Network Policy Runtime Security IaC & Config Registry RBAC & IAM Secrets Audit & Compliance

20 Featured Tools

01 Network Policy
Trireme-Kubernetes

Implements the Kubernetes Network Policies specification, enforcing fine-grained segmentation between pods and services.

GitHub →
02 Runtime Security
Falco

The de facto Kubernetes threat detection engine — monitors system calls in real time to detect anomalous behaviour and intrusions.

Visit →
03 IaC Security
Snyk IaC

Snyk Infrastructure as Code helps developers write secure Kubernetes and Terraform configurations, catching misconfigurations early in the pipeline.

Visit →
04 Registry
Harbor

Open-source registry that secures container artifacts with policies, role-based access control, vulnerability scanning, and image signing.

Visit →
05 RBAC
Permission Manager

Enables super-easy RBAC management for Kubernetes clusters through a simple web UI and CRD-driven approach.

GitHub →
06 Platform Security
Prisma Cloud

Complete security for Kubernetes from Palo Alto Networks — covering runtime protection, vulnerability management, compliance, and network security.

Visit →
07 Policy Enforcement
k-rail

A workload policy enforcement tool for Kubernetes that validates and blocks non-compliant workloads at admission time.

GitHub →
08 IAM
kube2iam

Provides AWS IAM credentials to containers running inside a Kubernetes cluster, eliminating the need for static key management.

GitHub →
09 IAM
Kiam

Runs as an agent on each node and allows cluster users to associate IAM roles to Pods, providing per-workload AWS credential scoping.

GitHub →
10 Identity & Access
Keycloak

Open-source Identity and Access Management solution — provides SSO, OIDC, OAuth 2.0 and SAML support for Kubernetes workloads.

Visit →
11 RBAC
klum

Kubernetes Lazy User Manager — a simple controller that creates service accounts and manages user access via declarative CRDs.

GitHub →
12 Secrets
SOPS

An editor of encrypted files supporting YAML, JSON, ENV, INI and more — encrypts with AWS KMS, GCP KMS, Azure Key Vault, and PGP.

GitHub →
13 Audit
Kubeaudit

A CLI tool and Go package to audit Kubernetes clusters for various security concerns — covering privilege escalation, AppArmor, network policies and more.

GitHub →
14 Network Policy
illuminatio

The Kubernetes network policy validator — automatically tests whether your network policies behave as expected across all pod combinations.

GitHub →
15 RBAC
audit2rbac

Takes a Kubernetes audit log and username as input, generating RBAC role and binding objects that cover all the API requests made by that user.

GitHub →
16 Compliance
kube-bench

A Go application that checks whether Kubernetes is deployed securely by running the CIS Kubernetes Benchmark checks automatically.

GitHub →
17 Platform Security
Aqua Security

Full-stack Kubernetes security platform covering vulnerability scanning, runtime protection, compliance, and supply chain security.

Visit →
18 Operations
kOps Security

Securing Kubernetes Operations — kOps provides security hardening capabilities for clusters it provisions, covering IAM, encryption, and node security.

Visit →
19 Network Security
Calico

A network security solution for containers, VMs, and native host-based workloads — offering network policy enforcement and micro-segmentation.

Visit →
20 Container Security
NeuVector

Integrated, automated security for containers deployed with Kubernetes — providing zero-trust network security and runtime protection.

Visit →