
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Chaos and Order</title>
      <link>https://www.youngju.dev/blog</link>
      <description>천천히 올바르게. AI Researcher &amp; DevOps Engineer Youngju&#39;s tech blog. GPU/CUDA, LLM, MLOps, Kubernetes AI workloads, distributed training, and data engineering.</description>
      <language>ko</language>
      <managingEditor>fjvbn2003@gmail.com (Youngju Kim)</managingEditor>
      <webMaster>fjvbn2003@gmail.com (Youngju Kim)</webMaster>
      <lastBuildDate>Sat, 16 May 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://www.youngju.dev/tags/kubescape/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-16-container-kubernetes-scanning-2026-trivy-grype-snyk-container-anchore-clair-falco-kubescape-datree-deep-dive.en</guid>
    <title>Container &amp; Kubernetes Security Scanning 2026 Complete Guide - Trivy, Grype, Snyk Container, Anchore, Clair, Falco, Kubescape, Datree, Polaris, Tetragon Deep Dive</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-16-container-kubernetes-scanning-2026-trivy-grype-snyk-container-anchore-clair-falco-kubescape-datree-deep-dive.en</link>
    <description>A complete map of the container and Kubernetes security scanning ecosystem as of May 2026. Covers image vulnerability scanners (Trivy 0.58, Grype, Syft, Clair v4, Snyk Container), eBPF runtime security (Falco, Tetragon, Tracee), K8s misconfig scanners (Kubescape, Datree, kube-bench, Polaris, Checkov), supply-chain security (Cosign, Sigstore, SLSA), hardened images (Chainguard, Distroless, Wolfi), CNAPP platforms (Wiz, Prisma Cloud, Sysdig), and real adoption stories from Toss, NAVER Cloud, Yahoo!Japan, and Mercari.</description>
    <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>english</category><category>container-security</category><category>kubernetes-security</category><category>trivy</category><category>grype</category><category>snyk-container</category><category>anchore</category><category>clair</category><category>falco</category><category>kubescape</category><category>datree</category><category>tetragon</category><category>sbom</category><category>cnapp</category><category>2026</category><category>deep-dive</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-16-container-kubernetes-scanning-2026-trivy-grype-snyk-container-anchore-clair-falco-kubescape-datree-deep-dive.ja</guid>
    <title>コンテナ &amp; Kubernetes セキュリティスキャン 2026 完全ガイド - Trivy・Grype・Snyk Container・Anchore・Clair・Falco・Kubescape・Datree・Polaris・Tetragon 深掘り</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-16-container-kubernetes-scanning-2026-trivy-grype-snyk-container-anchore-clair-falco-kubescape-datree-deep-dive.ja</link>
    <description>2026年5月時点のコンテナ・Kubernetes セキュリティスキャンエコシステムを一気にまとめます。Trivy 0.58・Grype・Syft・Clair v4・Snyk Container などのイメージ脆弱性スキャナ、Falco・Tetragon・Tracee などの eBPF ランタイムセキュリティ、Kubescape・Datree・kube-bench・Polaris・Checkov などの K8s 設定不備スキャナ、Cosign/Sigstore のサプライチェーンセキュリティ、Chainguard/Distroless/Wolfi のハードニングイメージ、Wiz・Prisma Cloud・Sysdig などの CNAPP、そして Toss・NAVER Cloud・Yahoo!Japan・Mercari の事例まで網羅しました。</description>
    <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>日本語</category><category>container-security</category><category>kubernetes-security</category><category>trivy</category><category>grype</category><category>snyk-container</category><category>anchore</category><category>clair</category><category>falco</category><category>kubescape</category><category>datree</category><category>tetragon</category><category>sbom</category><category>cnapp</category><category>2026</category><category>deep-dive</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-16-container-kubernetes-scanning-2026-trivy-grype-snyk-container-anchore-clair-falco-kubescape-datree-deep-dive</guid>
    <title>컨테이너 &amp; 쿠버네티스 보안 스캐닝 2026 완벽 가이드 - Trivy · Grype · Snyk Container · Anchore · Clair · Falco · Kubescape · Datree · Polaris · Tetragon 심층 분석</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-16-container-kubernetes-scanning-2026-trivy-grype-snyk-container-anchore-clair-falco-kubescape-datree-deep-dive</link>
    <description>2026년 5월 기준 컨테이너·쿠버네티스 보안 스캐닝 생태계를 한 글에 정리합니다. Trivy 0.58·Grype·Syft·Clair v4·Snyk Container 같은 이미지 취약점 스캐너, Falco·Tetragon·Tracee 같은 eBPF 런타임 보안, Kubescape·Datree·kube-bench·Polaris·Checkov 같은 K8s 미스컨피그 스캐너, Cosign/Sigstore 공급망 보안, Chainguard/Distroless/Wolfi 하드닝 이미지, Wiz·Prisma Cloud·Sysdig 같은 CNAPP, 그리고 토스·NAVER Cloud·Yahoo!Japan·Mercari 사례까지 담았습니다.</description>
    <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>container-security</category><category>kubernetes-security</category><category>trivy</category><category>grype</category><category>snyk-container</category><category>anchore</category><category>clair</category><category>falco</category><category>kubescape</category><category>datree</category><category>tetragon</category><category>sbom</category><category>cnapp</category><category>2026</category><category>deep-dive</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-16-kubernetes-admission-policies-security-2026-kyverno-opa-gatekeeper-vap-falco-kubearmor-deep-dive.en</guid>
    <title>Kubernetes Admission Policies &amp; Security 2026 — Kyverno (CNCF Graduated) / OPA Gatekeeper / VAP (CEL) / Falco / KubeArmor / Tetragon Deep Dive</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-16-kubernetes-admission-policies-security-2026-kyverno-opa-gatekeeper-vap-falco-kubearmor-deep-dive.en</link>
