Kubernetes Security
Compare 152 kubernetes security tools to find the right one for your needs
📂 Subcategories
🔧 Tools
Compare and find the best kubernetes security for your needs
Doppler
A universal secrets manager that helps developers and security teams manage secrets across all environments.
Styra Declarative Authorization Service (DAS)
An enterprise management plane for Open Policy Agent (OPA).
ARMO (Kubescape)
An open-source Kubernetes security platform for risk analysis, compliance, and misconfiguration scanning.
Wiz
A cloud security platform that provides complete visibility and context into your cloud environment to help you identify and remediate the most critical risks.
Styra Declarative Authorization Service (DAS)
An enterprise-grade control plane for Open Policy Agent (OPA) that provides a management and visibility layer for policy enforcement.
Lacework
A CNAPP that uses anomaly detection to identify threats across cloud environments.
StrongDM
A platform that manages and audits access to databases, servers, clusters, and web apps.
Fairwinds Insights
A software platform that helps you enforce policies, detect misconfigurations, and manage security risks in your Kubernetes clusters.
SentinelOne
An autonomous AI-driven cybersecurity platform for endpoint, cloud, and identity.
CrowdStrike Falcon Cloud Security
A unified platform that provides comprehensive protection for the entire cloud estate, from development to production.
Teleport
An identity-native infrastructure access platform.
Sysdig
A cloud security platform that provides threat detection, compliance, and forensics.
Kubescape
An open-source Kubernetes security platform that provides configuration scanning based on multiple frameworks, including NSA-CISA, MITRE ATT&CK, and CIS.
Akeyless Vault Platform
A unified, SaaS-based platform for secrets management, secure remote access, and data protection.
CrowdStrike Falcon Cloud Security
A unified platform for complete code-to-cloud protection.
Orca Security
An agentless cloud security platform that provides 100% visibility into your cloud environment and identifies risks without the need for agents.
Snyk
Helps developers find and fix vulnerabilities in code, dependencies, containers, and IaC.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine for unified policy enforcement.
Infisical
An open-source platform to centralize secrets like API keys, database credentials, and configurations.
Wiz
A CNAPP that provides full-stack visibility and risk context for cloud environments.
Uptycs
A security analytics platform that provides unified visibility, threat detection, and compliance for your entire IT environment.
Snyk
A developer-first security platform that helps you find and fix vulnerabilities in your code, open source dependencies, containers, and IaC.
Tufin
A security policy management company specializing in automation.
Kyverno
A policy engine designed specifically for Kubernetes.
Keeper Secrets Manager
A fully managed, cloud-based solution for securing infrastructure secrets such as API keys, database passwords, and access keys.
Uptycs
A unified CNAPP and XDR platform for cloud, container, and endpoint security.
Dynatrace Application Security
An application security solution that provides visibility, threat detection, and response for cloud-native applications.
NeuVector
A container security platform providing deep visibility, vulnerability scanning, and run-time protection.
Sysdig
A cloud security platform that provides threat detection, compliance, and forensics for containers, Kubernetes, and cloud.
rbac-manager
An open-source Kubernetes operator for simplified RBAC management.
1Password Secrets
A secrets management solution from the popular password manager 1Password, designed for developers and DevOps teams.
Datadog Cloud Security Platform
Provides security monitoring and threat detection integrated with its observability platform.
Snyk
A developer-first security platform for finding and fixing vulnerabilities in code, dependencies, and containers.
Datadog Cloud Security Platform
Provides a unified platform for security, compliance, and threat detection in the cloud.
Prisma Cloud by Palo Alto Networks
A comprehensive cloud security platform that provides security and compliance coverage for the entire cloud-native application lifecycle.
Teleport
An identity-native infrastructure access platform for engineers and security professionals.
Rapid7 InsightCloudSec
A CNAPP for managing security, compliance, and governance from development to production.
Orca Security
An agentless CNAPP that provides full-stack visibility into cloud environments.
