Hardware and software requirements

To install and operate Kaspersky Container Security, the following infrastructure requirements must be met:

To implement runtime monitoring with container runtime profiles, orchestrator nodes must meet the following requirements:

Architecture requirements:

Kaspersky Container Security supports the x86 architecture.

Minimum supported versions of Linux distributions and Linux kernels for implementing runtime monitoring using container runtime profiles:

If your infrastructure contains host servers running other Linux distributions, we recommend contacting Technical Support. Technical Support will check the compatibility of the solution with your distributions. If such compatibility is not available, the distributions may be supported by future versions of Kaspersky Container Security.

Kaspersky Container Security ensures correct operation when used in an Istio service mesh infrastructure.

The solution supports integration with Hashicorp Vault 1.7 or later.

Kaspersky Container Security works with ClickHouse 22.6 or later.

When using external database management systems, Kaspersky Container Security supports the following DBMS:

Kaspersky Container Security supports integration with the following image registries:

Kaspersky Container Security supports both IPv4 and IPv6 networks.

Image requirements (OS, version, scanned packages):

When configuring Kaspersky Container Security in a cluster with three worker nodes, three scanner pods (kcs-ih) and a maximum image scan size of 10 GB, the cluster working node must meet the following requirements:

To run agents in a cluster, each worker node must be provided with the following additional resources:

  1. Basic requirements:
    • 0.2 processor cores
    • 200 MB of RAM
    • 15 GB of free disk space
  2. Requirements when enabling the following agent functionalities (additional to the baseline requirements):
    • Network and process monitoring:
      • 2 installed processor cores
      • 2 GB of added RAM
    • Anti-malware protection:
      • 2 installed processor cores
      • 2 GB of added RAM

When all agent functionalities are enabled, the following requirements to additional resources must be met:

An agent on a worker node discontinues its operation if the worker node stops working.

You must allocate free disk space for ClickHouse DBMS taking into account the number of monitored nodes. Each node requires 1 GB of free disk space for ClickHouse Persistent Volume.

The above requirements apply to Kaspersky Container Security deployment only; they do not take into account other loads on the client's resources.

Kaspersky Container Security user workstation requirements:

Page top