
kube-bench
Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark
The Lens
By Erik Loyd, SaaS CEO and former COO/CFO of an AWS Premier Partner.
Updated Jul 2026
kube-bench checks whether your Kubernetes cluster is configured according to the CIS Kubernetes Benchmark, the industry-standard hardening checklist. It runs the hundreds of checks in that benchmark automatically and tells you what passes, what fails, and how to fix each one. Open source, from Aqua Security, free.
It runs as a job or container on your nodes and inspects the actual configuration of the control plane, kubelet, and policies against the benchmark. The output maps directly to CIS recommendations, which makes it the standard tool when an auditor asks whether you meet the benchmark. Setup is straightforward and it's built to run on a schedule.
Fully free with no paid tier. It's single-purpose in the best way: it does CIS benchmarking and nothing else, so it pairs naturally with broader tools like Kubescape or a runtime monitor like Falco. Any team that needs to demonstrate CIS compliance for Kubernetes runs this.
The catch: it measures against the CIS benchmark, which is a configuration checklist, not a complete security posture. A cluster can pass kube-bench and still have application-level holes, weak RBAC choices the benchmark doesn't judge, or runtime threats it can't see. It answers are we hardened to CIS, not are we secure.
Free vs Self-Hosted vs Paid
fully freeSelf-hosted (free): kube-bench under Apache-2.0, from Aqua Security. Runs the CIS Kubernetes Benchmark checks against your control plane, kubelet, and policies, mapping results to CIS recommendations. Runs as a job or container, built for scheduling.
Commercial: None.
The call: Single-purpose CIS benchmarking. Pairs with broader tools like Kubescape and a runtime monitor like Falco.
Completely free and open source. No paid tier.
What to do by team size
- Solo
- Free. Run CIS checks against your cluster.
- Small team
- Free. Schedule it and track failures.
- Medium team
- Free; pair with broader tools like Kubescape.
- Large team
- Free; the standard evidence tool for CIS Kubernetes compliance.
Get tools like this every Wednesday
One featured tool, three on the radar. No fluff.
Similar Tools

Monitoring system and time series database

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.

APM and monitoring system

CNCF distributed tracing platform

Fast monitoring and time series DB
A low score is not a verdict on quality. Young and niche tools start low by design. How we calculate scores
Trust Signals
About
- Owner
- Aqua Security (Organization)
- Stars
- 8,144
- Forks
- 1,333
Explore Further
More tools in the directory
openclaw
Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞
386.5k ★everything-claude-code
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
240.5k ★hermes-agent
The agent that grows with you
231.6k ★