Skip to content
Spinoza

Documentation

Cluster checks

128 checks over security, reliability and efficiency, decided against the live cluster.

What they read

The registry covers workloads, RBAC, networking, storage and custom resources. Checks that match a published framework carry PSS baseline, PSS restricted or NSA/CISA labels.

  • Security posture and risky workload configuration.
  • Reliability, rollout and availability failures.
  • Resource waste and missing capacity controls.
  • APIs removed by a coming Kubernetes release and certificates nearing expiry.
  • References to objects that no longer exist.

Working with findings

The view opens on the findings themselves. Scope, baselines, muted rules, imported findings and export sit together behind one Configure control, so the list is what you see first.

Findings rank by how far the problem reaches. Mute a rule, take a baseline to compare later or across clusters, and add checks of your own as CEL expressions.

Findings from elsewhere

Point Spinoza at the output of another scanner and its findings are shown beside the built-in ones, attached to the objects they name, so one list covers both.

Pod Security Standard verdicts come from the standard's own implementation rather than a second reading of the rules, so what you see here matches what an admission controller would decide.

What they run against

Checks read the caches Spinoza already keeps, so running them installs nothing in the cluster and costs no extra API traffic.