Back to changelog
New
•2 minute read

Kubernetes Operator: Security Scanning

A new AtlasSecurityScan resource runs atlas security scan from the operator on a schedule or after a schema change, and grades the findings against a policy.

The Atlas Kubernetes Operator now runs atlas security scan with the new AtlasSecurityScan resource. It scans a database on a cron schedule and after an AtlasSchema or AtlasMigration listed in its triggers applies a change. It then grades the findings against a policy and stores them in an AtlasSecurityReport owned by the scan.

security-scan.yaml
apiVersion: db.atlasgo.io/v1alpha1
kind: AtlasSecurityScan
metadata:
name: app
spec:
urlFrom:
secretKeyRef:
name: app-db
key: url
cloud:
tokenFrom:
secretKeyRef:
name: atlas-token
key: ATLAS_TOKEN
schedule: "0 6 * * *"
timeZone: UTC
policy:
minSeverity: ELEVATED
failOn: HIGH

Scanning requires the Security Graph to be enabled for the organization, and an Atlas Pro token in cloud.tokenFrom, which references a bot token.

When Scans Run

  • schedule: a cron expression evaluated in timeZone. Slots missed while the operator was not running are caught up with a single scan.
  • triggers: AtlasSchema and AtlasMigration resources in the same namespace. A scan runs when one of them applies a new revision.
  • On demand: setting the db.atlasgo.io/scan-requested-at annotation to a new value runs a scan, and the value is echoed to status.lastHandledScanRequest when it succeeds.

Reading the Result

The Ready condition says whether the scan ran, and the Compliant condition whether the database is within the policy. Use kubectl wait --for=condition=Compliant as a deployment gate.

$ kubectl get atlassecurityscans
NAME READY REASON COMPLIANT FINDINGS HIGHEST LAST SCAN NEXT SCAN AGE
app True Scanned False 3 HIGH 0s 2026-10-01T06:00:00Z 6s

COMPLIANT is False because a HIGH finding reached failOn. The status holds only a summary. The extensions and their CVEs are listed in the AtlasSecurityReport of the same name, which is readable through its own ClusterRole, aggregated into the built-in admin role by default and kept out of view and edit.

Policy

  • minSeverity: the lowest level reported. Findings below it are not in the report.
  • failOn: the lowest level at which a finding sets Compliant to False. When unset, findings are reported only.
  • ignore: waivers for individual CVEs, each with a reason and an optional expiration time. A waived finding stays in the report, marked with its waiver, and leaves the counts and the verdict. When the waiver expires, a scan runs and the finding counts again.

See the security scanning guide for failures and retries, access to reports, and notifications.

featurekubernetesoperatorsecuritycveatlas pro