Kubernetes clusters face probing attempts within 18 minutes of deployment. OpenShift was built to handle that - hardened by default, compliance-friendly, and designed to run anywhere from public cloud to air-gapped datacenters. But the platform being secure isn’t the same as your environment being secure. Your workloads, configurations, identities, and data are your responsibility. That’s the shared responsibility model, and it’s where most security gaps live.
A Unified Security Model for OpenShift
Security teams responsible for securing OpenShift are often forced to stitch together a platform for posture management, a separate tool for runtime detection, standalone compliance tooling, and fragmented admission controls - with no unified view of how those risks connect to the rest of their infrastructure.
Securing your side of the shared responsibility model means having visibility before a workload is deployed, while it’s running, and across every environment it touches - from cloud to bare metal to air-gapped.
Wiz approaches OpenShift security as a continuous lifecycle:
Mapping your Kubernetes architecture, and cloud relationships
Continuously validating posture and compliance
Blocking insecure workloads before they reach production
Detecting threats in real-time as they unfold
Every signal feeds into Wiz’s Security and Investigation Graph’s so instead of correlating OpenShift signals across disconnected tools, your team gets a single, contextual view of risk and threats across your entire OpenShift environment.
Mapping your Kubernetes across every environment
Kubernetes and OpenShift security starts with understanding how everything connects - which workloads have excessive permissions, which identities have paths to cloud resources, which ingress configurations expose services to the internet. Without that map, you’re not managing risk, you’re guessing at it.
Wiz Kubernetes Connectors continuously interrogate Kubernetes and OpenShift APIs to build that map, feeding metadata directly into the Wiz Security Graph. For self-managed OpenShift environments - whether running on VMware, bare-metal, or disconnected infrastructure - Wiz models each cluster as a first-class entity, making it possible to see exactly how your OpenShift workloads relate to cloud identities, internet exposure, vulnerable packages, and potential attack paths. That includes lateral movement opportunities that span hybrid infrastructure and would never surface in a tool that only sees one environment at a time.
The result is unified inventory and risk visibility across your entire OpenShift and Kubernetes footprint - not a siloed view of your clusters, but a complete picture of how they connect to everything else.
Extending visibility to on-prem OpenShift workloads
Wiz extends security coverage to on-prem and hybrid OpenShift environments through our Wiz Runtime Sensor and the Sensor Workload Scanner - continuously evaluating running workloads for vulnerabilities, malware, exposed secrets, sensitive data, and host misconfigurations. This matters beyond the cluster itself: an on-prem OpenShift workload storing AWS credentials or cloud API keys isn’t just a local risk, it’s a lateral movement path to your cloud environment.
Every finding feeds into the same unified view of risk - so whether a threat originates in the cloud or in an on-prem OpenShift cluster, your team sees the full picture in one place.
From Compliance Checkbox to Actual Risk
Modern OpenShift security isn’t just about detecting threats after workloads are deployed - it’s about continuously validating that clusters are configured according to security best practices before those threats materialize. But most compliance tools treat this as a separate audit workflow, disconnected from the actual risk picture.
Wiz KSPM continuously evaluates Kubernetes and OpenShift environments against security frameworks and compliance benchmarks - including the CIS Red Hat OpenShift Container Platform Benchmark, PCI DSS, SOC 2, HIPAA, and NIST - identifying risky configurations, weak RBAC relationships, privilege escalation paths, exposed services, and configuration drift as they happen. For OpenShift customers operating in regulated industries, this means continuous validation against the frameworks that matter most to their business, not just a point-in-time snapshot.
What makes this different is context. A misconfigured RBAC policy becomes significantly more dangerous when it’s combined with internal exposure and a lateral movement path to cloud credentials - and that’s exactly the kind of combined risk Wiz surfaces, helping teams move beyond checklist compliance (which is needed) and prioritize risks to fix that are exploitable.
Prevent risk before deployment with Wiz Admission Controller
Continuous risk analysis of your production environments helps your Cloud Security and Vulnerability Management teams prioritize the most critical attack paths - but the best time to catch an insecure workload is before it ever reaches production. That’s where the Wiz Admission Controller (AC) comes in.
The Wiz Admission Controller centrally enforces Kubernetes and OpenShift security policies using admission webhooks, giving teams the ability to proactively govern deployments before workloads are admitted into clusters. That means only images from trusted registries make it through, privileged containers and root-running workloads are blocked at the gate, and pods without resource limits or improper NodePort exposure are caught before they become a problem.
For software supply chain security, Wiz AC ensures only trusted and validated images move from CI/CD pipelines into production - with policy enforcement extending across Kubernetes manifests, Helm charts, and Dockerfiles. This is especially valuable in OpenShift environments running multi-tenant clusters, GitOps workflows, and shared platform engineering teams, where a single insecure workload can have outsized impact across the environment.
Detecting Threats as they happen with the Runtime Sensor
The Wiz Runtime Sensor is a lightweight sensor that delivers deep runtime visibility with minimal operational overhead - monitoring running processes, network connections, file activity, system calls, container execution, and suspicious process behavior across Kubernetes, OpenShift, Linux hosts, and hybrid infrastructure.
When a threat is detected, Wiz doesn’t just alert - it investigates. Wiz’s Forensics combines runtime telemetry, process lineage, Kubernetes context, cloud relationships into a unified storyline, so SOC analysts and IR teams can understand exactly how an attack unfolded without manually having to stitch together isolated alerts across tools.
For an example, take a privileged OpenShift workload that executed nsenter and chroot operations to interact with host namespaces - activity commonly associated with container escape attempts, privilege escalation, and node compromise. The Wiz Runtime Sensor immediately generates a critical runtime detection, correlating process execution, container privilege level, Kubernetes workload context, and OpenShift node relationships into a single investigation.
Built for OpenShift, not Just Kubernetes
OpenShift introduces additional security considerations that generic kubernetes tools often aren’t built to handle. Security Context constraints (SCCs) - particularly the default restricted-v2 SCC - enforce non-root execution, prevent privilege escalation, and restrict host access across all workloads, including the security tools you deploy. Namespace-specific UID ranges, assigned via openshift.io/sa.scc.uid-range, add another layer of configuration that must align with deployment requirements.
Wiz is built with these OpenShift-specific constraints in mind. Our Kubernetes Connector, Runtime Sensor, Admission Controller, and Sensor-Based Workload Scanner all support OpenShift-aware deployment models via unified Helm deployments - allowing organizations to onboard securely while remaining fully aligned with OpenShift’s operational and security requirements.
One Platform. Every OpenShift Environment.
Securing your side of the OpenShift shared responsibility model doesn’t require a different tool for every environment you run. Wiz brings together kubernetes visibility, continuous posture management, admission control, runtime protection, and AI-powered investigations into a single operational workflow - covering cloud, hybrid, bare-metal, edge, and air-gapped OpenShift deployments from one platform.
If you’re running OpenShift and are a Wiz customer on-board your OpenShift environment into Wiz today, if you’re interested in a demo for how Wiz can help secure your OpenShift environment, schedule a demo today.