Kubernetes Policy
Compare 35 kubernetes policy tools to find the right one for your needs
🔧 Tools
Compare and find the best kubernetes policy for your needs
Styra Declarative Authorization Service (DAS)
An enterprise-grade control plane for Open Policy Agent (OPA) that provides a management and visibility layer for policy enforcement.
Fairwinds Insights
A software platform that helps you ship cloud-native applications faster and with more confidence by providing a unified view of your Kubernetes security, compliance, and cost.
Kubescape
An open-source tool that provides risk analysis, security compliance, and misconfiguration scanning for Kubernetes.
Snyk
A developer-first security platform that helps you find and fix vulnerabilities in your code, open source dependencies, containers, and IaC.
Sysdig
A cloud security platform that provides threat detection, compliance, and forensics for containers, Kubernetes, and cloud.
Prisma Cloud by Palo Alto Networks
A comprehensive cloud security platform that provides security and compliance coverage for the entire cloud-native application lifecycle.
Aqua Security
A comprehensive security platform for cloud-native applications, from development to production.
Rapid7 InsightCloudSec
A Cloud-Native Application Protection Platform (CNAPP) that provides unified visibility, risk management, and compliance.
SUSE NeuVector
A container security platform that provides vulnerability scanning, compliance, and zero-trust runtime security.
Zscaler
A cloud security company providing a Zero Trust Exchange platform for secure access to applications and data.
Sysdig Secure
A cloud-native security platform that provides threat detection, compliance, and forensics for containers, Kubernetes, and cloud.
Red Hat Advanced Cluster Security for Kubernetes (ACS)
A Kubernetes-native security platform that protects applications across the build, deploy, and run phases.
NeuVector by SUSE
A container security platform that provides deep visibility, vulnerability scanning, and run-time protection for Kubernetes.
Lacework
A cloud security platform that provides automated threat detection, compliance, and visibility for cloud-native environments.
Zscaler Posture Control
A CNAPP that helps you secure your cloud-native applications by providing visibility, security, and compliance across your entire cloud environment.
Alcide
A Kubernetes security platform that provides configuration and compliance scanning, as well as runtime security.
Calico
An open-source networking and network security solution for containers, virtual machines, and native host-based workloads.
Tigera Calico
An open-source networking and network security solution for containers, virtual machines, and native host-based workloads.
Datadog
A monitoring and security platform for cloud applications, providing observability, security, and analytics.
Datadog Cloud Security Platform
A comprehensive security solution that provides visibility, threat detection, and compliance monitoring for cloud-native environments.
K-Rail
An open-source policy enforcement tool for Kubernetes that helps you secure a multi-tenant cluster with minimal disruption.
MagTape
An open-source admission controller from T-Mobile for validating and mutating resources based on annotations.
Open Policy Agent (OPA)
An open source, general-purpose policy engine that enables unified, context-aware policy enforcement across the entire stack.
KubeLinter
An open-source static analysis tool that checks Kubernetes YAML files and Helm charts for security misconfigurations and adherence to best practices.
Checkov
A static code analysis tool for infrastructure as code (IaC) that scans for misconfigurations and security vulnerabilities.
jsPolicy
An open-source policy engine for Kubernetes that allows users to write policies using JavaScript or TypeScript.
Cilium
An open-source project providing networking, observability, and security for cloud-native environments using eBPF.
KubeArmor
A CNCF sandbox project that provides runtime security enforcement for Kubernetes using LSMs.
Kyverno
A policy engine designed specifically for Kubernetes that allows you to manage policies as Kubernetes resources.
Gatekeeper
A customizable admission webhook for Kubernetes that enforces policies executed by the Open Policy Agent (OPA).
Open Policy Agent (OPA) / Gatekeeper
A general-purpose policy engine that can be used across the stack. Gatekeeper is its specialized Kubernetes admission controller.
Polaris
An open-source tool that validates and enforces Kubernetes best practices, helping you avoid common configuration problems.
Falco
An open-source runtime security tool that detects anomalous activity in your applications and containers.
Trivy
An open-source vulnerability scanner that can be used to scan container images, filesystems, and Git repositories for security issues.
Kube-bench
An open-source tool that checks whether your Kubernetes deployment meets the security recommendations of the CIS Kubernetes Benchmark.