AppSecNews

Container Security

Container and Kubernetes Security

Scan images, enforce policy and watch runtime behavior in containerized workloads.

8 tools profiled

How it differs Scans container images and enforces policy on running containers and Kubernetes workloads. Checking the manifests before deploy is IaC security.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

2 tools match

  • Calico

    Tigera

    Container Security

    A Kubernetes networking and network policy engine that enforces workload level segmentation through iptables or eBPF dataplanes, with commercial tiers adding observability and egress control.

    Open source and commercial
    Established
  • NeuVector

    SUSE

    Container Security

    An open source container security platform whose enforcer inspects pod traffic at the application layer and blocks process, file and network behavior outside a learned baseline.

    Open source
    Established
  • Calico

    Tigera

    A Kubernetes networking and network policy engine that enforces workload level segmentation through iptables or eBPF dataplanes, with commercial tiers adding observability and egress control.

    Open source and commercial Established
    Container Security
  • NeuVector

    SUSE

    An open source container security platform whose enforcer inspects pod traffic at the application layer and blocks process, file and network behavior outside a learned baseline.

    Open source Established
    Container Security
Tick up to 4 tools above.