Skip to main content10ETLabsRequest demo

Containers

Container & Kubernetes Security

Clusters are cloud resources. Score them with the rest of the estate.

10ETLabs lists EKS clusters and ECR repositories through your AWS reader role, AKS clusters through Azure Resource Graph, and GKE clusters through Cloud Asset Inventory on your GCP connection. For workload-level checks on any cluster — EKS, AKS, GKE, or self-managed — you connect its Kubernetes API with a read-only service-account token. Public LoadBalancers, privileged or hostNetwork pods, public EKS, AKS, and GKE API endpoints, AKS clusters without RBAC or with local accounts, GKE legacy ABAC and static credentials, and ECR repositories without scan-on-push show up as findings next to VMs and buckets — one queue, not a bolt-on K8s console. All of that is agentless. If you want more, an optional Helm chart adds a runtime sensor (what AI workloads actually do: shells in model servers, instance-metadata access, unexpected egress, miners) and an admission webhook that warns or blocks risky deploys, with a simulate view before you enforce.

Container and cluster operations on a workstation

Containers

EKS and AKS from your cloud roles, plus any Kubernetes API you connect with a reader token — clusters as cloud resources.

See it work

Every cloud’s findings, one ranked queue

Findings from each provider share one shape, then 10ET Score orders them by exposure and blast radius.

Many clouds · one ranked queue

01Scan each cloud

Posture jobs list each connected provider’s control plane with its reader role or token — AWS deepest, then Azure, GCP, and Kubernetes.

Sample findings using real rule titles. Scores follow the 10ET Score formula.

What you get

Cluster and registry inventory

EKS clusters and ECR repositories from AWS, AKS clusters from Azure, GKE clusters from GCP, and nodes, services, deployments, and pods from any Kubernetes API you connect with a token.

Public API endpoints

Public EKS API endpoints, AKS and GKE API servers with no authorized IP ranges, and public LoadBalancer services are treated as exposure.

Registry gaps

ECR repositories without scan-on-push are flagged. Other registries (ACR, Artifact Registry) are not assessed in this release.

Optional runtime sensor, honestly scoped

A small DaemonSet samples /proc and the Kubernetes API on each node (not eBPF): shells in model-serving containers, IMDS access, egress to deny-listed or unapproved addresses, miners, and privileged or hostPath pods actually running. Metadata only — never file contents, environment values or request bodies. Short-lived activity between samples can be missed.

Admission policy with simulate

An optional ValidatingAdmissionWebhook enforces, warns or audits per policy — privileged, host namespaces, hostPath, root, limits, untrusted registries, :latest, public model servers, GPU namespaces, cluster-admin notebooks. Simulate against the last N days of inventory first. Fails open by default.

In this module

  1. Step 1

    Read cluster APIs

    The worker lists cluster resources the service-account token can read, plus EKS and ECR through your AWS role.

  2. Step 2

    Flag exposure

    Public services, privileged pods, public EKS / AKS / GKE endpoints, weak AKS and GKE cluster auth, and ECR scan-on-push gaps become findings.

  3. Step 3

    See them with the estate

    Open K8s & containers or inventory filtered by category. Container findings are ranked by 10ET Score; cluster hops join attack paths only when the optional sensor observed them (for example a public service → a pod with a shell and IMDS access → node credentials).

In this release

  • EKS, AKS, GKE, and connected-cluster inventory
  • Optional runtime sensor and admission webhook (Helm), with policy simulate and signed policy bundles
  • Public service, privileged pod, EKS / AKS / GKE endpoint, AKS RBAC and local-account, GKE ABAC / static-credential / Shielded Nodes, and ECR scan-on-push checks
  • Shared 10ET Score with the rest of 10ETLabs
Request a demo

On the roadmap

  • ACR and Artifact Registry posture
  • eBPF syscall-level runtime sensor

Labeled roadmap for this module only. Site-wide scope is on Trust and FAQ.

More of the platform

Other modules — not a reprint of this page.