Skip to main content

vamp-k8s-audit

Python 3.8+ License MIT VampSecure Labs

Kubernetes Security Auditor — part of the VampSecure Labs toolkit.

Detects dangerous configurations in Kubernetes clusters through kubectl queries (no SDK required). Produces structured findings with remediation guidance, JSON output, and a professional HTML report for client delivery.


Prerequisites

  • Python 3.8+
  • kubectl installed and reachable in PATH
  • Active cluster access — the current kubectl context must point to the target cluster
  • Sufficient RBAC permissions to read: pods, services, secrets, configmaps, clusterrolebindings, rolebindings, networkpolicies, ingresses, namespaces, nodes

Optional, for PDF export:

pip install fpdf2>=2.7

Installation

git clone <repo-url> vamp-k8s-audit
cd vamp-k8s-audit
pip install -r requirements.txt   # optional, only needed for PDF

No additional dependencies beyond Python stdlib are required for JSON and HTML output.


Usage

# Basic audit — current kubectl context, all namespaces
python3 vamp_k8s_audit.py

# Specific context and namespace
python3 vamp_k8s_audit.py --context prod-cluster --namespace production

# Save findings as JSON
python3 vamp_k8s_audit.py --output findings.json

# Generate professional HTML report for client delivery
python3 vamp_k8s_audit.py \
  --report-html report.html \
  --client "Acme Corp S.A." \
  --engagement "Kubernetes Security Review Q3-2026" \
  --auditor "VampSecure Labs"

# Custom kubeconfig path
python3 vamp_k8s_audit.py --kubeconfig ~/.kube/custom-config --context staging

# Skip image analysis (faster)
python3 vamp_k8s_audit.py --skip-images --output findings.json

# Verbose mode (show evidence in console)
python3 vamp_k8s_audit.py --verbose

# Full example
python3 vamp_k8s_audit.py \
  --context production \
  --namespace app-prod \
  --client "Client Name" \
  --engagement "K8S-Audit-2026" \
  --auditor "Analyst Name" \
  --output results.json \
  --report-html report.html \
  --verbose

CLI Arguments

Argument Description Default
--context CTX kubectl context to use current context
--namespace NS Limit audit to one namespace all namespaces
--kubeconfig PATH Path to kubeconfig file ~/.kube/config
--output FILE Save findings as JSON
--report-html FILE Generate professional HTML report
--client NAME Client name for the report Confidencial
--engagement DESC Engagement description
--auditor NAME Auditor name VampSecure Labs
--skip-images Skip image analysis (Phase 6) false
--verbose Verbose mode false

Audit Phases and Finding IDs

Phase Scope Finding IDs Key Checks
1 — Cluster Context Cluster-wide K8S-001..K8S-009 Anonymous API access, node versions, node health
2 — RBAC Cluster + namespaces K8S-010..K8S-029 cluster-admin SA bindings, wildcard ClusterRoles, default SA permissions, anonymous user permissions
3 — Pod Security All pods K8S-030..K8S-059 Privileged containers, root execution, privilege escalation, dangerous capabilities, hostPID/IPC/Network, sensitive host mounts, missing resource limits
4 — Network All namespaces K8S-060..K8S-079 LoadBalancer/NodePort exposure, missing NetworkPolicies, Ingress without TLS, Dashboard exposure, etcd TCP access
5 — Secrets All namespaces K8S-080..K8S-099 Secrets in plain env vars, secrets in ConfigMaps, Opaque secrets in default namespace
6 — Images & Runtime All pods K8S-090..K8S-109 :latest tags, public registries, missing readOnlyRootFilesystem, missing Pod Security Admission

Finding Severity Distribution

Severity Color Meaning
CRITICAL Red Immediate exploitation risk, full cluster compromise
HIGH Orange Significant security weakness requiring urgent attention
MEDIUM Yellow Configuration issue reducing security posture
LOW Blue Best practice deviation
INFO Grey Informational observation

Exit Codes

Code Meaning
0 No CRITICAL or HIGH findings
1 At least one HIGH finding detected
2 At least one CRITICAL finding detected

These codes are suitable for use in CI/CD pipelines to gate deployments.


Output Formats

Console — Color-coded ANSI output with severity badges, affected resources, and a summary table.

JSON (--output FILE) — Structured VSL schema with metadata, summary by severity, and full finding detail.

HTML (--report-html FILE) — Standalone professional report for client delivery. Includes cover page, executive summary with risk bars, findings table, and detailed cards. No external dependencies (fully self-contained).


Required RBAC Permissions

The tool requires read-only access to cluster resources. A minimal ClusterRole:

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: vamp-k8s-audit-reader
rules:
- apiGroups: [""]
  resources:
  - pods
  - services
  - secrets
  - configmaps
  - namespaces
  - nodes
  - serviceaccounts
  verbs: ["get", "list"]
- apiGroups: ["rbac.authorization.k8s.io"]
  resources:
  - clusterroles
  - clusterrolebindings
  - roles
  - rolebindings
  verbs: ["get", "list"]
- apiGroups: ["networking.k8s.io"]
  resources:
  - networkpolicies
  - ingresses
  verbs: ["get", "list"]

Legal Notice

This tool is intended for authorized security audits only. Using it against clusters you do not have explicit permission to test is illegal and unethical.


© VampSecure Studios — VampSecure Labs Security Research Division
All rights reserved. Authorized use only.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

vamp_k8s_audit-1.0.tar.gz (34.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

vamp_k8s_audit-1.0-py3-none-any.whl (35.6 kB view details)

Uploaded Python 3

File details

Details for the file vamp_k8s_audit-1.0.tar.gz.

File metadata

  • Download URL: vamp_k8s_audit-1.0.tar.gz
  • Upload date:
  • Size: 34.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.14.6

File hashes

Hashes for vamp_k8s_audit-1.0.tar.gz
Algorithm Hash digest
SHA256 1092e0c9c2fb935704da5ffb451bf4a12b2cb17bda640b285340e3233c8400fb
MD5 266dc2e5819fa1d2e993ce74a82c3f11
BLAKE2b-256 b17914c04b9fb47c128eb3347baa3a3ac9690319c6e477686141c3d6388efd05

See more details on using hashes here.

File details

Details for the file vamp_k8s_audit-1.0-py3-none-any.whl.

File metadata

  • Download URL: vamp_k8s_audit-1.0-py3-none-any.whl
  • Upload date:
  • Size: 35.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.14.6

File hashes

Hashes for vamp_k8s_audit-1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 0073ff1fae319dda0c10553faf135a98dff4c36338a717ef681b662ffc1e56df
MD5 63f661ef7dfbe8a51f8208008a716cab
BLAKE2b-256 78bb9b888826414d68a7dee8dbd9a047ef5cf93f6fbd07893375eb477d40b99c

See more details on using hashes here.

Release history Release notifications | RSS feed

1.0.post1

2 files

This release

1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page