Solutions · Kubernetes

Production Kubernetes Security That Goes Beyond CIS Benchmarks

Kubernetes misconfigurations — privileged pods, exposed dashboards, RBAC bindings that grant cluster-admin — are a leading cause of container-based breaches. Onam audits every cluster object without deploying a sidecar or daemonset.

250+
Kubernetes security rules
EKS / AKS / GKE
+ self-managed
Agentless
no sidecar, no daemonset
< 5 min
per cluster
Coverage

Services we monitor on Kubernetes

Every service below is scanned continuously — no agents, no network changes, read-only.

Deployments, StatefulSets & DaemonSets
Pods & PodSecurity Standards
RBAC — Roles & ClusterRoles
ServiceAccounts & Bindings
NetworkPolicies
Ingress & Services
Secrets & ConfigMaps
Admission Controllers
Container Images & Registries
Nodes & Kubelet Config
CRDs & Custom Resources
etcd & Control-Plane Settings

Plus: GKE Autopilot, EKS Fargate, OpenShift, Rancher-managed clusters, and self-hosted kubeadm clusters.

Compliance

Compliance frameworks

Onam maps every Kubernetes finding to the frameworks your auditors care about.

CIS Kubernetes BenchmarkCIS EKS / AKS / GKE BenchmarksNSA/CISA Kubernetes Hardening GuidePCI-DSS v4.0SOC 2 Type II
Onboarding

Connect in 3 steps

From consent to first finding in under five minutes.

1

Grant read-only cluster access

Apply the Onam ClusterRole manifest — one kubectl apply. It grants get, list, and watch on every resource, and nothing else. No exec, no port-forward, no impersonation.

2

Bind to Onam's service account

Federated OIDC binding to Onam's service account — no long-lived kubeconfig files exchanged. For self-managed clusters, a short-lived token is stored in Onam's HSM-backed vault.

3

First findings in under 5 minutes

Onam watches the API server for drift and audits every workload against CIS Kubernetes, NSA/CISA hardening, and image-supply-chain rules — no runtime agent required.

See it live

Kubernetes in the real console.

Not a mockup — the actual Onam console on a live demo account: connect, inventory and posture in one view.

Add Cloud Account
Docs
AWS · Production
Read-only • No agents
1
Create read-only IAM role
2
Paste Role ARN
3
Validated — scanning…
onam · console
$aws cloudformation create-stack --stack-name onam --template-url ...
Connect your first cloud account
Read-only IAM role — validated and scanning in under 3 minutes
Clip length
9s
Data
Demo account
Differentiators

What makes Onam different on Kubernetes

Beyond CIS — real attack paths

Privileged pods on nodes that reach the metadata service, service accounts with cluster-admin bindings, and NetworkPolicy gaps are correlated into concrete attack paths — not disconnected findings.

RBAC effective-permission graph

Every RoleBinding, ClusterRoleBinding, and ServiceAccount is resolved into what a pod can actually do — including cross-namespace escalation via aggregation rules and impersonation verbs.

Image supply-chain analysis

Container images are traced back to their registries and their base layers. Unscanned images, missing signatures, and vulnerable OS packages are surfaced with the workloads that run them.

FAQ

Questions we get a lot

No. Onam is 100% agentless. It talks to the Kubernetes API server as a read-only ServiceAccount — no sidecar, no daemonset, no eBPF probes.

Ready to secure your Kubernetes environment?

Connect a read-only role in three minutes. Your first findings surface in under five.