> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/kubernetes/whats-new-in-kubernetes-connector.md).

# What's new in Kubernetes connector

This topic describes the changes, additions, known issues, and fixes for each version of the Kubernetes Connector. If Auto Upgrade is enabled in your Kubernetes Connector, you will automatically enjoy the latest released features without having to manually upgrade to the new version.

### Kubernetes Connector releases

Cortex Cloud supports the following current Kubernetes Connector versions. Click the link to view the new features, addressed issues, and known issues per release.

| Release version | Release notes                                                         | Release date  |
| --------------- | --------------------------------------------------------------------- | ------------- |
| 2.2             | [Kubernetes Connector version 2.2](#kubernetes-connector-version-2.2) | July 26, 2026 |
| 2.0             | [Kubernetes Connector version 2.0](#kubernetes-connector-version-2.0) | May 3, 2026   |
| 1.4             | [Kubernetes Connector version 1.4](#kubernetes-connector-version-1.4) | Jan 11, 2026  |
| 1.3             | [Kubernetes Connector version 1.3](#kubernetes-connector-version-1.3) | Nov 9, 2025   |
| 1.2             | [Kubernetes Connector version 1.2](#kubernetes-connector-version-1.2) | July 20, 2025 |

### Kubernetes Connector version 2.2

**New features**

The following section describes the new features introduced in Kubernetes Connector version 2.2.

| Feature                                         | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ----------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Introducing Kubernetes Pods in Cortex Cloud     | <p>Protect Kubernetes Pods from misconfigurations. Kubernetes Pods deployed directly, or modified by other webhooks after their controller was approved, previously bypassed all compliance and image-trust checks. We now provide complete Kubernetes Pod support across inventory tracking, detailed asset visibility, compliance scanning, admission control prevention, and comprehensive container inspection. This closes critical security gaps identified by customers running workloads directly as pods instead of through controllers. • Pods in Cortex Cloud inventory: Cortex Cloud now provides a dedicated asset page for Kubernetes Pods in the inventory. The Kubernetes Pods page includes a relationship graph that shows how a pod connects to related Kubernetes resources. Pods are now available on Search Graph as well for discovery and investigation. • Containers table: Added a new Containers tab for Kubernetes Pod Group assets in Cortex Cloud Inventory, providing complete visibility into pod composition and container details. Use the Kubernetes Pod to investigate the security posture of individual pods and the containers that run in each pod. • Collection & Modeling: Implemented pod collection in the inventory with performance optimization for large clusters and pod-to-runtime-image relationships for complete asset tracking. This supports both K8s Connector agent and K8s Agentless deployments. • Compliance & Rules: Added Kubernetes Pod support to the compliance views, including system-rule validation for pod-scoped rego rules. This enables compliance checks on pods alongside traditional workload controllers. Custom compliance rules now support pods. • Prevention & Admission Control: Kubernetes Pods are now supported as part of CWP rules and policies, enabling the admission controller to block non-compliant pods and prevent misconfigurations at creation time.</p><p>NOTE: A Kubernetes Pod Group asset represents all the identical pod replicas of a Kubernetes workload in a single unique inventory asset. The uniqueness is derived by the Kubernetes workload owner unique identifier.</p> |
| Cluster deployment method visibility            | Understand how your clusters are being connected and scanned by Cortex Cloud. The cluster inventory now displays the deployment method (Agentless, Connector or None) for each cluster, along with connectivity status. This gives you immediate visibility into your scanning infrastructure and helps you identify which clusters are using agentless scanning versus connector-based approaches and which clusters are not connected at all.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Agentless Kubernetes security for GCP and Azure | Automatically onboard and secure all Kubernetes clusters across your GCP and Azure accounts without manual deployment. Monitor cluster inventory, vulnerabilities, malware, secrets, and misconfigurations, automatically discovering new clusters as they are added to your account.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |

### Kubernetes Connector version 2.0

#### New features

The following section describes the new features introduced in Kubernetes Connector version 2.0.

