart capabilities are configurable; the enabled scanners and external integrations determine the actual access and resource footprint.
Before adoption
Review node access, registry credentials, scan-data retention and any information exported to a provider. Grant only the permissions needed by the chosen capabilities. Decide who triages findings and how exceptions expire; a completed scan is not proof that a cluster is secure or compliant. Evaluate scan overhead and upgrade behavior against representative workloads before enabling continuous assessment broadly.
Read the installation guide and operator overview to choose capabilities deliberately.
Sources & further reading
Spotted something that needs another look?
Help improve this page →