---
title: Scanning pods for vulnerabilities
---

# Scanning pods for vulnerabilities {#pod-vulnerability-scan}

> [!IMPORTANT]
> The Red Hat Quay Container Security Operator has been deprecated and is planned for removal in a future release of OpenShift Container Platform. The official replacement product of the Red Hat Quay Container Security Operator is Red Hat Advanced Cluster Security for Kubernetes.

Using the Red Hat Quay Container Security Operator, you can access vulnerability scan results from the OpenShift Container Platform web console for container images used in active pods on the cluster.

The Red Hat Quay Container Security Operator:

- Watches containers associated with pods on all or specified namespaces
- Queries the container registry where the containers came from for vulnerability information, provided an image’s registry is running image scanning (such as [Quay.io](https://quay.io) or a [Red Hat Quay](https://access.redhat.com/products/red-hat-quay) registry with Clair scanning)
- Exposes vulnerabilities via the `ImageManifestVuln` object in the Kubernetes API

Using the instructions here, the Red Hat Quay Container Security Operator is installed in the `openshift-operators` namespace, so it is available to all namespaces on your OpenShift Container Platform cluster.

## Installing the Red Hat Quay Container Security Operator {#security-pod-scan-cso_pod-vulnerability-scan}

You can install the Red Hat Quay Container Security Operator from the OpenShift Container Platform web console OperatorHub, or by using the CLI.

**Prerequisites**

- You have installed the `oc` CLI.
- You have access to the web console as a user with `cluster-admin` privileges.
- You have containers that come from a Red Hat Quay or Quay.io registry running on your cluster.

**Procedure**

1. You can install the Red Hat Quay Container Security Operator by using the OpenShift Container Platform web console:

   1. On the web console, navigate to **Ecosystem** → **Software Catalog** and select **Security**.
   2. Select the **Red Hat Quay Container Security Operator** Operator, and then select **Install**.
   3. On the **Red Hat Quay Container Security Operator** page, select **Install**. **Update channel**, **Installation mode**, and **Update approval** are selected automatically. The **Installed Namespace** field defaults to `openshift-operators`. You can adjust these settings as needed.
   4. Select **Install**. The **Red Hat Quay Container Security Operator** is displayed after a few moments on the **Installed Operators** page.
   5. Optional: You can add custom certificates to the Red Hat Quay Container Security Operator. For example, create a certificate named `quay.crt` in the current directory. Then, run the following command to add the custom certificate to the Red Hat Quay Container Security Operator:

      ```terminal
      $ oc create secret generic container-security-operator-extra-certs --from-file=quay.crt -n openshift-operators
      ```
   6. Optional: If you added a custom certificate, restart the Red Hat Quay Container Security Operator pod for the new certificates to take effect.
2. Alternatively, you can install the Red Hat Quay Container Security Operator by using the CLI:

   1. Retrieve the latest version of the Container Security Operator and its channel by entering the following command:

      ```terminal
      $ oc get packagemanifests container-security-operator \
        -o jsonpath='{range .status.channels[*]}{@.currentCSV} {@.name}{"\n"}{end}' \
        | awk '{print "STARTING_CSV=" $1 " CHANNEL=" $2 }' \
        | sort -Vr \
        | head -1
      ```

      ```terminal {title="Example output"}
      STARTING_CSV=container-security-operator.v3.8.9 CHANNEL=stable-3.8
      ```
   2. Using the output from the previous command, create a `Subscription` custom resource for the Red Hat Quay Container Security Operator and save it as `container-security-operator.yaml`. For example:

      ```yaml
      apiVersion: operators.coreos.com/v1alpha1
      kind: Subscription
      metadata:
        name: container-security-operator
        namespace: openshift-operators
      spec:
        channel: ${CHANNEL}
        installPlanApproval: Automatic
        name: container-security-operator
        source: redhat-operators
        sourceNamespace: openshift-marketplace
        startingCSV: ${STARTING_CSV}
      ```

      where:

      `spec.channel`
      :   Specifies the values you obtained in the previous step for the `spec.channel`.

