Cortex Cloud: Issues are not being generated from Cloud Workload Misconfiguration Policies for Kubernetes Clusters

Cortex Cloud: Issues are not being generated from Cloud Workload Misconfiguration Policies for Kubernetes Clusters

146
Created On 06/29/26 21:38 PM - Last Modified 07/29/26 17:25 PM


Symptom


Misconfiguration scan results appear in findings, but do not appear in Issues table, despite having a policy set to do so.



Environment


  • Cortex Cloud
  • Cloud Workload Policies for Kubernetes


Cause


The policy scope being set to a static asset group with a particular cluster selected - Not currently supported.

The policy scope being set to a dynamic asset group filtered by "Name contains <Cluster Name>" - Not currently supported.



Resolution


To get a Cloud Workload Policy to generate misconfiguration issues from a Kubernetes resource, the asset group that the policy is scoped to must be set a certain way and the policy cannot be scoped to 'all'. 

  1. 1. Navigate to Inventory > Assets > Groups, right-click the asset group that is already scoped to the Cloud Workload Policy.
  2. Select "View Selected", uncheck anything that is already selected and remove all filters in the group.
  3. Select "Show Filters" underneath the group name on the top left, type in "Kubernetes Resource Cluster", and select it.
  4. Verify the filter states "Kubernetes Resource Cluster Contains <Your Cluster Name> and select "Save Dynamic Group" on the bottom right.
  5. Navigate to Posture Management > Kubernetes Security > Kubernetes Clusters, right-click your cluster, and select "Request Scan".
  6. Select both check boxes and execute the scan. Allow 30 minutes to confirm misconfiguration issues are now properly generating.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000sZ1qKAE&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail