Skip to content
kix /docs
Install the CLI

Reference Scorecard

Built-in security rules

The built-in checks for workload identity, privilege, cluster-wide RBAC, image references, read-only filesystems, and namespace network policy.

The security rule set lives in kix.rules.security. Rules run by default, but their findings are capped at scorecard.maxSeverity, which defaults to warning.

RuleLevelDeclared severityWhat it checks
security.nonRootmanifesterrorEvery regular and init container resolves to runAsNonRoot = true, or to a non-zero runAsUser when runAsNonRoot is unset.
security.noPrivilegedmanifesterrorNo regular or init container sets securityContext.privileged = true.
security.readOnlyRootfsmanifestwarningEvery regular and init container sets securityContext.readOnlyRootFilesystem = true.
security.noHostNetworkmanifesterrorThe pod does not enable hostNetwork, hostPID, or hostIPC.
security.noClusterAdminmanifesterrorNo ClusterRoleBinding binds the cluster-admin ClusterRole, and no ClusterRole has a rule whose apiGroups, resources, and verbs all contain "*".
security.noLatestTagmanifestwarningEvery container image has an explicit tag other than latest.
security.noUnresolvedPlaceholdermanifestwarningNo image reference contains a common placeholder or the start of an unexpanded Nix-style variable.
security.hasNetworkPolicynamespacewarningA namespace containing a Deployment, StatefulSet, or DaemonSet also contains a policy kind supplied by its network-policy provider.

The manifest rules other than noClusterAdmin apply to Deployments, StatefulSets, DaemonSets, and Jobs. noClusterAdmin applies to ClusterRoleBindings and ClusterRoles. A namespaced RoleBinding to cluster-admin and a wildcard limited to one API group pass it. The finding names the binding and its subjects; derive narrower rules with scope.rbac instead. For nonRoot, a container-level setting overrides the pod setting. A container with runAsNonRoot = false therefore fails even if the pod sets it to true.

noUnresolvedPlaceholder recognizes REPLACE_ME, REPLACEME, CHANGE_ME, CHANGEME, PLACEHOLDER, TODO, FIXME, XXX, and ${... in image references. It cannot tell whether a plausible tag or digest exists; use kix pin check for registry verification.

Four rules have matching meta.unsafe grants:

RuleGrant
security.nonRootrun-as-root
security.noPrivilegedprivileged
security.noHostNetworkhost-network
security.noClusterAdmincluster-admin

The exception removes that rule from the package and produces an info-level architecture.unsafeGrants audit finding. There is no grant for readOnlyRootfs, image checks, or hasNetworkPolicy; change their severity through scorecard policy when necessary.