> ## Documentation Index
> Fetch the complete documentation index at: https://docs.polystack.tech/llms.txt
> Use this file to discover all available pages before exploring further.

# Runtime Vulnerability Scanning

> Protect every Kubernetes cluster with StackRox runtime security and scan every container image with Harbor and its built-in Trivy scanner.

## Overview

The On-Prem AI Infrastructure Platform secures containerized AI workloads at two layers.
**StackRox** provides runtime vulnerability scanning and threat detection across every
Kubernetes cluster, and the **Harbor** registry with built-in **Trivy** scans every container
image before it is deployed.

<Note>
  StackRox protection is deployed automatically. Every new cluster created through
  [Polystack K8SaaS](/services/kubernetes/index) is enrolled with no manual onboarding.
</Note>

***

## Architecture

```mermaid theme={null}
graph TD
    subgraph MGMT[Management Cluster]
        CENTRAL[StackRox Central<br/>policy, dashboards, reporting]
    end
    subgraph C1[Kubernetes Cluster A]
        S1[Sensor] --- COL1[Collector]
    end
    subgraph C2[Kubernetes Cluster B]
        S2[Sensor] --- COL2[Collector]
    end
    S1 --> CENTRAL
    S2 --> CENTRAL
    HARBOR[Harbor Registry<br/>built-in Trivy scanner] -->|scanned images| C1
    HARBOR -->|scanned images| C2
```

***

## Components

<Tabs>
  <Tab title="Runtime Security" icon="shield-halved">
    | Component | Location | Role |
    | - | - | - |
    | **StackRox Central** | Management cluster | Central policy engine, vulnerability database, dashboards, and reporting for all clusters |
    | **StackRox Sensor** | Every Kubernetes cluster | Watches the cluster and enforces policy, reporting to Central |
    | **StackRox Collector** | Every node | Captures runtime process and network activity on each node |

    Sensor and Collector are deployed to each cluster automatically, so every cluster is
    covered from creation.
  </Tab>

  <Tab title="Image and Registry Scanning" icon="box-archive">
    | Component | Role |
    | - | - |
    | **Harbor** | Private container registry for platform and team images |
    | **Trivy (built into Harbor)** | Scans images for known vulnerabilities as they are pushed to the registry |

    Scanning at the registry catches vulnerable images before they reach a cluster, while
    StackRox covers what is already running.
  </Tab>
</Tabs>

***

## Coverage

<AccordionGroup>
  <Accordion title="Before deployment" icon="box-archive">
    Harbor with Trivy scans images in the registry, so vulnerable images are identified
    before they are deployed.
  </Accordion>

  <Accordion title="At runtime" icon="eye">
    StackRox continuously scans running workloads and monitors process and network activity
    on every node through the Collector.
  </Accordion>

  <Accordion title="Across the fleet" icon="layer-group">
    StackRox Central gives security teams one view of vulnerabilities and policy violations
    across all Kubernetes clusters on the platform.
  </Accordion>
</AccordionGroup>

***

## Next Steps

<CardGroup cols={2}>
  <Card title="Operator Framework" icon="puzzle-piece" href="/services/ai-platform/operator-framework" color="#bf9667">
    The other platform add-on deployed to every cluster.
  </Card>

  <Card title="MLOps Platform" icon="diagram-project" href="/services/ai-platform/mlops" color="#bf9667">
    The AI cluster template, which includes the Harbor registry.
  </Card>

  <Card title="Kubernetes Security" icon="lock" href="/services/kubernetes/admin-guide/security" color="#bf9667">
    Security configuration for Polystack K8SaaS clusters.
  </Card>

  <Card title="Unified Console" icon="window-maximize" href="/services/ai-platform/unified-console" color="#bf9667">
    One portal and single sign-on across the platform.
  </Card>
</CardGroup>
