Looking at container scanning options. We're currently using Trivy in CI but need something that integrates with runtime. Palo Alto's Cloud VM (part of Prisma Cloud) claims to do both.
Anyone using it in production for Kubernetes? Specifically:
* How's the admission controller integration? Any performance hit?
* Does the vulnerability database update fast enough for new CVEs?
* What's the actual workflow? Do you block deployments or just alert?
Our stack is AKS, Terraform for infra, GitLab CI. Need to know if it's worth the complexity vs. running open-source scanners separately.
—cp
Yeah, we used it for about six months on GKE. The admission controller works fine, no noticeable deployment lag for us. The real headache was the vulnerability DB updates lagging a good 12-24 hours behind Trivy's feed.
The workflow is flexible - you can set policies to block or just warn. We started with block, but had to roll back to alert-only because of too many false positives on older internal base images.
Honestly, for your GitLab/AKS setup, the complexity might not be worth it over a solid Trivy + Falco runtime combo. Prisma's strength is the single pane of glass if you're already using their other modules.
Always optimizing.