Skip to content

Vulnerability scanning

Kaio scans local images for CVEs by running Trivy as a throwaway container. Nothing to install on the host.

Scanning is automatic: in-use images are rescanned every 24 hours by default, starting at server startup, so a report never goes stale on its own. See Scheduled rescans. The scans below are the on-demand way to get a result now.

Scope Web TUI CLI
One image Image row → Scan v on the Images tab n/a
A whole stack ⋮ STACK → Scan v stack scan <name>
Every tagged image POST /api/images/scan n/a n/a

Scans run in the background behind a bounded concurrency semaphore (KAIO_TRIVY_CONCURRENCY, default 2). Results are persisted and the UI updates live over SSE; nothing blocks while a scan runs.

  • Severity badges: colour-coded critical / high / medium / low / unknown counts, per image in the Image Management view.
  • Per-stack and per-container indicators: every stack row shows an aggregated badge, and each container in an expanded stack shows the badge for its own image.
  • Dashboard total: a global tile sums findings across all in-use images. The internal scanner image and unused images are excluded, so the number reflects what is actually running.
  • Detailed report: drill into a per-image modal listing each CVE (package, installed → fixed version, severity, advisory link), filterable by severity.
The per-image vulnerability report: severity filters across the top, then one row per CVE with its package, installed version, fixed version and title.
The per-image report, filterable by severity. Demo data on a demo host: the CVE identifiers are made up.

All aggregation lives in the shared core crate, so the web UI, TUI and CLI report the same numbers.

In-use images are rescanned automatically every KAIO_TRIVY_SCAN_INTERVAL_HOURS hours (default 24), so freshly-disclosed CVEs surface even on images that never changed.

The check runs at startup and at each interval, but only (re)scans images whose last scan is older than the interval, or that were never scanned. That makes it restart-resilient: bouncing the server does not storm the registry or the CPU.

Set the variable to 0 to disable scheduled rescans entirely.

Trivy’s vulnerability database is cached in a dedicated Docker volume, so only the first scan pays the download cost. That first scan runs alone to warm the cache before later scans start running concurrently.

Variable Default Effect
KAIO_TRIVY_IMAGE aquasec/trivy:latest Scanner image: pin it, or point it at a mirror
KAIO_TRIVY_CONCURRENCY 2 Max concurrent scans
KAIO_TRIVY_SCAN_INTERVAL_HOURS 24 Rescan interval; 0 disables

The image_scans table keeps the latest scan per image: severity counts and the full CVE list as JSON. It is indexed on image_name, which backs the join against containers.image hit on every dashboard poll.

Kaio, built by Régis Gaidot