Kvisor
Configure, install, and upgrade the Cast AI Kvisor cluster observability agent.
Kvisor is Cast AI's cluster observability agent. It collects network traffic flows, resource usage statistics, GPU metrics, and storage data that powers Cast AI's monitoring and cost features. When security insights are enabled, Kvisor additionally performs image vulnerability scanning and compliance checks.
What is Kvisor?
Kvisor operates as both a Kubernetes controller (Deployment) and an agent (DaemonSet). The controller reconciles cluster state and schedules assessment jobs; the agent runs on each node to collect real-time telemetry.
The agent is lightweight and minimally invasive. By default it runs in a read-only observability mode — security features are opt-in additions to this baseline.
Key capabilities
Network traffic monitoring
Kvisor collects Kubernetes network flows using eBPF. This data powers Cast AI's network cost monitoring feature, giving you visibility into pod-to-pod and pod-to-external traffic patterns across IPv4 and IPv6.
Resource metrics
Kvisor collects storage utilization, Pressure Stall Information (PSI) metrics, and CPU/memory/I/O usage statistics from containers and nodes. This data surfaces in the Cast AI console's Node list and powers reliability metrics.
GPU metrics
On clusters with NVIDIA GPUs, Kvisor collects GPU utilization data via DCGM Exporter. This powers Cast AI's GPU utilization monitoring feature.
Cluster proxy
When enabled, the Kvisor controller exposes a cluster proxy that lets Cast AI query the Kubernetes API on demand for live cluster state — including container logs for OpsPilot troubleshooting. It runs under a dedicated ServiceAccount and ClusterRole (separate from the main Kvisor service account) with read-only (get, list, watch) access. See Kvisor Cluster Proxy permissions.
Container image vulnerability scanning (optional)
When enabled, Kvisor scans container images running in your cluster against known vulnerability databases. It evaluates both public and private registries and provides severity assessments based on CVSS scores. See Vulnerabilities for details.
Compliance checks (optional)
When enabled, Kvisor evaluates your Kubernetes environment against security best practices, identifying misconfigurations and validating RBAC settings. See Compliance for details.
Architecture
Kvisor operates with a two-component architecture:
-
Kvisor Controller (Deployment): Communicates with the Cast AI control plane, reconciles cluster state, and schedules scanning jobs.
-
Kvisor Agent (DaemonSet): Runs on every node to collect real-time telemetry. Required for netflow monitoring, resource metrics, and GPU metrics.
Permissions
Kvisor uses the same base permission set as the standard Cast AI agent, plus additional permissions for its cluster proxy component. For detailed information, see Kubernetes permissions.
Extended system permissions
Some optional features require additional system-level privileges.
Kube-bench configuration validation
The Kvisor Controller schedules castai-kube-bench jobs to validate kubelet and other system components against security benchmarks. These jobs require elevated privileges to access system configuration files.
Required privileges:
- HostPID access
Read-only host mounts:
/var/lib/kubelet/etc/systemd/etc/kubernetes/home/kubernetes
Updated 4 days ago
