Run an on-demand Kubernetes cluster scan
Request an Inventory or Nodes and containers scan for an eligible Kubernetes cluster.
On-demand scanning applies to individual Kubernetes clusters managed by an active Cortex Cloud KSPM connector. On-demand scanning does not replace scheduled scan cycles and does not support bulk operations across multiple clusters simultaneously.
The Request scan option is available to all Cortex Cloud users with access to the Kubernetes Clusters inventory. No additional role-based permissions are required to request a scan.
Scan types
The Request scan dialog provides the following scan types:
Inventory
Collects and updates the full inventory of Kubernetes resources in the cluster.
1 hour
Nodes and containers
Scans all nodes in the cluster, including container images, for vulnerabilities and misconfigurations.
6 hours
The nodes and containers scan is both CPU and memory-intensive. Run the scan no more than once every six hours to avoid performance degradation on the target cluster.
Each scan type enforces a cooldown period after a successful request. When a scan type is in cooldown, the corresponding checkbox is disabled, and a countdown badge indicates when the next scan request becomes available.
Request an on-demand scan
The Request scan option is available from two locations in the Cortex Cloud console:
Select scan types
In the Request scan dialog, review the cluster details: cluster name, cluster distribution (EKS, AKS, GKE, OpenShift, or Kubernetes), cloud account name, and cloud provider.
Under Select scan type, select one or both scan types: Inventory scan and Nodes & containers scan.
Select Request.
Results
After a successful request, Cortex Cloud displays the Scan Requested confirmation, followed by one of the following messages:
An Inventory scan was successfully requested
A Nodes and Containers scan was successfully requested
The connector is inactive (no heartbeat received in the last 15 minutes).
Known limitations
The scan executes after the next connector heartbeat (approximately 30 seconds), not immediately upon request.
Bulk scan requests across multiple clusters simultaneously are not supported.
Customization of cooldown periods is not available through the Cortex Cloud console.
A historical audit log of on-demand scan requests is not available.
Last updated
Was this helpful?
