kubectl kguardian
The kguardian CLI is a kubectl plugin that generates security policies from observed runtime behavior.Installation
See the Installation Guide for detailed instructions.Global Flags
Available for all commands:--broker-namespace and --broker-service matter when kguardian is
installed outside the default kguardian namespace — the CLI
port-forwards to the broker and needs to find it.
With broker authentication
enabled, give the CLI the read token. There is no flag that takes the
token directly, because anything in argv is visible through ps:
broker requires authentication (HTTP 401).
It won’t carry on and treat every peer as unknown.
The broker read commands (profile, images and vulns) normally
open a port-forward to the broker. To use a broker you already reach
another way (an Ingress, your own port-forward), set its URL and no
port-forward is opened:
http:// to anything but
loopback it travels unencrypted, and the CLI warns; use https:// or a
port-forward.
Commands
gen networkpolicy
Generate Network Policies from observed traffic
gen seccomp
Generate Seccomp profiles from syscall usage
audit promote
Convert an AuditNetworkPolicy into an enforced networking.k8s.io/v1 NetworkPolicy ready for kubectl apply.
audit promote-cluster
Convert an AuditClusterNetworkPolicy into one NetworkPolicy per matched namespace (discovery from
namespaceSelector).compute findings
List throttled, contended and noisy-neighbour pods with the evidence behind each finding. Read-only.
profile
Show a workload’s security posture, diff profile revisions, and print a recommended securityContext patch. Read-only.
images
List the image digests workloads run, their vulnerabilities (with a CI gate) and SBOMs. Read-only.
vulns
List vulnerabilities across the cluster, and where one CVE runs and how exposed it is. Read-only.
version
Print client version information. Also available as
-v / --version on the root command.