Generate SBOMs for containers and Kubernetes
Create SBOMs for container images and Kubernetes clusters with Observer CLI, and review an image layer by layer.
Generate an SBOM for one container image, or for every image running in a Kubernetes cluster, and upload it to SBOM Observer.
Scan a container image
observer image runs a container scanner to create a CycloneDX SBOM of an image: Trivy by default, or Syft with --scanner syft. Install the scanner first.
Scan the image
observer image -o app.cdx.json nginx:latestThe SBOM lists the image's OS packages and application dependencies.
Upload to SBOM Observer
observer upload app.cdx.jsonOr in the web interface: Attestations, then Upload.
Pass a full image reference for other registries:
observer image -o app.cdx.json docker.io/library/nginx:latest
observer image -o app.cdx.json ghcr.io/myorg/myapp:v1.2.3See the CLI reference for all options.
An SBOM from any other tool works too, as long as it is CycloneDX or SPDX:
docker run -v ./output:/output aquasec/trivy image \
-q --scanners vuln \
--format cyclonedx \
--output /output/result.cdx \
nginx:latest
observer upload output/result.cdxScan a Kubernetes cluster
observer k8s finds the images running in a cluster, control plane included, and with --sbom creates an SBOM for each one.
Experimental
The k8s command is experimental and may change or be removed in a future release.
Prerequisites: kubectl configured for the cluster, Trivy or Syft installed for the image SBOMs, and OBSERVER_TOKEN set for the upload.
observer k8s --sbom --uploadThis uses the current kubeconfig context and all namespaces, creates an SBOM per image, and uploads the SBOMs. It also uploads a snapshot of the cluster's resources. SBOM Observer doesn't import cluster snapshots, so the snapshot is listed under the Invalid tab on the Attestations page. -n limits it to given namespaces, --kubeconfig picks another config, and --scanner and -o work as for image. See the CLI reference.
Review an image layer by layer
Open the image from Components (filter Type to container). Its page lists the base images and every layer with the components, vulnerabilities, and policy violations it added, so you can see which build step brought in a vulnerable package.
Next steps
- Generate and upload SBOMs for the other upload options.
- Enforce policies in CI/CD to fail an image build on a
fail-buildviolation. - Analyze vulnerability impact to see which images and projects include a vulnerable package.
- Share SBOMs with customers to export an image's SBOM.