A new AtlasSecurityScan resource runs atlas security scan from the operator on a schedule or after a schema change, and grades the findings against a policy.
The Atlas Kubernetes Operator now runs atlas security scan with the new AtlasSecurityScan resource. It scans a database on a cron schedule and after an AtlasSchema or AtlasMigration listed in its triggers applies a change. It then grades the findings against a policy and stores them in an AtlasSecurityReport owned by the scan.
apiVersion: db.atlasgo.io/v1alpha1kind: AtlasSecurityScanmetadata:name: appspec:urlFrom:secretKeyRef:name: app-dbkey: urlcloud:tokenFrom:secretKeyRef:name: atlas-tokenkey: ATLAS_TOKENschedule: "0 6 * * *"timeZone: UTCpolicy:minSeverity: ELEVATEDfailOn: HIGH
Scanning requires the Security Graph to be enabled for the organization, and an Atlas Pro token in cloud.tokenFrom, which references a bot token.
When Scans Run
- schedule: a cron expression evaluated in timeZone. Slots missed while the operator was not running are caught up with a single scan.
- triggers: AtlasSchema and AtlasMigration resources in the same namespace. A scan runs when one of them applies a new revision.
- On demand: setting the db.atlasgo.io/scan-requested-at annotation to a new value runs a scan, and the value is echoed to status.lastHandledScanRequest when it succeeds.
Reading the Result
The Ready condition says whether the scan ran, and the Compliant condition whether the database is within the policy. Use kubectl wait --for=condition=Compliant as a deployment gate.
$ kubectl get atlassecurityscansNAME READY REASON COMPLIANT FINDINGS HIGHEST LAST SCAN NEXT SCAN AGEapp True Scanned False 3 HIGH 0s 2026-10-01T06:00:00Z 6s
COMPLIANT is False because a HIGH finding reached failOn. The status holds only a summary. The extensions and their CVEs are listed in the AtlasSecurityReport of the same name, which is readable through its own ClusterRole, aggregated into the built-in admin role by default and kept out of view and edit.
Policy
- minSeverity: the lowest level reported. Findings below it are not in the report.
- failOn: the lowest level at which a finding sets Compliant to False. When unset, findings are reported only.
- ignore: waivers for individual CVEs, each with a reason and an optional expiration time. A waived finding stays in the report, marked with its waiver, and leaves the counts and the verdict. When the waiver expires, a scan runs and the finding counts again.
See the security scanning guide for failures and retries, access to reports, and notifications.