Container Security Inventory
Upon onboarding of clusters, registries, and other resources, the Assets page showcases all details of the assets including:
- Asset name and metadata (For example, cloud account, region, and so on)
- Qualys or Cloud Tags
- Security posture – vulnerabilities, compliance
- Scan dates
While Qualys performs risk prioritization and compliance assessments across a variety of Kubernetes and container resources, the primary resources are highlighted as the following:
- Clusters: List of Kubernetes Clusters that are scanned for vulnerabilities, compliance, and threats including AWS EKS, Azure AKS, Google GKE/Autopilot, Red Hat OpenShift and more.
Note: This requires Qualys Cluster sensor - Containers: Containers that are discovered and scan by Qualys sensors across Kubernetes, Standalone environments, AWS ECS, Fargate and more
- Images: Scanned images that span CI/CD scans, registry, and runtime. Filter by images in-use to see actively deployed images.
- Hosts: These are pulled from VMDR and CSAM to show hosts that are running containers.
- Registries: Qualys can scan any container registry and associated images for vulnerabilities, secrets, and malware including JFrog Artifactory, AWS ECR, Azure ACR and more. This page can be used to configure registry connectors and scan jobs.
- Serverless Functions: Inventory and scan results for functions such as AWS Lambda and Azure Functions. View <> to learn how to configure these scans
- Code: Code repositories can be scanned by Qualys QScanner and viewed here including code commit information and SCA vulnerability findings.
See Also
View Asset Details (for Hosts, Images, Containers, Registries)