| Feature                                                    | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ---------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Agentless Kubernetes security                              | Expanded Agentless Kubernetes security helps eliminate security blind spots and reduces deployment friction by delivering visibility into inventory, compliance, and runtime images across AWS Kubernetes and containers.                                                                                                                                                                                                                                                                                                                                                                      |
| Unified Kubernetes cluster management                      | Manage your infrastructure from a single, streamlined interface. You can now access all controls directly from the Kubernetes Clusters page instead of navigating legacy connectivity screens. We consolidated these tools into a unified view to simplify your workflow and remove unnecessary navigation steps.                                                                                                                                                                                                                                                                              |
| Enhanced security and deployment for Kubernetes Connectors | <p>Minimize your attack surface by applying stricter security controls to your Kubernetes connectors. Recent updates include:</p><ul><li>Private registry support: You can now pull images directly from private container registries.</li><li>GitOps integration: The standalone installer now fully supports GitOps workflows.</li><li>Least privilege enforcement: Restrict connector management to specific namespaces rather than the entire cluster. We have narrowed the access scope and removed unnecessary secret creation permissions to better protect your environment.</li></ul> |
| Tag Kubernetes endpoints instantly                         | Automate your security deployment. Our new tag support for Kubernetes lets you seamlessly associate XDR security profiles with specific connectors during configuration.                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Enhanced KSPM Graph                                        | We've introduced several design improvements to the KSPM Graph, focused on streamlining your user experience. You can now more intuitively explore the relationships between your workloads, nodes, and cloud resources to seamlessly map and manage your cluster topology and security posture.                                                                                                                                                                                                                                                                                               |
| Maintain system availability                               | Maintain system availability during unexpected disruptions. You can now choose whether to allow or block requests if the admission controller is unreachable. We added a Failure Policy setting to give you full control over your environment's stability.                                                                                                                                                                                                                                                                                                                                    |
| On-demand Kubernetes cluster scans                         | Secure your environment instantly. You no longer have to wait for scheduled cycles to evaluate newly deployed resources, including your inventory, containers, and nodes. We added a "Request Scan" button and API support so you can trigger on-demand cluster scans and see results in minutes.                                                                                                                                                                                                                                                                                              |
| Optimized resource usage                                   | Optimize system performance by eliminating redundant security scans. Your devices run more efficiently because the XDR agent automatically disables Adaptive Vulnerability Assessment (AVA) when a KSPM connector is deployed. The KSPM posture module now handles the AVA scan directly to save local resources.                                                                                                                                                                                                                                                                              |

#### Known limitations

Refer to [KSPM limitations and system components](/kubernetes-security/kspm-limitations-and-system-components.md) for known limitations.

### Kubernetes Connector version 1.4

#### New features

The following section describes the new features introduced in Kubernetes Connector version 1.4.

| Feature                                        | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ---------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Secure OpenShift with container image scanning | Strengthen your software supply chain by identifying vulnerabilities earlier in the development lifecycle. Cortex Cloud KSPM now offers direct integration with the OpenShift Internal Registry, allowing you to automatically scan and secure images as soon as they are pushed to the registry . By leveraging the existing Kubernetes connector, you can now extend your security coverage to images stored in the registry.                                                                                                                                                       |
| Interactive KSPM Graph (Beta)                  | Visualize your Kubernetes security posture across supported Kubernetes clusters using the new KSPM Graph. It provides an interactive visualization that maps relationships across your clusters, specifically illustrating Workload-to-Image relationships within Kubernetes Namespaces. It overlays critical security context, such as misconfigurations and detected vulnerabilities, directly onto the graph topology. This allows security and operations teams to quickly identify asset dependencies, correlate risk, and efficiently prioritize where to focus their response. |
| Container image security scanning              | Cortex Cloud expands its security coverage beyond agentless and agent-based scans with a Kubernetes-native container image and container drift scanning capability. Powered by the lightweight KSPM connector, it provides consistent detection of misconfigurations, vulnerabilities, malware, and exposed secrets across Kubernetes environments, managed or on-prem, where agentless disk scanning is not available.                                                                                                                                                               |
| KSPM support for AWS EKS Fargate clusters      | Gain comprehensive security visibility into container images, inventory, and compliance reporting for your nodeless clusters. We now support deploying the Kubernetes Connector directly onto AWS EKS Fargate environments.                                                                                                                                                                                                                                                                                                                                                           |
| KSPM support for Rancher                       | Simplify security and gain central visibility across all your Rancher-managed Kubernetes clusters. The Kubernetes Connector now supports K3s, RKE, and RKE2 clusters. This allows you to unify security posture management, asset inventory, and compliance reporting for your Rancher-managed clusters alongside all other supported cloud and on-premises environments, ensuring consistent security policy enforcement across your entire infrastructure.                                                                                                                          |
| Simplified navigation for Kubernetes Security  | KSPM now has a dedicated navigation section under Modules.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |

