> For the complete documentation index, see [llms.txt](https://docs.portainer.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.portainer.io/portainer-documentation/3.0-sts/admin/environments/policies/kubernetes-policies/create-a-kubernetes-vulnerability-scanning-policy.md).

# Create a Kubernetes vulnerability scanning policy

Define a vulnerability scanning policy that deploys [trivy-operator](https://aquasecurity.github.io/trivy-operator/latest/) to every Kubernetes environment in the environment groups the policy is attached to. Trivy-operator scans the images backing running workloads on a schedule and records what it finds as `VulnerabilityReport` resources in the cluster.&#x20;

Once the policy is applied, an [**Image Vulnerabilities**](/portainer-documentation/3.0-sts/user/kubernetes/more-resources/image-vulnerabilities.md) item appears under **More resources** in the sidebar of each environment it covers, providing a list of vulnerabilities and severity.&#x20;

{% hint style="warning" %}
Scanning is real work on a busy cluster. Keep the interval long and the concurrency low unless you have headroom to spare.
{% endhint %}

To create a Kubernetes vulnerability scanning policy, in the menu, under **Environment-related**, select **Policies** then select **Create policy**. From the policy type list, navigate to the **Kubernetes** > **Vulnerability Scanning** section, select **Custom** then select **Continue** to begin configuring the policy.

{% hint style="info" %}
Currently, only custom vulnerability scanning policies can be created. Future improvements to the policies feature will introduce policy templates.
{% endhint %}

| Field/Option       | Overview                                                                                                                                                                                                                                            |
| ------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Name               | Define a name for this policy.                                                                                                                                                                                                                      |
| Environment groups | Select one or more Kubernetes environment [groups](https://docs.portainer.io/admin/environments/groups) from the dropdown menu. If the selected group is already included in an existing policy, a warning icon will appear next to the group name. |

<figure><img src="https://1210853305-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNaHIkLFUk78GrFLS4raF%2Fuploads%2F4zkBvSENOVFgBhXwUqIh%2F3.0-vulnerability-scanning-1.png?alt=media&amp;token=f9b0dc32-f941-4b09-a706-c6e055a62731" alt=""><figcaption></figcaption></figure>

### Scanning&#x20;

| Field/Option                   | Overview                                                                                                                                            |
| ------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------- |
| Rescan running workloads every | How often trivy-operator rescans running workloads, in hours, days or weeks. Minimum 1 hour. Default is 7 days.                                     |
| Maximum concurrent scans       | How many scan jobs may run at once, from 1 to 10. A higher limit finishes a sweep sooner but takes more of the cluster while it runs. Default is 2. |
| Record findings of severity    | Select which of the five severities (Critical, High, Medium, Low, Unknown) the scanner records.                                                     |

<figure><img src="https://1210853305-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNaHIkLFUk78GrFLS4raF%2Fuploads%2FDFtB2ggjVicPcjvTr9aW%2F3.0-vulnerability-scanning-2.png?alt=media&amp;token=e41ed4e6-2ce4-4c5b-b311-3c93b54678bf" alt=""><figcaption></figcaption></figure>

### Namespace scope

Choose which namespaces trivy-operator scans:

| Field/Option          | Overview                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| --------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| All namespaces except | <p>Click <strong>Add namespace</strong> to add namespaces you want to exclude from scanning.</p><p>Every namespace is scanned except those listed. Entries may use glob patterns, such as <code>kube-\*</code>. </p><p><code>kube-system</code>, <code>kube-public</code>, <code>kube-node-lease</code>, <code>portainer</code> and the operator namespace are excluded by default. Any entry can be removed using the trashcan icon.</p> |
| Only these namespaces | <p>Click <strong>Add namespace</strong> to add namespaces you want to be included in scanning.</p><p>Only the namespaces listed are scanned. Entries must be exact namespace names - patterns aren't supported in this mode. Namespaces created later aren't covered until you add them here.</p>                                                                                                                                         |

<figure><img src="https://1210853305-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNaHIkLFUk78GrFLS4raF%2Fuploads%2Ffb2El4e6dIuFRuvsH1MT%2F3.0-vulnerability-scanning-3.png?alt=media&amp;token=5a5326e7-fa1d-422c-b26f-1d254d7bce90" alt=""><figcaption></figcaption></figure>

### Advanced&#x20;

| Field/Option       | Overview                                                                                                 |
| ------------------ | -------------------------------------------------------------------------------------------------------- |
| Operator namespace | The namespace trivy-operator itself runs in - not the namespace(s) it scans. Defaults to `trivy-system`. |

<figure><img src="https://1210853305-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNaHIkLFUk78GrFLS4raF%2Fuploads%2FXbUl6npeNe6m2VR9sOZi%2F3.0-vulnerability-scanning-4.png?alt=media&amp;token=507f3ed0-d60a-4536-8566-01dbbb64d8dc" alt=""><figcaption></figcaption></figure>

When you have completed the entries, click **Create policy**. A confirmation screen displays the changes being made and any existing policy that will be replaced. Click **Confirm** to acknowledge the changes and create the policy.
