Compliance

K8s Manifest Auditor

A new tool extracted from the codebase.

Last reviewed by the Radiatus Cloud team

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

Audit Kubernetes manifests

Kubernetes configurations carry security and compliance implications, and reviewing them by hand is hard. This tool audits Kubernetes manifests against good practice, so you can find the compliance and security issues in your own configurations.

Why manifest auditing matters

A Kubernetes manifest defines how workloads run, and many security-relevant settings default to the permissive option: running as root, no resource limits, privileged containers, missing security contexts. Each of these is both a security weakness and, often, a compliance gap against benchmarks that expect them to be set. Auditing manifests against these expectations surfaces the issues systematically, which is far more reliable than spotting them by eye in a wall of YAML. This is defensive review of your own configurations to harden them and meet the benchmarks compliance frameworks reference.

Harden your configs

It runs entirely in your browser, so nothing you enter is uploaded, which matters when the input describes your security or compliance posture.

Related tools

Frequently Asked Questions

What issues does it look for?

Security-relevant settings left at permissive defaults, running as root, no resource limits, privileged containers, missing security contexts, that are weaknesses and compliance gaps.

Why do these matter for compliance?

Because benchmarks that compliance frameworks reference expect these settings to be hardened. Leaving them at defaults is both a risk and a gap.

Is this scanning my cluster?

No. It reviews the manifests you provide, before they are applied, so you can harden your own configurations.

Why audit rather than review by eye?

Because spotting these issues in a wall of YAML by hand is unreliable. A systematic audit surfaces them consistently.

Is my configuration uploaded?

No. The audit runs entirely in your browser.

Privacy & Security

Processed locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.