Sysdig Secure
A comprehensive cloud-native application protection platform (CNAPP) that provides security from source to run.
Aqua Security
A comprehensive security platform for Kubernetes, offering runtime protection, vulnerability scanning, and compliance management.
HashiCorp Vault
A tool for managing secrets and protecting sensitive data. It provides a centralized service to manage secrets across applications, systems, and infrastructure.
VMware Carbon Black
An endpoint and workload protection platform.
Lacework
A CNAPP that uses behavioral analytics to detect threats across cloud environments.
Zscaler for Workloads
A cloud security solution that provides zero trust security for cloud workloads.
Rapid7 InsightCloudSec
A Cloud-Native Application Protection Platform (CNAPP) that provides unified visibility, risk management, and compliance.
Snyk Container
A developer-friendly tool for finding and fixing vulnerabilities in container images and Kubernetes applications.
Delinea Secret Server
A solution for storing, managing, and auditing privileged accounts and credentials.
Dynatrace
A software intelligence platform for observability, AIOps, and application security.
SUSE NeuVector
A container security platform that provides vulnerability scanning, compliance, and zero-trust runtime security.
Aqua Security
Provides a full lifecycle security solution for cloud-native applications.
Lacework
A cloud security platform that provides automated threat detection, configuration compliance, and workload protection for cloud-native environments.
AWS Secrets Manager
A secrets management service that helps you protect access to your applications, services, and IT resources.
Sysdig
A cloud-native security platform for containers, Kubernetes, and cloud services.
Palo Alto Networks Prisma Cloud
A comprehensive CNAPP for code-to-cloud security in any cloud environment.
Zscaler
A cloud security company providing a Zero Trust Exchange platform for secure access to applications and data.
Datree
A command-line tool that helps you prevent misconfigurations in your Kubernetes manifests by running automated checks.
Deepfence ThreatMapper
An open-source platform that provides security observability for cloud-native applications, from development to production.
Armo Kubescape
An open-source platform for testing if Kubernetes is deployed securely.
Cilium
An open-source project that provides networking, observability, and security for cloud-native environments using eBPF.
SentinelOne Singularity Cloud Security
A cloud-native application protection platform (CNAPP) that provides unified visibility, threat protection, and response for cloud workloads.
Deepfence ThreatStryker
An open-source security observability platform that provides visibility, threat detection, and compliance for cloud-native environments.
Illumio
Provides zero trust segmentation to stop the spread of breaches and ransomware.
Twistlock
A comprehensive security platform for containers, serverless, and cloud-native applications, now part of Prisma Cloud.
StackRox
An open-source, Kubernetes-native security platform, the upstream project for Red Hat Advanced Cluster Security.
Snyk
A developer-first security platform that helps you find and fix vulnerabilities in your code, open source dependencies, containers, and infrastructure as code.
Rapid7 InsightCloudSec
A cloud-native security platform that provides unified visibility, security, and compliance across multi-cloud environments.
Datadog Cloud Security Management
A cloud security platform that combines security and observability to provide deep visibility and threat detection for cloud-native environments.
Sysdig Secure
A unified security and visibility platform for containers and Kubernetes, offering runtime security, vulnerability management, and compliance.
Red Hat Advanced Cluster Security for Kubernetes (ACS)
A Kubernetes-native security platform that protects applications across the build, deploy, and run phases.
NeuVector by SUSE
A container security platform that provides deep visibility, vulnerability scanning, and run-time protection for Kubernetes.
Lacework
A cloud security platform that provides automated threat detection, compliance, and visibility for cloud-native environments.
Red Hat Advanced Cluster Security for Kubernetes
A Kubernetes-native security platform that provides a holistic view of your clusters and helps enforce policies across the build, deploy, and runtime stages.
Azure Key Vault
A cloud service for securely storing and accessing secrets, such as API keys, passwords, or certificates.
Fortanix Data Security Manager
A unified platform for data security that includes secrets management, key management, and tokenization.
Google Cloud Secret Manager
A secure and convenient storage system for API keys, passwords, certificates, and other sensitive data.
