Aqua Security
Full-lifecycle container and cloud-native security platform from build scanning to runtime control.
Technical Architecture & Overview
Aqua secures container images during build, controls what runs at deploy time through admission policies, and monitors runtime behavior with drift prevention and container firewall controls. The platform covers VMs, serverless, and Kubernetes alongside containers, and the company maintains major open source projects including Trivy and kube-bench. Assurance policies enforce image immutability in production.
Targeted Technical Use Cases
Container-heavy estates that want enforceable runtime controls, not just scanning.
Evaluation & Trade-offs
Core Strengths
- +Runtime enforcement with drift prevention.
- +Open source tooling lineage (Trivy, kube-bench).
- +Mature Kubernetes admission control.
Trade-Offs & Limitations
- -Agent deployment per host for full runtime features.
- -Console breadth needs role-based rollout.
Defensive Security Application
Blocking vulnerable or unauthorized containers from running and detecting drift at runtime.
Frequently Asked Questions
What is Aqua Security?→
Aqua secures container images during build, controls what runs at deploy time through admission policies, and monitors runtime behavior with drift prevention and container firewall controls. The platform covers VMs, serverless, and Kubernetes alongside containers, and the company maintains major open source projects including Trivy and kube-bench. Assurance policies enforce image immutability in production.
What is Aqua Security used for?→
Container-heavy estates that want enforceable runtime controls, not just scanning.
What are the strengths of Aqua Security?→
- +Runtime enforcement with drift prevention.
- +Open source tooling lineage (Trivy, kube-bench).
- +Mature Kubernetes admission control.
What are the limitations of Aqua Security?→
- +Agent deployment per host for full runtime features.
- +Console breadth needs role-based rollout.
How is Aqua Security used defensively?→
Blocking vulnerable or unauthorized containers from running and detecting drift at runtime.