Home / Companies / Sysdig / Blog / Post Details
Content Deep Dive

Shielding your Kubernetes runtime with image scanning on admission controller

Blog post from Sysdig

Post Details
Company
Date Published
Author
Víctor Jiménez Cerrada
Word Count
1,596
Company Posts That Month
9
Language
English
Hacker News Points
-
Post removed?
No
Summary

Implementing image scanning on Kubernetes admission controllers provides a robust last line of defense for securing clusters by ensuring that all deployed images adhere to security policies. Admission controllers, a native Kubernetes feature, intercept API requests before object persistence, enabling them to block the deployment of non-compliant images. Various strategies exist for implementing this, ranging from DIY open-source integrations using tools like Anchore, Falco, and OPA, to commercial solutions like the Sysdig Admission Controller. The latter offers streamlined setup and operation, with features such as centralized scan results, policy reuse, and continued protection even during connectivity issues. Incorporating image scanning at this stage complements other security measures, addresses vulnerabilities in manual deployments, and enhances overall cluster security.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 19 965 131 44 +22%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.