CyberArk Conjur
A secrets management solution tailored for the unique requirements of native cloud, containers, and DevOps.
Check Point CloudGuard
A unified cloud native security platform from Check Point.
Zscaler
A cloud security company providing a Zero Trust platform.
Palo Alto Networks (Prisma Cloud)
A comprehensive CNAPP that provides security from code to cloud.
Red Hat Advanced Cluster Security for Kubernetes
A Kubernetes-native security platform that protects applications across the build, deploy, and runtime phases.
Rapid7
A cybersecurity company providing solutions for security operations (SecOps).
Aqua Security
A comprehensive security platform for cloud-native applications, from development to production.
Prisma Cloud
A security platform that provides comprehensive protection for cloud-native applications.
Tigera Calico
An open-source networking and network security solution for containers, virtual machines, and native host-based workloads.
NeuVector
A container security platform that provides real-time visibility, threat detection, and vulnerability management for Kubernetes environments.
Sophos Cloud Workload Protection
A cloud security solution that provides visibility, threat detection, and response for cloud-native environments.
Palo Alto Networks Prisma Cloud
A comprehensive CNAPP that provides security and compliance coverage for the entire cloud-native application lifecycle.
Zscaler Workload Communications
Provides zero trust security for communications between cloud workloads.
Capsule8
A runtime security platform for Linux environments, now part of Sophos.
Tenable.cs
A cloud-native application protection platform (CNAPP) that provides security for the entire cloud-native stack.
Check Point CloudGuard
A unified cloud-native security platform that provides automated security and compliance for assets, workloads, and applications across the cloud.
Zscaler Cloud Protection
A comprehensive cloud security platform that provides unified visibility, security, and compliance for multi-cloud environments.
F5 Distributed Cloud Services
A platform that provides a suite of security, networking, and application management services for multi-cloud and edge environments.
GitLab Container Security
A set of security features integrated into the GitLab DevOps platform to help you find and fix vulnerabilities in your container images.
Zscaler Posture Control
A CNAPP that helps you secure your cloud-native applications by providing visibility, security, and compliance across your entire cloud environment.
Alcide
A Kubernetes security platform that provides configuration and compliance scanning, as well as runtime security.
Calico
An open-source networking and network security solution for containers, virtual machines, and native host-based workloads.
Palo Alto Networks Prisma Cloud
A comprehensive cloud security platform that provides security and compliance coverage for hosts, containers, and serverless, from development to production.
Tigera (Calico)
Provides networking, observability, and security for containers and Kubernetes.
Tenable
A cybersecurity company providing solutions for exposure management.
Check Point CloudGuard
A unified cloud-native security platform for threat prevention and posture management.
Zscaler
A cloud security company that provides a Zero Trust Exchange platform.
Falco
Open-source tool for real-time intrusion and abnormality detection in cloud-native environments.
Red Hat Advanced Cluster Security for Kubernetes
A Kubernetes-native security platform that provides visibility, vulnerability management, and compliance for containerized applications.
Qualys Cloud Agent
A lightweight agent that provides continuous visibility, security, and compliance for your IT assets, wherever they are.
Tenable Cloud Security
A cloud-native application protection platform (CNAPP) that provides unified visibility and security for the entire cloud stack.
Cisco Cloud Native Security (Panoptica)
A cloud-native application protection platform (CNAPP) that provides end-to-end security for cloud-native applications.
Tigera Calico
An open-source networking and network security solution for containers, virtual machines, and native host-based workloads.
Aqua Security
A full-lifecycle security platform for cloud-native applications.
Datadog
An observability platform that includes security monitoring capabilities.
Qualys
A cloud-based platform for IT, security, and compliance.
Anchore
A software supply chain security platform that helps you identify and remediate security risks in your containerized applications.
Datadog
A monitoring and security platform for cloud applications, providing observability, security, and analytics.
Datadog Cloud Security Platform
A unified platform that brings together security, monitoring, and observability for cloud-native environments.
