Skip to content

Kubescape Security Scanning for Kubernetes

This guide enables Kubescape in offline mode for lightweight configuration and vulnerability scanning.

ArgoCD deploys Kubescape from infrastructure/kubescape/.

Terminal window
kubectl -n argocd get applications | rg kubescape
Terminal window
kubectl -n kubescape get pods

Configuration scans:

Terminal window
kubectl get workloadconfigurationscans -A

Image vulnerability scans:

Terminal window
kubectl get vulnerabilitymanifests -A

Edit infrastructure/kubescape/kubescape.yaml to adjust capabilities or namespace filters, then let ArgoCD sync.

The defaults keep admission control and runtime detections disabled to avoid disrupting workloads.