security-inspector is the key component of the security inspection feature in Container Compute Service (ACS). It scans your workload configurations across multiple dimensions and surfaces security risks in real time.
How security-inspector works
security-inspector uses Polaris, an open source project that is used to identify security risks of workload configurations in a Kubernetes cluster, to run scans against your ACS cluster.
The following diagram shows the architecture of security-inspector.
Scan dimensions
Each inspection report covers five dimensions: health checks, images, networks, resources, and security. Use the findings to identify risks and harden your workload configurations.
For a step-by-step guide on running inspections, see Use the inspection feature to detect security risks in the workloads of an ACK cluster.
Release notes
August 2024
| Version | Release date | Changes | Impact |
|---|---|---|---|
| v0.14.1.0-g829a93d-aliyun | August 1, 2024 | Improved compatibility of security-inspector. First release with support for ACS clusters. | No impact on workloads. |