Tracee
An open-source runtime security and forensics tool for Linux, built by Aqua Security.
Cilium Tetragon
An open-source security observability and runtime enforcement tool for Kubernetes.
Kyverno
A policy engine designed specifically for Kubernetes that uses simple YAML configurations to define and enforce policies.
Open Policy Agent (OPA) / Gatekeeper
A general-purpose policy engine that can be used across the stack. Gatekeeper is its specialized Kubernetes admission controller.
Polaris
An open-source tool that runs a variety of checks to ensure that Kubernetes pods and controllers are configured using best practices.
KubeLinter
An open-source command-line tool that spots misconfigurations in Kubernetes objects by reviewing YAML files and Helm charts.
Checkov
A static code analysis tool that scans infrastructure as code (IaC) for misconfigurations.
jsPolicy
An open-source policy engine for Kubernetes that lets users build policies using JavaScript or TypeScript.
Cilium
An open-source project that provides networking, observability, and security for cloud-native environments using eBPF.
KubeArmor
A CNCF sandbox project that provides runtime security enforcement for Kubernetes using LSMs.
K-Rail
An open-source policy enforcement tool for Kubernetes that helps you secure a multi-tenant cluster with minimal disruption.
MagTape
An open-source admission controller from T-Mobile for validating and mutating resources based on annotations.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine that can be used to enforce policies across the stack.
Gatekeeper
A customizable admission webhook for Kubernetes that enforces policies executed by the Open Policy Agent (OPA).
Falco
An open-source runtime security tool that detects unexpected application behavior, configuration changes, and security events in Kubernetes clusters.
Trivy
A comprehensive, open-source vulnerability scanner for containers and other artifacts, and can identify misconfigurations in Kubernetes manifests.
Kube-bench
An open-source tool that checks whether Kubernetes is deployed securely by running the checks documented in the CIS Kubernetes Benchmark.
Terrascan
An open-source static code analyzer that scans infrastructure as code (IaC) for security vulnerabilities and compliance violations.
Kube-hunter
An open-source tool that runs penetration tests on Kubernetes clusters to discover security vulnerabilities.
Kube-scan
An open-source tool that scans Kubernetes clusters for risks and provides a risk score for each workload.
Kube-score
An open-source tool that performs static analysis of Kubernetes object definitions to find security and reliability issues.
Calico
Provides networking, network policy, and observability for Kubernetes.
Cilium
Provides networking, observability, and security for cloud-native environments using eBPF.
Open Policy Agent (OPA)
An open source, general-purpose policy engine that unifies policy enforcement across the stack.
Kyverno
A policy engine designed specifically for Kubernetes.
Antrea
An open-source CNI plugin for Kubernetes focused on performance and security.
Weave Net
A CNI plugin for Kubernetes that creates a virtual network for containers.
Sealed Secrets
An open-source tool that allows you to encrypt Kubernetes Secrets, which can then be safely stored in a public Git repository.
SOPS (Secrets OPerationS)
An open-source editor for encrypted files that helps you manage secrets in a GitOps-friendly way.
External Secrets Operator
A Kubernetes operator that reads information from external secret management systems and automatically injects the values into Kubernetes Secrets.
Secrets Store CSI Driver
A Kubernetes CSI driver that allows you to mount secrets from external stores as volumes in your pods.
Cisco Panoptica
A security platform for cloud-native applications, from development to runtime.
Kube-router
An all-in-one networking solution for Kubernetes.
Kamus
An open-source tool for encrypting secrets for specific applications running in Kubernetes.
Berglas
An open-source tool from Google for managing secrets on Google Cloud Platform, particularly with services like Google Kubernetes Engine and Cloud Run.
git-secret
An open-source bash script that allows you to encrypt and store secrets in a Git repository.
Trousseau
An open-source Kubernetes KMS provider that allows you to encrypt Kubernetes secrets using a key from a remote KMS.
Keywhiz
An open-source secrets management system developed by Square.