KSPM · clusters · runtime

Every cluster is
one role from takeover.

Kubernetes multiplies your attack surface — clusters, nodes, pods, service accounts, admission controllers, images. OnDuty KSPM inventories every layer, catches drift the moment it happens, and shows you exactly which containers are reachable at runtime.

Clusters, by the numbers

Every cluster.
One risk graph.

Cluster posture tools stop at YAML. OnDuty ties every RBAC binding, network policy and image vulnerability to what's actually running — so you fix the misconfig that leads to a real pod escape, not the one that just looks scary in a report.

6+

Distros supported

EKS · AKS · GKE · OpenShift · self-managed

1,200+

CIS Benchmark checks

Kubernetes · Docker · nodes

94%

Alerts auto-suppressed

Runtime-reachability aware

9 min

Median cluster onboarding

Read-only service account

Six capabilities, one platform

KSPM, graded by
runtime reachability.

Capability / 01

Cluster & workload inventory

Agentless discovery of every cluster, namespace, node, pod, service account and admission controller — refreshed continuously.

  • Multi-cluster, multi-cloud
  • Namespace ownership mapping
  • Helm & operator awareness
Capability / 02

RBAC & control-plane hardening

Flag over-privileged service accounts, exposed API servers and dangerous cluster-role bindings before they're exploited.

  • Least-privilege graph
  • Anonymous access checks
  • Admission policy gaps
Capability / 03

Image & registry scanning

Scan every image on push and at rest for CVEs, secrets and malware — mapped to the workloads that actually run them.

  • SBOM per image
  • Base-image drift
  • Registry-wide coverage
Capability / 04

Runtime network exposure

eBPF sensors observe real pod-to-pod and pod-to-internet traffic, so you know which network policies actually matter.

  • Live traffic graph
  • Ingress/egress exposure
  • Toxic combination detection
Capability / 05

Shift-left to manifests

Catch misconfigured YAML, Helm charts and Kustomize overlays in CI before they ever reach a cluster.

  • PR checks
  • Policy as code (OPA)
  • Manifest → cluster diffing
Capability / 06

Compliance for containers

Map cluster posture to CIS Kubernetes Benchmark, PCI DSS, SOC 2 and NIST — with audit-ready evidence on demand.

  • CIS Kubernetes Benchmark
  • Custom control packs
  • Continuous evidence

The Cluster Graph

One graph. Every cluster.

Every RBAC binding, image and network path is tied to the workload it protects — so you see the one privilege escalation path that matters, not a thousand disconnected findings.

Explore the dashboard
Cluster graph · org-root · all clusters LIVE
Pod
RBAC
Image
Network

ClusterRoleBinding grants cluster-admin

sa:default/ci-runner · bound cluster-wide · CIS 5.1.1

Pod running as root with hostPath mount

ns:prod-payments/checkout-7f9 · privileged: true

Base image 47 days behind upstream

registry.internal/checkout:1.4.2 · 6 critical CVEs

NetworkPolicy missing on namespace

ns:staging-analytics · unrestricted east-west traffic

The KSPM lifecycle

From cluster scan
to audit-ready.

Phase / 01

Discover

Agentless discovery of every cluster, namespace, workload, image and RBAC binding.

Phase / 02

Evaluate

Run CIS Kubernetes Benchmark and custom Rego policies continuously against live state.

Phase / 03

Correlate with runtime

eBPF sensors confirm which pods, images and network paths are actually reachable.

Phase / 04

Remediate

Auto-route tickets, generate manifest patches and prove compliance with live evidence.

FAQ

Frequently asked questions.

KSPM (Kubernetes Security Posture Management) continuously inventories every cluster, node, pod, service account and image across your fleet, evaluates them against the CIS Kubernetes Benchmark and your own policies, and correlates each finding with what's actually running. Instead of a wall of YAML lint warnings, OnDuty shows the misconfigurations that lead to a real pod escape or cluster takeover.

Secure every cluster before it ships

See the path to takeover,
not the 10,000 lint warnings.

See your real Kubernetes attack paths, RBAC exposure and image risk in a 30-min guided demo with our team.

  • Agentless inventory of every cluster, node, pod & RBAC binding
  • RBAC & control-plane hardening mapped to the CIS Benchmark
  • Image & registry scanning tied to the workloads that run them
  • eBPF runtime reachability that auto-suppresses ~94% of noise
  • Shift-left manifest, Helm & Kustomize checks in every PR