---
title: "Quick and easy vulnerability management with Calico Cloud"
source: "https://www.tigera.io/blog/quick-and-easy-vulnerability-management-with-calico-cloud/"
---

[Technical Blog](https://www.tigera.io/category/technical-blog/)

# Quick and easy vulnerability management with Calico Cloud

By [Dhiraj Sehgal](https://www.tigera.io/blog/author/dhiraj-sehgal/) on Aug 09, 2022 • 4 min read

As more enterprises adopt containers, microservices, and Kubernetes for their cloud-native applications, they need to be aware of the vulnerabilities in container images during build and runtime that can be exploited. In this blog, I will demonstrate how you can implement vulnerability management in CI/CD pipelines, perform image assurance during build time, and enforce runtime threat defense to protect your workloads from security threats.

## Image scanning and automatic blocking of high-risk images

The majority of images in CI/CD pipelines have vulnerabilities, misconfigurations, or both. An active cloud-native application protection platform ([CNAPP](https://www.tigera.io/learn/guides/cnapp/)) should scan, identify, and list vulnerabilities in container images based on databases such as NIST and NVD. The active [CNAPP](https://www.tigera.io/learn/guides/cnapp/) should then help teams build security policies to determine which images should be deployed or blocked based on several factors such as severity, last scan timestamp, and organizational exceptions. Given the sheer amount of vulnerabilities that appear daily, users will be easily overwhelmed if they have to address all existing vulnerabilities. Security teams will have to build a deploy/block criteria to prioritize vulnerabilities that they will address first—a workflow that is easy to start but difficult to manage and operate long-term. Hence, security teams should look for a security platform that makes this workflow an automated process by building policies to ensure what images can be deployed and have a level of acceptable security exposure.

An active security platform scans container images on-demand and provides the controls to build policies to admit or deny container images into the pipeline, and these functions are all incorporated into Calico Cloud’s image assurance abilities. With Calico Cloud’s Image Scanning and Admission Controller, DevOps and security teams can:

- Build security policies to block the deployment of vulnerable images automatically whose CVSS score is higher than the specified score.

- Categorize vulnerabilities as pass, warn, or fail. Pass and fail deploy and block images respectively, while warn deploys the image with an alert.

![Screenshot of image scanning results showing pass, warn, and fail statuses for images, supporting automated vulnerability](https://www.tigera.io/app/uploads/2022/08/Image-Scanning-3.png)Fig 1: Image Scanning with Calico Cloud

- Build security policies to deploy container images based on the last scan timestamp. For example, a policy can declare: - Any image that hasn’t been scanned within the last 3 days will not be deployed. - Any image that hasn’t been scanned within the last 7 days will not be deployed.

- Create exceptions based on image version or image type.

![Screenshot of vulnerability exceptions for container images, showing CVEs, tags, and repositories with an option to remove](https://www.tigera.io/app/uploads/2022/08/Vulnerability-Exception.png)Fig 2: Vulnerability exception handling with Calico Cloud

## Runtime view of vulnerabilities and active risk mitigations

DevOps, SREs, and security teams don’t have a simplified security view of Kubernetes deployments due to the distributed and dynamic nature of Kubernetes. This means when a security incident occurs, teams must stitch data from the build and run time together, correlate the data, then use that data to build a security incident response plan. This process can take hours or longer. Organizations with a slow incident response time to security threats risk having customer data stolen, losing business, and sacrificing credibility.

Calico Cloud provides a runtime view of workloads and associated clusters, including their existing vulnerabilities. Calico also looks for anomalies and zero-day threats during runtime with ML-based detection and alerts users for unusual activity, even at the namespace level. If malware or a data exfiltration threat is detected, you can mitigate it by utilizing custom rule sets or Calico’s recommended policies. Combined with the workload communication visibility provided in the Dynamic Service and Threat Graph, you can quickly assess your Kubernetes cluster’s security posture during runtime. Teams will have a security view of their cluster across the stack, with all underlying metadata already correlated. This will allow you to quickly and easily identify threats in the runtime environment. You can use these findings to leverage Calico Cloud’s Policy Board to quarantine the affected workloads in seconds until the security risk is mitigated and solved.

![Calico Cloud's service graph showing runtime network traffic and security policies between namespaces and workloads. Packet](https://www.tigera.io/app/uploads/2022/08/Dynamic-Service-and-Threat-Graph-with-Stats-2.png)Fig 3: Calico Cloud’s Dynamic Service and Threat Graph

## Summary

Effective vulnerability management should be quick, simple, and easy. It should result in minimal service disruptions and strengthen the security posture of your cloud-native application, and Calico Cloud’s Image Assurance is built with that in mind. Try it yourself by signing up for a [free trial of Calico Cloud](https://link.tigera.io/ueOp4).

 

***Ready to learn more? Gain hands-on experience with our upcoming and on-demand [webinars and live online workshops](https://link.tigera.io/ueP6q).***

[Products](https://www.tigera.io/tags/products/)

## Related posts

[![Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/app/uploads/2026/09/Meet-Mylo-An-AI-native-way-to-work-with-Calico.png)](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

#### [Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

By [Phil DiCorpo](https://www.tigera.io/blog/author/phil-dicorpo/)
on Sep 3, 2026

A library of Calico tools and skills — delivered through the Calico MCP Server What if your hardest network question took ten minutes instead of ten days? Anyone who has operated Kubernetes networking at scale...

[Read more](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[![The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/app/uploads/2026/08/The-Safest-Place-to-Run-an-AI-Agent-Is-On-a-Cluster-That-Doesnt-Trust-It.png)](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

#### [The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 27, 2026

Every organization running AI agents has already made a hosting decision. Most made it by accident. The sales team switched on the agent built into their CRM. Engineering is piloting a coding agent in a...

[Read more](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

[![AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/app/uploads/2026/08/AI-Red-Team-Agents-Automate-Attacks-on-your-AI-Agents.-Runtime-Policies-Automate-their-Defense.png)](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

#### [AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 24, 2026

The AI red teaming market grew up fast this year. OpenAI bought Promptfoo, Cisco and Microsoft shipped automated attack suites, and a seed-stage startup publicly compromised 50 of 55 live customer service bots. These platforms...

[Read more](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=3206 metric#misses=33 metric#hit-ratio=99.0 metric#bytes=1548276 metric#prefetches=0 metric#store-reads=176 metric#store-writes=13 metric#store-hits=172 metric#store-misses=22 metric#sql-queries=30 metric#ms-total=453.03 metric#ms-cache=26.56 metric#ms-cache-avg=0.1413 metric#ms-cache-ratio=5.9 sample#redis-hits=10951320 sample#redis-misses=4314712 sample#redis-hit-ratio=71.7 sample#redis-ops-per-sec=56 sample#redis-evicted-keys=0 sample#redis-used-memory=140833952 sample#redis-used-memory-rss=109838336 sample#redis-memory-fragmentation-ratio=0.8 sample#redis-connected-clients=1 sample#redis-tracking-clients=0 sample#redis-rejected-connections=0 sample#redis-keys=140895 -->
