Skip to main content
Version: 1.0

Security Services

The security pipeline consists of three cooperating services: security-cron, security-collector, and security-api. Together they provide continuous vulnerability scanning, configuration analysis, and a compliance posture score.

Architecture​

Security pipeline

Scan → findings → posture score and incidents. Select any service for details.

SecurityFinding
security-cron triggers security-collector, which publishes findings for security-api and incident-manager.

security-cron​

A scheduled job service. On a configurable interval (default: every 6 hours), it sends a trigger message to security-collector to initiate a new scan cycle. Supports manual trigger via POST /api/v1/scan/trigger.

security-collector​

Executes the actual scanning against connected clusters:

  • Vulnerability scanning — checks container images against CVE databases
  • RBAC analysis — identifies overly permissive ClusterRoleBindings and wildcard permissions
  • Network policy gaps — finds namespaces with no NetworkPolicy defined
  • CIS benchmark checks — evaluates pod security contexts, privilege escalation settings, host path mounts

Findings are structured as SecurityFinding records (resource, category, severity, recommendation) and published to the security.posture RabbitMQ exchange.

security-api​

Port: 8086 · DB Schema: security

Stores all findings and serves the security posture API:

MethodPathDescription
GET/api/v1/posture/summaryOverall compliance score, severity counts
GET/api/v1/findingsAll findings with filters
GET/api/v1/findings/{id}Finding detail with remediation steps
POST/api/v1/findings/{id}/acknowledgeMark finding reviewed
GET/api/v1/scansScan history
POST/api/v1/scan/triggerTrigger manual scan

Compliance Score​

The posture score (0–100) is calculated as:

score = 100 - (critical × 20 + high × 10 + medium × 3 + low × 1)

Clamped to 0. The score is returned in the /posture/summary response alongside category breakdowns (vulnerabilities, configuration, RBAC, network).

Environment Variables​

VariableDescription
DATABASE_URLPostgreSQL connection
RABBITMQ_URLRabbitMQ connection
SCAN_INTERVALHow often security-cron triggers a scan (default: 6h)
KUBECONFIGPath to kubeconfig for cluster access (or uses in-cluster config)