mrkeyoor.com_
Tue 06 Oct 15:56 UTC
Dev Toolsevaluationupdated 06 Oct 2026

kubescape review

Kubescape is a Kubernetes security scanner that checks manifests, Helm charts, live clusters, and container images for configuration and vulnerability findings. The same project also supplies remediation commands, admission policies, an in-cluster operator, runtime monitoring, and an MCP server for querying stored results.

Verdict

Our Kubescape run passed all 135 tests, but installing and building it took 639 seconds and pulled 1,607 packages, so source-level ownership is substantial. Use the CLI first for manifests and cluster posture, then add the operator or patching only when their extra privileges solve a named problem. A narrower linter is easier to govern if YAML policy is all you need.

We ran it

Lab card: what happened when we ran kubescapeScreenshot of kubescape (kubescape.io)
Install✓ · 170s1607 packages
Build✓ · 469s
Tests✓ · 407s135 passed · 0 failed of 135 (go test)
Repo1755 files~263,290 lines of source · 96.7 MB · 5 CI workflows

Answers from our run

Does kubescape build from source?

Dependencies installed in 170 seconds (1607 packages), and the build succeeded in 469 seconds. We cloned commit f96a146 into a clean Debian container with 3 CPUs and no project-specific setup.

Do kubescape's tests pass?

Yes: 135 of 135 passed when we ran the project's own test command (go test). Some failures need services or credentials a bare container does not have.

Who should not use kubescape?

Teams that only need a small YAML linter: Kubescape also pulls in image scanning, remediation, patching, operator, and runtime concerns.

What are the alternatives to kubescape?

Trivy, Polaris, KubeLinter. Our Kubescape run passed all 135 tests, but installing and building it took 639 seconds and pulled 1,607 packages, so source-level ownership is substantial.

Setup3/5Binaries are simple; our source install and build took 639 seconds
Docs5/5Commands, outputs, offline use, operator, and access needs are clear
Community5/511,769 stars, a September release, and an October 6 push
Maturity4/5v4.0.15 is active and 135 tests passed in our sandbox

Who it’s for

Kubernetes teams that want one CLI for local manifest checks and live-cluster posture scans.
Platform engineers who need JSON, JUnit, SARIF, HTML, PDF, or CSV reports in CI.
Cluster operators prepared to deploy the Helm operator for continuous scans and runtime visibility.
Air-gapped teams willing to download frameworks and a Grype database ahead of time.
MCP users who want an assistant to read Kubescape configuration and vulnerability results.

Who it’s NOT for

Teams that only need a small YAML linter: Kubescape also pulls in image scanning, remediation, patching, operator, and runtime concerns.
CI jobs that may scan untrusted Helm charts without isolation: open issue 4009 reports dependency downloads and writes inside the scanned tree.
Operators who expect image patching to be unprivileged: the documented path starts BuildKit and runs the patch command with sudo.
Anyone who wants auto-fix to change a live cluster directly: the README says cluster fixes are printed and must be piped into kubectl deliberately.
Organizations unable to grant cluster read access or protect exported reports: live scans need Kubernetes access, and reports can contain sensitive metadata unless hidden or encrypted.

Setup reality

Our fresh Debian sandbox installed commit f96a146 in 170 seconds, adding 1,607 packages. The build succeeded in 469 seconds. Go test completed in 407 seconds with 135 passed and 0 failed out of 135.

Local manifest scans do not need a hosted account or cluster credential. Live scans need kubeconfig access, private image scans may need registry credentials, and encrypted reports require a master key of at least 16 characters. Image patching also needs BuildKit and the documented commands use sudo.

The standalone CLI is the small operational starting point. Continuous scanning adds a Helm-installed operator, Custom Resources, image scanning components, and optional eBPF node agents. Offline use requires downloading scan artifacts and, for image checks, serving a local Grype database.

The CLI covers manifests, clusters, images, and reports

Kubescape can check a YAML directory before deployment, inspect a live Kubernetes cluster, or scan a container image. Policy packs include NSA-CISA guidance, MITRE ATT&CK mappings, and CIS benchmarks. Results can go to the terminal or to JSON, JUnit XML, SARIF, HTML, PDF, and CSV files. That range makes the CLI useful in a developer shell and a CI job without forcing the in-cluster operator on day one.

The commands do more than report. fix can rewrite manifest files, although it has a dry-run mode and can put changed copies in a separate directory. A cluster fix is printed rather than applied, so an operator must explicitly pipe it to kubectl apply. Image patching uses Copacetic and needs a running BuildKit daemon; the README's example starts and invokes those steps with sudo. Each mode deserves its own permissions and review policy.

