Cluster & workload inventory
Agentless discovery of every cluster, namespace, node, pod, service account and admission controller — refreshed continuously.
- Multi-cluster, multi-cloud
- Namespace ownership mapping
- Helm & operator awareness
Kubernetes multiplies your attack surface — clusters, nodes, pods, service accounts, admission controllers, images. OnDuty KSPM inventories every layer, catches drift the moment it happens, and shows you exactly which containers are reachable at runtime.
Clusters, by the numbers
Cluster posture tools stop at YAML. OnDuty ties every RBAC binding, network policy and image vulnerability to what's actually running — so you fix the misconfig that leads to a real pod escape, not the one that just looks scary in a report.
6+
Distros supported
EKS · AKS · GKE · OpenShift · self-managed
1,200+
CIS Benchmark checks
Kubernetes · Docker · nodes
94%
Alerts auto-suppressed
Runtime-reachability aware
9 min
Median cluster onboarding
Read-only service account
Six capabilities, one platform
Agentless discovery of every cluster, namespace, node, pod, service account and admission controller — refreshed continuously.
Flag over-privileged service accounts, exposed API servers and dangerous cluster-role bindings before they're exploited.
Scan every image on push and at rest for CVEs, secrets and malware — mapped to the workloads that actually run them.
eBPF sensors observe real pod-to-pod and pod-to-internet traffic, so you know which network policies actually matter.
Catch misconfigured YAML, Helm charts and Kustomize overlays in CI before they ever reach a cluster.
Map cluster posture to CIS Kubernetes Benchmark, PCI DSS, SOC 2 and NIST — with audit-ready evidence on demand.
The Cluster Graph
Every RBAC binding, image and network path is tied to the workload it protects — so you see the one privilege escalation path that matters, not a thousand disconnected findings.
Explore the dashboardClusterRoleBinding grants cluster-admin
sa:default/ci-runner · bound cluster-wide · CIS 5.1.1
Pod running as root with hostPath mount
ns:prod-payments/checkout-7f9 · privileged: true
Base image 47 days behind upstream
registry.internal/checkout:1.4.2 · 6 critical CVEs
NetworkPolicy missing on namespace
ns:staging-analytics · unrestricted east-west traffic
The KSPM lifecycle
Agentless discovery of every cluster, namespace, workload, image and RBAC binding.
Run CIS Kubernetes Benchmark and custom Rego policies continuously against live state.
eBPF sensors confirm which pods, images and network paths are actually reachable.
Auto-route tickets, generate manifest patches and prove compliance with live evidence.
FAQ
KSPM (Kubernetes Security Posture Management) continuously inventories every cluster, node, pod, service account and image across your fleet, evaluates them against the CIS Kubernetes Benchmark and your own policies, and correlates each finding with what's actually running. Instead of a wall of YAML lint warnings, OnDuty shows the misconfigurations that lead to a real pod escape or cluster takeover.
Related solutions
OnDuty is one platform on a single graph. Here's where the rest of it connects.
Secure every cluster before it ships
See your real Kubernetes attack paths, RBAC exposure and image risk in a 30-min guided demo with our team.