CRJun 23

A Comparison of Kubernetes Compliance Standards and Configuration Scanners

arXiv:2606.244383.0
Predicted impact top 85% in CR · last 90 daysOriginality Synthesis-oriented
AI Analysis

For Kubernetes practitioners and security tool developers, this work reveals inconsistencies in existing guidelines and scanners, but the contribution is incremental as it primarily documents known issues.

The paper compares eight Kubernetes hardening guidelines and evaluates ten static configuration scanners, finding substantial disparities in coverage and scoring of configuration issues, highlighting the need for standardized assessment approaches.

Kubernetes has become the industry standard for orchestrating containers in microservice-based software architectures. While several hardening guidelines and scanning tools for securing Kubernetes clusters and deployments have emerged in recent years, their differing guidance and outputs often lead to inconsistent configuration and prioritization decisions. This work presents a systematic comparison of eight commonly used Kubernetes hardening guidelines. Through this comparison and the inclusion of best practices, we established a benchmark of 79 Kubernetes configuration recommendations and conducted the a structured empirical evaluation of ten popular static configuration scanning tools and their scoring outputs. Our findings reveal substantial disparities in the coverage of configuration issues across hardening guidelines and scanners, as well as inconsistencies in how configuration issues are scored and ranked by different scanners. These results highlight the need for more standardized, transparent, and consistent approaches to risk and severity assessment of Kubernetes configuration issues.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes