Skip to main content

kubectl kguardian

The kguardian CLI is a kubectl plugin that generates security policies from observed runtime behavior.

Installation

See the Installation Guide for detailed instructions.

Global Flags

Available for all commands: --broker-namespace and --broker-service matter when kguardian is installed outside the default kguardian namespace — the CLI port-forwards to the broker and needs to find it. With broker authentication enabled, give the CLI the read token. There is no flag that takes the token directly, because anything in argv is visible through ps:
Without it, the CLI stops with broker requires authentication (HTTP 401). It won’t carry on and treat every peer as unknown. The broker read commands (profile, images and vulns) normally open a port-forward to the broker. To use a broker you already reach another way (an Ingress, your own port-forward), set its URL and no port-forward is opened:
The token is sent to that URL. Over plain http:// to anything but loopback it travels unencrypted, and the CLI warns; use https:// or a port-forward.

Commands

gen networkpolicy

Generate Network Policies from observed traffic

gen seccomp

Generate Seccomp profiles from syscall usage

audit promote

Convert an AuditNetworkPolicy into an enforced networking.k8s.io/v1 NetworkPolicy ready for kubectl apply.

audit promote-cluster

Convert an AuditClusterNetworkPolicy into one NetworkPolicy per matched namespace (discovery from namespaceSelector).

compute findings

List throttled, contended and noisy-neighbour pods with the evidence behind each finding. Read-only.

profile

Show a workload’s security posture, diff profile revisions, and print a recommended securityContext patch. Read-only.

images

List the image digests workloads run, their vulnerabilities (with a CI gate) and SBOMs. Read-only.

vulns

List vulnerabilities across the cluster, and where one CVE runs and how exposed it is. Read-only.

version

Print client version information. Also available as -v / --version on the root command.

Examples