Inventory
Discover namespaces, workloads, Istio resources, Gateway API routes, proxy versions, ztunnel, and waypoints.
Community release · v0.2.0
OpenMeshGuard resolves deployed mTLS and authorization for sidecar, ambient, and mixed meshes. Every conclusion carries the policies that produced it, so you can inspect the evidence and act on what is known. Add an optional Prometheus endpoint to compare sidecar configuration with observed destination mTLS evidence.
payments/frontend-gatewayWildcard host exposes an internal serviceclaims-prodWorkload has no explicit authorization coverageztunnel coverage2 scheduled nodes have missing ambient evidenceWhy it exists
Available in v0.2.0
Start with a lean Go CLI that reads Kubernetes, Istio, and Gateway API resources using explicit least-privilege RBAC. OpenMeshGuard reports effective posture and missing evidence with remediation guidance. Missing permissions and unclassified context stay unknown; declared and runtime-verified posture remain separate.
Discover namespaces, workloads, Istio resources, Gateway API routes, proxy versions, ztunnel, and waypoints.
Resolve effective mTLS and authorization; evaluate gateway exposure, ambient enforcement gaps, ownership, and exceptions.
Export canonical JSON, SARIF, and self-contained HTML. Use weighted scores and opt-in CI thresholds with explicit unknowns.
Install and scan
Download signed archives for macOS and Linux, on Intel / amd64 or arm64. Verify the archive and signed checksumsbefore extraction, then put the binary on your PATH. Homebrew is also available through the public OpenMeshGuard tap. A Go toolchain is an alternative.
The scanner uses only Kubernetes get/list operations. It never reads Secrets, changes resources, installs Istio, or opens exec sessions. Review the RBAC profiles.
# Install with Homebrew
brew install openmeshguard/tap/openmeshguard
# Alternative install with Go 1.24+
go install github.com/openmeshguard/openmeshguard/cmd/openmeshguard@v0.2.0
openmeshguard version
# Scan one namespace; save canonical JSON
openmeshguard scan --context my-cluster --namespace payments > report.json
# Render self-contained HTML and SARIF
openmeshguard report --input report.json --format html --output report.html
openmeshguard export --input report.json --format sarif --output report.sarif
# Inspect scores from the same evidence
openmeshguard score --input report.jsonOptional runtime evidence
Use a Prometheus endpoint containing metrics for the scanned cluster only. Declared and runtime-verified posture stay separate. The default lookback is seven days; the report shows the actual window when collection degrades.
The mTLS event share combines HTTP request events and TCP connection-opening events; it does not measure bytes or compare traffic volume across protocols. Plaintext observed during the window can predate the current policy. Missing telemetry stays unknown, and no traffic does not prove protection.
# Add destination-side runtime evidence
openmeshguard scan --context my-cluster --namespace payments \
--prometheus-url https://prometheus.example.com \
--prometheus-token-file /path/to/prometheus-token \
--prometheus-lookback 168h > verified-report.json
openmeshguard report --input verified-report.json --output verified-report.htmlSupport and boundaries
Sidecar, ambient, and mixed meshes are supported. A scan evaluates one cluster at a time. Multi-cluster participation can be detected; cross-cluster policy correlation is future work.
Prometheus adds observed destination plaintext and the mutual TLS share of combined HTTP request and TCP connection-opening events. Missing telemetry and no observed traffic cannot establish a pass. Ambient/mixed runtime verification and source attribution remain unsupported.
Read the telemetry boundariesReport unexpected results with the affected policy and resolution chain. Distribution validation, lifecycle controls, offline scanning, and GitOps drift are future work.
Report a finding or ask a questionOpenMeshGuard produces security posture evidence, not a compliance certification. Lifecycle scores remain unknown until lifecycle controls ship.