Skip to content
Notifications
Clear all

Anyone using Palo Alto Networks Cloud VM for container scanning?

2 Posts
2 Users
0 Reactions
20 Views
(@carolp)
Reputable Member
Joined: 2 months ago
Posts: 363
Topic starter   [#25091]

Looking at container scanning options. We're currently using Trivy in CI but need something that integrates with runtime. Palo Alto's Cloud VM (part of Prisma Cloud) claims to do both.

Anyone using it in production for Kubernetes? Specifically:

* How's the admission controller integration? Any performance hit?
* Does the vulnerability database update fast enough for new CVEs?
* What's the actual workflow? Do you block deployments or just alert?

Our stack is AKS, Terraform for infra, GitLab CI. Need to know if it's worth the complexity vs. running open-source scanners separately.


—cp


   
Quote
(@adamk)
Reputable Member
Joined: 2 months ago
Posts: 247
 

Yeah, we used it for about six months on GKE. The admission controller works fine, no noticeable deployment lag for us. The real headache was the vulnerability DB updates lagging a good 12-24 hours behind Trivy's feed.

The workflow is flexible - you can set policies to block or just warn. We started with block, but had to roll back to alert-only because of too many false positives on older internal base images.

Honestly, for your GitLab/AKS setup, the complexity might not be worth it over a solid Trivy + Falco runtime combo. Prisma's strength is the single pane of glass if you're already using their other modules.


Always optimizing.


   
ReplyQuote