aicoolies logo
Kubescape logo
Kubescape logo

Kubescape

Open-source Kubernetes security platform for risk analysis and compliance

open sourceupdated Aug 16, 2026

Kubescape is a CNCF-backed open-source Kubernetes security platform that scans clusters, manifests, and container images for vulnerabilities, misconfigurations, and compliance violations. It checks against NSA-CISA, MITRE ATT&CK, and CIS benchmarks, integrates into CI/CD pipelines, and provides runtime threat detection via eBPF. Supports SBOM generation and vulnerability scanning. Used by ARMO with growing enterprise adoption in cloud-native security.

Read our Kubescape review

A detailed review by the aicoolies team — click to read

Kubescape provides comprehensive Kubernetes security coverage across the entire development lifecycle. In CI/CD, it scans Helm charts, Kubernetes manifests, and Dockerfiles against security frameworks including NSA-CISA hardening guidelines, MITRE ATT&CK for containers, and CIS Kubernetes Benchmarks. Each finding includes severity scoring and actionable remediation steps, enabling teams to catch misconfigurations before they reach production.

At runtime, Kubescape uses eBPF-based monitoring to detect anomalous behavior in running workloads — unexpected network connections, file system modifications, process executions, and privilege escalation attempts. The integrated vulnerability scanner assesses container images against known CVE databases and generates Software Bill of Materials (SBOM) for supply chain compliance. Results aggregate into a risk score per workload, namespace, and cluster.

Kubescape is Apache 2.0 licensed and maintained within the CNCF ecosystem alongside projects like Falco and OPA. It integrates with Prometheus for metrics, Slack for alerts, and popular CI systems including GitHub Actions, GitLab CI, and Jenkins. For teams needing a managed experience, ARMO Platform provides a SaaS dashboard with historical trends and multi-cluster visibility. The CLI can be installed via Homebrew, curl, or Krew kubectl plugin.

Pricing

Free open-source; ARMO Platform managed plans available

Platforms

CLI, CI/CD plugins, Kubernetes operator, ARMO SaaS

Categories

Tags

Use Cases

Related Tools

computed discovery: shared active categories · kept separate from editor-verified Alternatives

KTransformers parent kvcache-ai logo

KTransformers

Heterogeneous CPU-GPU inference and SFT for large MoE models

Open-source framework for running and fine-tuning large Mixture-of-Experts models with heterogeneous CPU-GPU execution, optimized kernels, limited VRAM and SGLang or LLaMA-Factory integrations.

Open Source
vLLM Production Stack parent vLLM logo

vLLM Production Stack

Official Kubernetes and Helm reference stack built on the vLLM inference engine

Official vLLM reference implementation for scaling the existing inference engine on Kubernetes with Helm, request routing, KV-cache offload, autoscaling and Prometheus/Grafana observability.

Open Source
Dynamo logo

NVIDIA Dynamo

Distributed inference orchestration above vLLM, SGLang and TensorRT-LLM

Open-source, datacenter-scale orchestration layer that coordinates vLLM, SGLang and TensorRT-LLM across nodes with disaggregated serving, KV-aware routing, multi-tier cache management and automatic scaling.

Open Source
GPUStack logo

GPUStack

Open-source GPU control plane for scalable AI model serving

Open-source GPU cluster manager that configures vLLM, SGLang, TensorRT-LLM or custom engines, serves models through compatible APIs, and provisions SSH-accessible GPU instances across on-premises, Kubernetes and cloud environments.

Open Source
Mooncake logo

Mooncake

Disaggregated KV cache storage and transfer for LLM serving

Open-source infrastructure for disaggregated LLM serving that pools KV caches across prefill and decode workers, with high-performance transfer, distributed storage and integrations for vLLM and SGLang.

Open Source
ToolHive mascot logo

ToolHive

Run and govern MCP servers across desktop, CLI and Kubernetes

Open-source MCP runtime and governance platform that runs servers in isolated containers, curates registries, enforces access policies, and operates gateways across desktop, CLI, and Kubernetes.

Open Source

Used in Stacks

FAQ

What is Kubescape?

Kubescape is a CNCF-backed open-source Kubernetes security platform that scans clusters, manifests, and container images for vulnerabilities, misconfigurations, and compliance violations. It checks against NSA-CISA, MITRE ATT&CK, and CIS benchmarks, integrates into CI/CD pipelines, and provides runtime threat detection via eBPF. Supports SBOM generation and vulnerability scanning. Used by ARMO with growing enterprise adoption in cloud-native security.

Is Kubescape free?

Yes — Kubescape is open source and free to use. Free open-source; ARMO Platform managed plans available

Is Kubescape open source?

Yes — Kubescape is open source.

What are the best Kubescape alternatives?

The top editor-verified Kubescape alternatives are Mindgard, mirrord.

How does Kubescape score in our review?

Our hands-on review scores Kubescape 81/100 overall, based on speed, privacy, and developer-experience testing.