logo

When Security Scans Break the Brain: Solving Trivy’s etcd Exhaustion Problem

ID: cbb8f542-e1ee-5fdf-9d50-48ada9858230

STIX ID: report--cbb8f542-e1ee-5fdf-9d50-48ada9858230

Feed Name: Aqua Security Blog

Date Published: 2026-06-30

Date Updated: 2026-07-01

...
...

This article explains how Trivy Operator vulnerability reports stored as Kubernetes CRDs can produce excessive etcd MVCC churn and large objects (hitting the 1.5 MiB API limit), which may exhaust etcd storage and render the API server read-only. It outlines mitigations including moving reports off-etcd to a PVC, configuring report TTLs, running regular etcd compaction and defragmentation, switching to Client-Server mode to reduce scanner overhead, and filtering by severity to limit stored data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.