Security Services
The security pipeline consists of three cooperating services: security-cron, security-collector, and security-api. Together they provide continuous vulnerability scanning, configuration analysis, and a compliance posture score.
Architecture
Security pipeline
Scan → findings → posture score and incidents. Select any service for details.
security-cron
A scheduled job service. On a configurable interval (default: every 6 hours), it sends a trigger message to security-collector to initiate a new scan cycle. Supports manual trigger via POST /api/v1/scan/trigger.
security-collector
Executes the actual scanning against connected clusters:
- Vulnerability scanning — checks container images against CVE databases
- RBAC analysis — identifies overly permissive ClusterRoleBindings and wildcard permissions
- Network policy gaps — finds namespaces with no NetworkPolicy defined
- CIS benchmark checks — evaluates pod security contexts, privilege escalation settings, host path mounts
Findings are structured as SecurityFinding records (resource, category, severity, recommendation) and published to the security.posture RabbitMQ exchange.
security-api
Port: 8086 · DB Schema: security
Stores all findings and serves the security posture API:
| Method | Path | Description |
|---|---|---|
GET | /api/v1/posture/summary | Overall compliance score, severity counts |
GET | /api/v1/findings | All findings with filters |
GET | /api/v1/findings/{id} | Finding detail with remediation steps |
POST | /api/v1/findings/{id}/acknowledge | Mark finding reviewed |
GET | /api/v1/scans | Scan history |
POST | /api/v1/scan/trigger | Trigger manual scan |
Compliance Score
The posture score (0–100) is calculated as:
score = 100 - (critical × 20 + high × 10 + medium × 3 + low × 1)
Clamped to 0. The score is returned in the /posture/summary response alongside category breakdowns (vulnerabilities, configuration, RBAC, network).
Environment Variables
| Variable | Description |
|---|---|
DATABASE_URL | PostgreSQL connection |
RABBITMQ_URL | RabbitMQ connection |
SCAN_INTERVAL | How often security-cron triggers a scan (default: 6h) |
KUBECONFIG | Path to kubeconfig for cluster access (or uses in-cluster config) |