Kubescape
Open-source Kubernetes security platform covering misconfiguration scanning, image vulnerabilities, compliance checks and runtime monitoring.
- GitHub stars
- 12k
- Last commit
- today
- Latest release
- v4.0.15
- Licence
- Apache-2.0
- Self-hosted
- Yes

Kubescape is an open-source Kubernetes security platform that covers the lifecycle from development to runtime. It was created by ARMO and is a Cloud Native Computing Foundation incubating project. It works in an IDE, in CI/CD pipelines and against running clusters, with the aim of saving administrators time on risk analysis and compliance work.
Misconfiguration scanning checks clusters, YAML files and Helm charts against NSA-CISA guidance, MITRE ATT&CK and CIS Benchmarks. Image vulnerability scanning detects CVEs using Grype, image patching uses Copacetic, and auto-remediation can fix manifest issues. Admission control uses Validating Admission Policies, runtime monitoring is eBPF-based through Inspektor Gadget, and an MCP server connects AI assistants.
Kubescape is written in Go and released under the Apache-2.0 license. It installs through options such as Homebrew and Krew, and an in-cluster operator is available for continuous scanning. Results include an overview of control plane status, access control risks, workload misconfigurations, network policy gaps and compliance scores.
Key features
- Misconfiguration scanning against NSA-CISA, MITRE, CIS
- Image vulnerability scanning with Grype
- Automatic image patching with Copacetic
- Auto-remediation for Kubernetes manifests
- eBPF-based runtime security monitoring
- In-cluster operator and MCP server
Pricing: Free and open source under the Apache-2.0 license.



