OPA Gatekeeper
Open Policy Agent (CNCF)
The Kubernetes admission controller for Open Policy Agent, packaging Rego policies as reusable constraint templates and cluster-scoped constraints.
IaC Security
Catch misconfigurations in Terraform, Kubernetes manifests and cloud templates before deploy.
17 tools profiled
How it differs Scans Terraform, Kubernetes manifests and other infrastructure definitions before they are applied. Scanning the built images is container security.
Open Policy Agent (CNCF)
The Kubernetes admission controller for Open Policy Agent, packaging Rego policies as reusable constraint templates and cluster-scoped constraints.
The Kyverno Project (CNCF)
A Kubernetes-native policy engine that enforces, mutates and generates resources through admission webhooks, with policies written as YAML.
AccuKnox (CNCF project)
A CNCF runtime security engine that uses Linux security modules and eBPF to block, not just alert on, disallowed behavior inside workloads.
Open Policy Agent (CNCF)
The Kubernetes admission controller for Open Policy Agent, packaging Rego policies as reusable constraint templates and cluster-scoped constraints.
The Kyverno Project (CNCF)
A Kubernetes-native policy engine that enforces, mutates and generates resources through admission webhooks, with policies written as YAML.
AccuKnox (CNCF project)
A CNCF runtime security engine that uses Linux security modules and eBPF to block, not just alert on, disallowed behavior inside workloads.
The Falco Project (CNCF)
A CNCF runtime security engine that taps Linux kernel syscalls with eBPF and raises alerts when activity matches a rule.
ARMO (CNCF project)
A CNCF tool that scans Kubernetes clusters and manifests against control frameworks such as NSA-CISA hardening guidance and CIS benchmarks.
Sysdig
A commercial cloud and container security platform built on Falco, combining runtime detection with posture, vulnerability management and capture-based forensics.
The Falco Project (CNCF)
A CNCF runtime security engine that taps Linux kernel syscalls with eBPF and raises alerts when activity matches a rule.
ARMO (CNCF project)
A CNCF tool that scans Kubernetes clusters and manifests against control frameworks such as NSA-CISA hardening guidance and CIS benchmarks.
Sysdig
A commercial cloud and container security platform built on Falco, combining runtime detection with posture, vulnerability management and capture-based forensics.