Workload security

Connect and assess a Kubernetes cluster

Register a Kubernetes cluster, install the Secorvia collector, verify inventory, and inspect workload findings and compliance impact.

Reviewed

Before you start

Have permission to register the cluster and install its collector. For direct registration, the cluster API must be reachable and you need its CA certificate and bearer token.

Choose the connection model

Open Kubernetes Security. Connect Self-Managed Cluster uses an in-cluster collector that reports outbound; no cloud account, API endpoint, or cluster bearer token is needed. Register With Credentials lets Secorvia connect directly to an API server using supplied credentials.

Register the cluster

For a self-managed cluster, enter Cluster Name and complete registration. For direct registration, select Cloud Account and enter the optional Region, API Server Endpoint, CA Certificate (PEM), and Bearer Token. Use the model appropriate for your network and credential policy.

Save the collector credential and install

For the collector model, copy the one-time credential into your approved secret store. Use the exact Install with Helm or Install with kubectl command generated by your deployment. Complete any pull-secret prerequisite first. Check whether the displayed image is pinned by digest.

Verify the connection and inventory

Use Watch it connect, logs, and Verify Connection. Open Cluster Detail to check Last report, collector version, Nodes, Namespaces, Workloads, and Pods. Secret metadata may be shown; the collector does not collect Kubernetes Secret values.

Investigate workload security

Review security posture and use View in Findings and View in Compliance. Container vulnerability correlation requires image content digests. To explore relationships in Attack Path, rebuild a graph snapshot that includes the cluster’s latest inventory.

Where you are now

Your cluster is registered, collection is reporting, and you can trace its inventory to findings and compliance mappings.

WHEN SOMETHING LOOKS OFF

A few things to check

No installation command is available

The deployment may not have a published collector image configured. Registration can succeed while installation remains unavailable; ask the platform administrator to configure the collector release.

No workloads discovered

Check collector logs, outbound connectivity, credential validity, and Last report. A cloud-discovered cluster is not necessarily connected for in-cluster inventory.

PUT IT INTO PRACTICE

Make your next move in Secorvia.

Open the app and follow along with your own organization.

Open Secorvia