Secure Your Self-Managed Clusters
Complete CIS Benchmark validation for vanilla Kubernetes with 83+ checks. Control plane, worker nodes, and policy security for kubeadm and bare-metal clusters.
Built for Self-Managed Kubernetes
Full visibility into every component you manage
All flags validated
At-rest & transit
Node-level security
Full benchmark
Complete Self-Managed Kubernetes Security
From API server to kubelet, validate every component you control
Full Control Plane Security Validation
Complete CIS Benchmark validation for self-managed control plane components. Audit API server, etcd, controller-manager, and scheduler configurations.
- API Server SecurityValidate all kube-apiserver flags and configurations
- etcd SecurityCheck etcd encryption, authentication, and backup
- Controller & SchedulerAudit controller-manager and scheduler security
Worker Node & Kubelet Security
Validate kubelet configurations, kernel parameters, and container runtime security on all worker nodes.
- Kubelet SecurityCheck kubelet flags, authentication, and authorization
- Node HardeningValidate kernel parameters and OS-level security
- Container RuntimeAudit containerd/Docker security configurations
Complete CIS Kubernetes Benchmark
Full coverage of CIS Kubernetes Benchmark v1.8.0. Every check for self-managed clusters including manual verification guidance.
- All 124 ChecksComplete CIS v1.8.0 coverage for self-managed clusters
- Automated + ManualAutomated checks with guidance for manual validations
- Remediation ScriptsReady-to-use scripts to fix common misconfigurations
CIS Kubernetes Benchmark v1.8.0
Complete coverage of all 124 CIS checks for self-managed clusters
Control Plane
48API Server, etcd, Controller Manager, Scheduler configurations
Worker Nodes
32Kubelet configuration, kernel parameters, file permissions
Policies
28RBAC, Pod Security, Network Policies, Secrets management
Authentication
8Service accounts, certificates, OIDC, webhook auth
Logging & Audit
6Audit logging, log retention, monitoring configuration
Hardening
2Encryption providers, admission controllers, security contexts
Frequently Asked Questions
Everything you need to know about self-managed Kubernetes security
Ready to Secure Your Self-Managed Clusters?
Start with a free CIS Benchmark scan. Full control plane and worker node validation.