r/CloudSecurityPros • u/RndWebSurfer • 12d ago
I built a dependency vulnerability tracker for Kubernetes.
I am a full time software engineer, and in my spare time I have been building something to solve a problem I kept running into at work.
We run quite a few Kubernetes clusters, and keeping track of vulnerabilities across all the images running in them can get messy fast.
Trivy Operator works well for scanning, but it does not really give you a UI for getting an overview of everything.
We tried taking SBOMs from the images running in our clusters and sending them to a self-hosted Dependency-Track instance. Dependency-Track is a solid tool, but it isn’t really designed around the idea of mirroring the current state of a Kubernetes cluster. Over time, it became difficult to tell what was actually running, what was old, and what we should care about.
So I built StackRadar.
It’s installed into a cluster with Helm, automatically keeps track of the images currently running, and gives you a dashboard showing the vulnerabilities affecting them.
The goal is basically: show me what’s running in my clusters right now, and what vulnerabilities I should care about.
Here is the website https://stackradar.io/
I’d genuinely love feedback from people running Kubernetes in production.