Generate SBOMs for containers and Kubernetes

Create SBOMs for container images and Kubernetes clusters with Observer CLI, and review an image layer by layer.

Generate an SBOM for one container image, or for every image running in a Kubernetes cluster, and upload it to SBOM Observer.

Scan a container image

observer image runs a container scanner to create a CycloneDX SBOM of an image: Trivy by default, or Syft with --scanner syft. Install the scanner first.

Scan the image

observer image -o app.cdx.json nginx:latest

The SBOM lists the image's OS packages and application dependencies.

Upload to SBOM Observer

observer upload app.cdx.json

Or in the web interface: Attestations, then Upload.

Pass a full image reference for other registries:

observer image -o app.cdx.json docker.io/library/nginx:latest
observer image -o app.cdx.json ghcr.io/myorg/myapp:v1.2.3

See the CLI reference for all options.

An SBOM from any other tool works too, as long as it is CycloneDX or SPDX:

docker run -v ./output:/output aquasec/trivy image \
  -q --scanners vuln \
  --format cyclonedx \
  --output /output/result.cdx \
  nginx:latest

observer upload output/result.cdx

Scan a Kubernetes cluster

observer k8s finds the images running in a cluster, control plane included, and with --sbom creates an SBOM for each one.

Experimental

The k8s command is experimental and may change or be removed in a future release.

Prerequisites: kubectl configured for the cluster, Trivy or Syft installed for the image SBOMs, and OBSERVER_TOKEN set for the upload.

observer k8s --sbom --upload

This uses the current kubeconfig context and all namespaces, creates an SBOM per image, and uploads the SBOMs. It also uploads a snapshot of the cluster's resources. SBOM Observer doesn't import cluster snapshots, so the snapshot is listed under the Invalid tab on the Attestations page. -n limits it to given namespaces, --kubeconfig picks another config, and --scanner and -o work as for image. See the CLI reference.

Review an image layer by layer

Open the image from Components (filter Type to container). Its page lists the base images and every layer with the components, vulnerabilities, and policy violations it added, so you can see which build step brought in a vulnerable package.

Next steps