Civo
SBOM generation and vulnerability scanning on Civo Kubernetes (k3s or Talos): save the kubeconfig with the civo CLI, install the Helm chart, verify it reports.
Civo clusters are k3s or Talos under the hood, and both run the scanner unchanged. Civo’s small default node sizes are the only thing to watch: the scanner’s requests are modest, but leave room for the image scratch space.
Prerequisites
- A Civo cluster and the civo CLI with an API key configured.
- Helm 3.8+ and kubectl.
- A free StackRadar account.
Point kubectl at your Civo Kubernetes cluster
bashcivo kubernetes config <cluster-name> --save --switch kubectl get nodesInstall the scanner
Create a cluster in the StackRadar dashboard and copy its cluster ID and cluster-scoped API key (see API keys & cluster scoping):
bashexport STACKRADAR_API_KEY=<your-api-key> export STACKRADAR_CLUSTER_ID=<your-cluster-id>Then install the scanner chart (Helm 3.8+ for the OCI method). The command pins the current release,
0.3.0— published versions are immutable, so the install is reproducible.bashhelm install stackradar-scanner \ oci://ghcr.io/lockdep/charts/stackradar-scanner \ --version 0.3.0 \ --namespace stackradar --create-namespace \ --set stackradar.apiKey=$STACKRADAR_API_KEY \ --set stackradar.clusterId=$STACKRADAR_CLUSTER_IDVerify
bashkubectl get pods --namespace stackradarOnce the pod is
Running, the scanner sends a heartbeat and the cluster shows as connected in the dashboard. SBOMs for running workloads follow within a few minutes. If the cluster never connects, see Troubleshooting.
Civo notes
- Talos-based Civo clusters enforce the restricted Pod Security profile; the chart’s defaults satisfy it.
- Small nodes: on the smallest instance sizes, lower watcher.scratchSizeLimit so the scanner never competes with your workloads for disk.
- Civo’s marketplace can install Helm charts, but the StackRadar chart is not listed there; install it with Helm directly as below.
Images from a private registry? The scanner pulls each image itself and reuses the imagePullSecrets your pods declare. If your nodes authenticate some other way, give the scanner a credential via dockerConfigSecret — see authenticating to a private registry. No public egress at all? Same page: restricted-network installs.
What happens after install
The scanner reports the cluster's workload inventory first — namespaces, workloads, containers, plus the Helm releases and GitOps applications that deliver them — so the dashboard shows every discovered workload and its scan coverage right away. Its first pass covers the whole cluster, not just new deploys: the initial sync lists every pod already running, and each container image is queued for scanning immediately. The scanner generates a CycloneDX SBOM per image and uploads it for matching against 900K+ OSV.dev advisories, then keeps coverage current as pods start, restart, or change — no scan schedules to configure. See architecture & data flow for what runs where and exactly what data leaves the cluster.
Next steps
- Architecture & data flowHow the StackRadar scanner works: what runs in your cluster, exactly what data leaves it, how SBOMs are matched to vulnerabilities, and where data is stored.
- TroubleshootingFixes for common StackRadar scanner issues: 401/403 API errors, a cluster that never appears in the dashboard, Helm install failures, and missing SBOMs.