    <description>The full topology of Kubernetes security in 2026. Kyverno that became CNCF Graduated in November 2024, Rego-based OPA Gatekeeper, the built-in Validating Admission Policy that went GA in k8s 1.30 (CEL), the alpha Mutating Admission Policy in 1.32, Pod Security Admission replacing PSP, CNCF Graduated Falco, eBPF-based KubeArmor and Cilium Tetragon, Sigstore Policy Controller, Connaisseur, Trivy Operator, Polaris, Goldilocks, Kubescape (ARMO), kube-bench, kube-hunter, kube-score, Checkov — who blocks admission, who watches runtime, who verifies images, plus how Toss, Kakao, and Mercari actually run these stacks.</description>
    <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>kubernetes</category><category>security</category><category>admission-controller</category><category>kyverno</category><category>opa-gatekeeper</category><category>rego</category><category>cedar</category><category>validating-admission-policy</category><category>cel</category><category>pod-security-admission</category><category>falco</category><category>kubearmor</category><category>cilium-tetragon</category><category>ebpf</category><category>sigstore</category><category>cosign</category><category>connaisseur</category><category>trivy-operator</category><category>polaris</category><category>goldilocks</category><category>kubescape</category><category>armo</category><category>kube-bench</category><category>kube-hunter</category><category>checkov</category><category>2026</category><category>deep-dive</category><category>english</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-16-kubernetes-admission-policies-security-2026-kyverno-opa-gatekeeper-vap-falco-kubearmor-deep-dive.ja</guid>
    <title>Kubernetes admission policies &amp; セキュリティ 2026 — Kyverno (CNCF Graduated) / OPA Gatekeeper / VAP (CEL) / Falco / KubeArmor / Tetragon 徹底ガイド</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-16-kubernetes-admission-policies-security-2026-kyverno-opa-gatekeeper-vap-falco-kubearmor-deep-dive.ja</link>
    <description>2026 年の Kubernetes セキュリティ全体地図。2024 年 11 月に CNCF Graduated になった Kyverno、Rego ベースの OPA Gatekeeper、k8s 1.30 で GA したビルトイン Validating Admission Policy (CEL)、1.32 alpha の Mutating Admission Policy、PSP を置き換えた Pod Security Admission、CNCF Graduated の Falco、eBPF ベースの KubeArmor と Cilium Tetragon、Sigstore Policy Controller、Connaisseur、Trivy Operator、Polaris、Goldilocks、Kubescape (ARMO)、kube-bench、kube-hunter、kube-score、Checkov まで — 誰が admit を止め、誰がランタイムを見て、誰がイメージを検証するのか、Toss・Kakao・メルカリの実例まで一気に整理する。</description>
    <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>kubernetes</category><category>security</category><category>admission-controller</category><category>kyverno</category><category>opa-gatekeeper</category><category>rego</category><category>cedar</category><category>validating-admission-policy</category><category>cel</category><category>pod-security-admission</category><category>falco</category><category>kubearmor</category><category>cilium-tetragon</category><category>ebpf</category><category>sigstore</category><category>cosign</category><category>connaisseur</category><category>trivy-operator</category><category>polaris</category><category>goldilocks</category><category>kubescape</category><category>armo</category><category>kube-bench</category><category>kube-hunter</category><category>checkov</category><category>2026</category><category>deep-dive</category><category>日本語</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-16-kubernetes-admission-policies-security-2026-kyverno-opa-gatekeeper-vap-falco-kubearmor-deep-dive</guid>
    <title>Kubernetes admission policies &amp; 보안 2026 — Kyverno (CNCF Graduated) / OPA Gatekeeper / VAP (CEL) / Falco / KubeArmor / Tetragon 심층 가이드</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-16-kubernetes-admission-policies-security-2026-kyverno-opa-gatekeeper-vap-falco-kubearmor-deep-dive</link>
    <description>2026년 쿠버네티스 보안의 전체 지형도. 2024년 11월 CNCF Graduated 가 된 Kyverno, Rego 기반 OPA Gatekeeper, k8s 1.30에서 GA 된 빌트인 Validating Admission Policy (CEL), 1.32 alpha 의 Mutating Admission Policy, PSP 를 대체한 Pod Security Admission, CNCF Graduated 가 된 Falco, eBPF 기반 KubeArmor 와 Cilium Tetragon, Sigstore Policy Controller, Connaisseur, Trivy Operator, Polaris, Goldilocks, Kubescape (ARMO), kube-bench, kube-hunter, kube-score, Checkov 까지 — 누가 admit 을 막고 누가 런타임을 보고 누가 이미지를 검증하는가, 토스·카카오·메르카리 사례까지 한 번에 정리한다.</description>
    <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>kubernetes</category><category>security</category><category>admission-controller</category><category>kyverno</category><category>opa-gatekeeper</category><category>rego</category><category>cedar</category><category>validating-admission-policy</category><category>cel</category><category>pod-security-admission</category><category>falco</category><category>kubearmor</category><category>cilium-tetragon</category><category>ebpf</category><category>sigstore</category><category>cosign</category><category>connaisseur</category><category>trivy-operator</category><category>polaris</category><category>goldilocks</category><category>kubescape</category><category>armo</category><category>kube-bench</category><category>kube-hunter</category><category>checkov</category><category>2026</category><category>deep-dive</category>
  </item>

    </channel>
  </rss>