      `spec.startingCSV`
      :   Specifies the value you obtained in the previous step for the `spec.startingCSV` parameter.
   3. Enter the following command to apply the configuration:

      ```terminal
      $ oc apply -f container-security-operator.yaml
      ```

      ```terminal {title="Example output"}
      subscription.operators.coreos.com/container-security-operator created
      ```

## Using the Red Hat Quay Container Security Operator {#security-pod-scan-cso-using_pod-vulnerability-scan}

You can use the Red Hat Quay Container Security Operator to access vulnerability scan results from the OpenShift Container Platform web console.

The following procedure shows you how to use the Red Hat Quay Container Security Operator.

**Prerequisites**

- You have installed the Red Hat Quay Container Security Operator.

**Procedure**

1. On the OpenShift Container Platform web console, navigate to **Home** → **Overview**. Under the **Status** section, **Image Vulnerabilities** provides the number of vulnerabilities found.
2. Click **Image Vulnerabilities** to reveal the **Image Vulnerabilities breakdown** tab, which details the severity of the vulnerabilities, whether the vulnerabilities can be fixed, and the total number of vulnerabilities.
3. You can address detected vulnerabilities in one of two ways:

   1. Select a link under the **Vulnerabilities** section. This takes you to the container registry that the container came from, where you can see information about the vulnerability.
   2. Select the **namespace** link. This takes you to the **Image Manifest Vulnerabilities** page, where you can see the name of the selected image and all of the namespaces where that image is running.
4. After you have learned what images are vulnerable, how to fix those vulnerabilities, and the namespaces that the images are being run in, you can improve security by performing the following actions:

   1. Alert anyone in your organization who is running the image and request that they correct the vulnerability.
   2. Stop the images from running by deleting the deployment or other object that started the pod that the image is in.

      > [!NOTE]
      > If you delete the pod, it might take several minutes for the vulnerability information to reset on the dashboard.

## Querying image vulnerabilities from the CLI {#security-pod-scan-query-cli_pod-vulnerability-scan}

You can display information about vulnerabilities detected by the Red Hat Quay Container Security Operator by using the `oc` command.

**Prerequisites**

- You have installed the Red Hat Quay Container Security Operator on your OpenShift Container Platform instance.

**Procedure**

1. Enter the following command to query for detected container image vulnerabilities:

   ```terminal
   $ oc get vuln --all-namespaces
   ```

   ```terminal {title="Example output"}
   NAMESPACE     NAME              AGE
   default       sha256.ca90...    6m56s
   skynet        sha256.ca90...    9m37s
   ```
2. To display details for a particular vulnerability, append the vulnerability name and its namespace to the `oc describe` command. The following example shows an active container whose image includes an RPM package with a vulnerability:

   ```terminal
   $ oc describe vuln --namespace mynamespace sha256.ac50e3752...
   ```

   ```terminal {title="Example output"}
   Name:         sha256.ac50e3752...
   Namespace:    quay-enterprise
   ...
   Spec:
     Features:
       Name:            nss-util
       Namespace Name:  centos:7
       Version:         3.44.0-3.el7
       Versionformat:   rpm
       Vulnerabilities:
         Description: Network Security Services (NSS) is a set of libraries...
   ```

## Uninstalling the Red Hat Quay Container Security Operator {#uninstalling-container-security-operator_pod-vulnerability-scan}

To uninstall the Container Security Operator, you must uninstall the Operator and delete the `imagemanifestvulns.secscan.quay.redhat.com` custom resource definition (CRD).

**Procedure**

1. On the OpenShift Container Platform web console, click **Ecosystem** → **Installed Operators**.
2. Click the Options menu ![](/openshift-docs-markdown/images/kebab.png "Options menu") of the Container Security Operator.
3. Click **Uninstall Operator**.
4. Confirm your decision by clicking **Uninstall** in the popup window.
5. Use the CLI to delete the `imagemanifestvulns.secscan.quay.redhat.com` CRD.

   1. Remove the `imagemanifestvulns.secscan.quay.redhat.com` custom resource definition by entering the following command:

      ```terminal
      $ oc delete customresourcedefinition imagemanifestvulns.secscan.quay.redhat.com
      ```

      ```terminal {title="Example output"}
      customresourcedefinition.apiextensions.k8s.io "imagemanifestvulns.secscan.quay.redhat.com" deleted
      ```

**Additional resources**
{._additional-resources}

- [Quay.io container registry](https://quay.io)
- [Red Hat Quay](https://access.redhat.com/products/red-hat-quay)