What happened when we ran it

Our sandbox installed commit f96a146 in 170 seconds and added 1,607 packages. Building took another 469 seconds. Go test finished in 407 seconds with 135 passed and 0 failed out of 135. The unprivileged Debian container had 3 CPUs, 8 GB of RAM, Go 1.24, and no secrets. The successful suite is useful evidence for the repository path we ran, not proof that every cluster integration will work.

The checkout itself held 1,755 files, about 263,290 lines of source, and occupied 96.7 MB. We found 5 CI workflow files, no Dockerfile, and no top-level tests directory. A clean 135-test run shows that test code still exists in the Go packages. The 469-second build and 407-second suite also make source work expensive enough to cache carefully in CI rather than rebuilding the entire tool for every policy change.

Manifest scans need less trust than live-cluster scans

Scanning local manifests can run without a Kubernetes credential or Kubescape account. A live scan needs a kubeconfig with access to the resources being assessed. Private image checks may need registry credentials. Reports can reveal object names and other cluster metadata, so --hide pseudonymizes fields, while encrypted JSON reports use KUBESCAPE_MASTER_KEY with a minimum of 16 characters. Those controls should be selected before reports enter CI artifacts.

Helm input needs another precaution. Open issue 4009, filed October 1, 2026, reports that scanning a chart can fetch dependencies and write a charts directory or lockfile changes into the scanned tree. An open pull request addresses vendored dependencies, but it was not merged when we checked. Treat third-party charts as active build input: scan them in a disposable checkout with outbound access controlled, then verify the working tree afterward.

Continuous monitoring adds cluster components and eBPF access

The Helm operator changes Kubescape from an on-demand tool into a cluster service. It watches resources, triggers configuration and image scans, and stores findings in Custom Resources. Runtime visibility adds a node agent using eBPF through Inspektor Gadget. Network observations and behavior profiles become more useful over time, but the installation now touches cluster-wide control paths and nodes rather than one CI container.

The architecture guide names separate pieces for the operator, image vulnerability work, host data, result storage, and the node agent. Prometheus can consume metrics from that deployment. Start with the CLI until continuous findings have an owner and retention plan. Then define which namespaces each component can read, who can inspect the result CRDs, and whether node-level runtime collection is allowed under your cluster policy.

The MCP server reads stored security findings

kubescape mcpserver exposes 5 documented tools for vulnerability manifests, individual CVEs, and configuration scan records. This can help an assistant answer questions about existing Kubescape output. It also makes security findings available through another protocol endpoint. Bind it narrowly, require the same access controls as the underlying reports, and do not assume that natural-language access makes a finding safe to disclose.

The MCP surface is read-oriented in the README, while remediation remains in explicit CLI commands. That separation is good. Keep it. An assistant can summarize a failed control, but a human-reviewed pipeline should decide whether to rewrite a manifest, deploy a Validating Admission Policy, or patch an image. Kubescape's own cluster-fix flow already models that boundary by printing changes for a separate kubectl apply.

v4.0.15 and an October 6 push show active maintenance

GitHub showed 11,769 stars and 51 open issues and pull requests on October 6, 2026. Search split that total into 29 issues and 22 pull requests. The repository was pushed that day, and v4.0.15 had shipped on September 29. The release included changes across scanning, report handling, image support, fleet summaries, MCP tests, and policy evaluation, which also explains why this is much larger than a single-purpose linter.

Kubescape is a strong choice when Kubernetes security posture is the actual job and a team can own the access it receives. Our 135 passing tests support trying the CLI, while the 1,607-package install and long source build argue against casual customization. Run the least privileged mode first. Add automated fixes, image patching, the operator, eBPF collection, or MCP access only after assigning an owner to each new action and data path.

Alternatives

ProjectWhat it isPick it when
Trivy gh↗A scanner for vulnerabilities, misconfigurations, secrets, SBOMs, images, repositories, and Kubernetes.pick this instead when artifact and image scanning across several environments matters more than Kubescape's Kubernetes posture workflow.
PolarisA Kubernetes best-practice validator available as a dashboard, admission controller, or command-line tool.pick this instead when workload configuration checks and admission are enough, without the wider runtime and image toolchain.
KubeLinterA static analyzer for Kubernetes YAML and Helm charts with configurable checks.pick this instead when you want a focused manifest linter for developer feedback and CI.

What people are saying

  1. [github-trending] kubescape/kubescape

Sources

  1. Kubescape repository and README
  2. Kubescape architecture guide
  3. Kubescape v4.0.15 release
  4. Issue 4009: Helm chart scan network and workspace behavior

More dev tools reviews

amass · rea · grokbot-field-notes · abide · dsh-echocat-skill-panel · Compositor · the whole board →