On-demand scanning applies to individual Kubernetes clusters managed by an active Cortex Cloud KSPM connector. On-demand scanning does not replace scheduled scan cycles and does not support bulk operations across multiple clusters simultaneously.
Prerequisites
Before requesting an on-demand scan, verify the following:
A KSPM connector is deployed on the target cluster. If no connector is deployed, the context menu displays a Deploy connector option instead of Request scan.
Ensure the Kubernetes connector for the target cluster is active and sends heartbeats to Cortex Cloud every 15 minutes.
The KSPM connector is running version 2.0 or later. This version includes redefined cluster-level RBAC permissions that enhance security by restricting access to specific namespaces where possible.
Note
If the Kubernetes connector for the target cluster sent a heartbeat more than 15 minutes ago, the Kubernetes Cluster Scan Now dialog displays the message: Action temporarily unavailable. The connector connectivity cannot currently be verified.
The Request scan option is available to all Cortex Cloud users with access to the Kubernetes Clusters inventory. No additional role-based permissions are required to request a scan.
Scan types
The Request scan dialog provides the following scan types:
Scan Type | Description | Cooldown Period | Default State |
|---|---|---|---|
Inventory | Collects and updates the full inventory of Kubernetes resources in the cluster. | 1 hour | Enabled |
Nodes | Scans all nodes in the cluster, including container images, for vulnerabilities and misconfigurations. | 6 hours | Disabled |
Important
The nodes and containers scan is both CPU and memory-intensive. Run the scan no more than once every six hours to avoid performance degradation on the target cluster.
Each scan type enforces a cooldown period after a successful request. When a scan type is in cooldown, the corresponding checkbox is disabled, and a countdown badge indicates when the next scan request becomes available.
Request an on-demand scan
The Request scan option is available from two locations in the Cortex Cloud console:
From the Kubernetes cluster asset detail panel:
Go to → .
Either right-click the target Kubernetes cluster row in the inventory table and select Request scan or open the asset detail panel and from the actions menu, select Request scan.
In the Request scan dialog, review the cluster details - cluster name, cluster distribution (EKS, AKS, GKE, OpenShift, or Kubernetes), cloud account name, and cloud provider.
Under Select scan type, select one or both scan types (Inventory scan, Nodes & containers scan) and then select Request.
Note
If the connector version is earlier than 2.0, the Request scan option appears as Request scan (Update required) and is disabled. Upgrade the Kubernetes connector to version 2.0 or later to enable on-demand scanning.
Results
After a successful request, Cortex Cloud displays the Scan Requested confirmation, followed by one of the following messages:
An Inventory scan was successfully requested
A Nodes and Containers scan was successfully requested
The connector is inactive (no heartbeat received in the last 15 minutes).
Known limitations:
The scan executes after the next connector heartbeat (approximately 30 seconds), not immediately upon request.
Bulk scan requests across multiple clusters simultaneously are not supported.
Customization of cooldown periods is not available through the Cortex Cloud console.
A historical audit log of on-demand scan requests is not available.