#### Known limitations

Refer to [KSPM limitations and system components](/kubernetes-security/kspm-limitations-and-system-components.md) for known limitations.

### Kubernetes Connector version 1.3

#### New features

The following section describes the new features introduced in Kubernetes Connector version 1.3.

| Feature                               | Description                                                                                                                                                                                                                                                                                                                                                                                               |
| ------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Unified Kubernetes Onboarding         | Streamlined Kubernetes onboarding process in a single, easy-to-use wizard. Now you can discover all available security capabilities based on your license, configure everything in one flow, and deploy your entire solution with one consolidated installer.                                                                                                                                             |
| Kubernetes Connector                  | Supports AKS, EKS, GKE, managed OpenShift, self-managed Kubernetes vanilla clusters, and self-managed OpenShift with a Kubernetes Native installation method of Helm Installer. For more details, see [Supported Kubernetes distributions](/cortex-cloud-posture-management/onboard-and-configure/deployment-steps-and-checklist/onboard-the-kubernetes-connector/supported-kubernetes-distributions.md). |
| KSPM Dashboard                        | A visual overview of your Kubernetes security posture. It includes inventory insights, protection coverage, most vulnerable clusters, malware and secrets detected, and more.                                                                                                                                                                                                                             |
| Compliance standards                  | Enjoy out-of-the-box CIS compliance standards for Kubernetes environments (CIS EKS, CIS GKE, CIS AKS, CIS OpenShift, and CIS Kubernetes).                                                                                                                                                                                                                                                                 |
| Secrets, malware, and vulnerabilities | Generate secret, malware, and vulnerabilities posture issues by declaring policies on Kubernetes clusters                                                                                                                                                                                                                                                                                                 |

#### Known limitations

The following table describes known limitations in the Kubernetes Connector release.

| Feature                                     | Description                                                                                                                                                                                                                                               |
| ------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Connector onboarding and cluster identifier | <p>The Kubernetes Connector automatically calculates the Kubernetes cluster cloud identifier by using the metadata service (for EKS and GKE) and cluster resources (for AKS).</p><ul><li>For EKS and GKE, the metadata service must be enabled.</li></ul> |

### Kubernetes Connector version 1.2

#### New features

The following section describes the new features introduced in Kubernetes Connector version 1.2.

| Feature                               | Description                                                                                                                                              |
| ------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Kubernetes Connector Onboarding       | Supports AKS, EKS, GKE, managed OpenShift, and self-managed Kubernetes Vanilla clusters, with a Kubernetes Native installation method of Helm Installer. |
| KSPM Dashboard                        | A visual overview of your Kubernetes security posture. It includes inventory insights, protection coverage, riskiest clusters, and more.                 |
| Compliance standards                  | Enjoy out-of-the-box CIS compliance standards for Kubernetes environments (CIS EKS, CIS GKE, CIS AKS, CIS OpenShift, and CIS Kubernetes).                |
| Secrets, malware, and vulnerabilities | Generate secret, malware, and vulnerabilities posture issues by declaring policies on Kubernetes clusters                                                |
| AWS WAF Detection                     | Detect the presence of AWS WAF protecting Internet-exposed assets                                                                                        |

#### Known limitations

The following table describes known limitations in the Kubernetes Connector release.

| Feature                                     | Description                                                                                                                                                                                                                                               |
| ------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Connector onboarding and cluster identifier | <p>The Kubernetes Connector automatically calculates the Kubernetes cluster cloud identifier by using the metadata service (for EKS and GKE) and cluster resources (for AKS).</p><ul><li>For EKS and GKE, the metadata service must be enabled.</li></ul> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/kubernetes/whats-new-in-kubernetes-connector.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
