Review agent · Infra & pipeline

Container & Kubernetes

Checks Dockerfiles and Kubernetes manifests for root, privileged and host-level access.

k8s/deploy.yaml1securityContext:2 privileged: true3 runAsUser: 04 readOnlyRootFilesystem: falseK8swhat this review answersRoot or privileged container?Added capabilities or host mounts?Is elevated access documented?$ verdict REAL ISSUE$ fix non-root, drop capabilities▍

Illustrative example of how this agent reviews a finding.

Why this agent matters

Containers are only as isolated as their config. Running as root, privileged mode or host mounts turn a compromised app into a compromised node.

These settings are often copied from examples and never revisited. The agent judges whether each container has more host access than it needs.

What it checks

  • Containers running as root or privileged
  • Added Linux capabilities and host path, namespace or network mounts
  • Missing read-only root filesystem
  • Kubernetes workloads without a restrictive securityContext

When it marks a finding as a likely false positive

  • Elevated access is required and documented, e.g. a node agent

The fix it suggests

  • A non-root user
  • Dropping capabilities and a read-only FS
  • A least-privilege securityContext / Pod Security Standard

Scope and limits

This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.

Common questions

Does OpenRouting follow these rules itself?

Yes. Every scanner runs in a container with no network, a non-root user, a read-only repo mount and all capabilities dropped.

Related agents

  • Infrastructure & IaC — Reviews Terraform, Helm, Ansible and server config for insecure defaults and exposure.
  • Cloud security — Checks cloud resources for public exposure, wildcard IAM and long-lived keys.
  • CI/CD pipeline — Checks pipelines for leaked secrets, untrusted code execution and over-broad tokens.

See all 20 review agents → · Agent setup reviewer · How the pipeline works

Run the Container & Kubernetes agent on your repository

100 free credits, no credit card. Every finding comes with a verdict and a fix.

Get started free