Aqua Blog

Integrate Aqua and VMware Tanzu to Control What Happens in Your Private Cloud

Integrate Aqua and VMware Tanzu to Control What Happens in Your Private Cloud

TL;DR Highly regulated industries like financial services often choose private cloud platforms such as VMware Tanzu Application Service (TAS) to retain greater control over their infrastructure, applications and sensitive data. That control does not remove risk at runtime, where exploitation actually happens and where a patch cycle often cannot catch up in time. Aqua’s integration with VMware Tanzu closes that gap.

What does the Aqua integration with VMware Tanzu do?

Aqua has partnered with VMware to protect applications running on Tanzu Application Service, Tanzu Kubernetes Grid Integrated Edition and VMware Kubernetes environments, including Tanzu Kubernetes Grid and vSphere Kubernetes Service. Aqua Security for VMware Tanzu provides vulnerability, malware and secrets scanning for application artifacts and Droplets, plus runtime policy enforcement for TAS, TKGI, TKG and vSphere Kubernetes Service workloads, so teams can prevent noncompliant artifacts from being deployed, contain threats in production and produce evidence for investigations and compliance.

That protection follows the application through its lifecycle, from the artifact that has not shipped yet to the workload that is already running.

Before deployment, Aqua Security Scanner for VMware Tanzu scans TAS Droplets and container artifacts from build, CI/CD and Blobstore workflows for vulnerabilities, malware, embedded secrets and configuration issues. Findings are evaluated against Aqua Assurance Policies so noncompliant artifacts can be prevented from progressing to production.

Once a workload is running, Aqua Security Enforcer for VMware Tanzu takes over. It observes process, file, network and workload activity, enforces immutability and behavioral policy, and can alert on or block unauthorized changes, suspicious connections, malware and other policy violations across TAS applications, Diego cells and supported Kubernetes workloads.

Regulated organizations, financial services chief among them, choose Tanzu because it lets them run private cloud infrastructure under their own control. Aqua extends that same principle to runtime, so control does not stop at the infrastructure layer. It reaches into the Droplets, Diego cells and Kubernetes workloads actually running the application.

How does the Aqua and VMware integration work?

Aqua Security Scanner for VMware Tanzu runs earlier in the lifecycle. It can be invoked during staging or deployment, through a CI/CD pipeline, sometimes called the Aqua CICD Scanner, or against artifacts already stored in the Blobstore, and noncompliant Droplets or artifacts can be stopped before they reach production.

Aqua Security Enforcer for VMware Tanzu picks up where the Scanner leaves off. For Tanzu Application Service, Enforcers are deployed through BOSH directly to the Diego cells that run application instances. For Kubernetes environments such as TKGI, TKG and vSphere Kubernetes Service, Enforcers run on supported cluster nodes. Once deployed, the Enforcer applies the runtime policy configured in Aqua Platform, the central console that manages both scanning and enforcement across every connected Tanzu environment. When remediation is not immediately possible, teams can apply compensating controls such as a virtual patch to reduce exploitability while a permanent fix is scheduled.

What does this integration mean for Aqua customers?

Vulnerability findings get resolved instead of stacking up. Aqua traces vulnerabilities found in running workloads back to the specific image and service owner responsible, so developers get production level context instead of a raw scan report with no owner attached.

Remediation stays realistic even when patching cannot happen right away. Aqua’s virtual patching, delivered through VShield, reduces exploitability on TKG workload clusters so a known issue does not stay wide open while a permanent fix waits.

Runtime policy protects the applications that matter most. Enforced immutability on Diego cells and Kubernetes nodes stops unauthorized changes before they take hold, and behavioral enforcement limits lateral movement and privilege escalation so one compromised workload does not turn into an environment-wide incident.

Investigations rest on evidence, not guesswork. Aqua observes process, file, network and memory activity inside running Kubernetes workloads to identify known and novel attacks. On TKG workload clusters specifically, Aqua can also capture container memory before a workload terminates, so investigators work from the actual state of the system at the time of compromise instead of reconstructing it after the fact.

Where does this matter most?

Production risk reduction. Because Aqua ties vulnerability findings to real exposure in running Droplets, images, services and workloads, security teams can prioritize the fixes that actually lower risk instead of working down an undifferentiated backlog.

Active incident containment. When Aqua’s Enforcer blocks a reverse shell, a suspicious network connection or cryptomining activity on a TAS app or Kubernetes workload, that containment happens inside the workload itself, without waiting on a human led response.

Audit and compliance reporting. Runtime policy enforcement across TAS, TKGI, TKG and vSphere Kubernetes Service produces evidence that maps to PCI DSS, HIPAA, GDPR, CIS Benchmarks and other regional requirements, and that evidence can be exported into SIEM, GRC and internal reporting platforms through APIs and direct query access. For financial services and other regulated organizations, that is evidence of enforcement, not just a record of what was observed.

What do you need to get started?

Aqua Security for VMware Tanzu is available today for organizations running Tanzu Application Service, Tanzu Kubernetes Grid Integrated Edition, Tanzu Kubernetes Grid or vSphere Kubernetes Service. Aqua Security Scanner for VMware Tanzu is distributed through the Broadcom Support Portal, and Aqua Security Enforcer for VMware Tanzu is distributed directly through Aqua Security.

Visit the Aqua Security for VMware Tanzu solution page to learn more, consult the Aqua documentation for deployment details, or request a demo to see scanning and runtime enforcement working together on Tanzu.

If you are heading to VMware Explore in Las Vegas, stop by Aqua at Booth #302 and see it in action. The show runs August 31 to September 3, 2026 at The Venetian Convention and Expo Center.

FAQ
What is the difference between Aqua Security Scanner and Aqua Security Enforcer for VMware Tanzu?

The Aqua Scanner checks Droplets and container artifacts for vulnerabilities, malware and secrets before deployment. The Enforcer applies runtime policy and behavioral enforcement inside Diego cells and Kubernetes nodes after deployment. Neither replaces the other. Together they cover the artifact before it runs and the workload while it is running.

Is the Aqua CICD Scanner a separate product?

No. It is Aqua Security Scanner for VMware Tanzu invoked from a CI/CD pipeline, typically through the scanner container, its command line interface or a CI integration such as Jenkins. It shares the same scanning engine and assurance policy as the Scanner used during staging or against the Blobstore.

Does this work across both Tanzu Application Service and Kubernetes?

Yes. Aqua Security for VMware Tanzu covers Tanzu Application Service, Tanzu Kubernetes Grid Integrated Edition, Tanzu Kubernetes Grid and vSphere Kubernetes Service, with the Enforcer adapting to Diego cells or Kubernetes nodes depending on the environment.

Aqua Team
Aqua Security is the pioneer in securing containerized cloud native applications from development to production. The Aqua full lifecycle solution prevents attacks by enforcing pre-deployment hygiene and mitigates attacks in real time in production, reducing mean time to repair and overall business risk. The Aqua Platform, a Cloud Native Application Protection Platform (CNAPP), integrates security from Code to Cloud, combining the power of agent and agentless technology into a single solution. With enterprise scale that doesn’t slow development pipelines, Aqua secures your future in the cloud. Founded in 2015, Aqua is headquartered in Boston, MA and Ramat Gan, IL protecting over 500 of the world’s largest enterprises.
Need to secure enterprise workloads?

Aqua Cloud Native Application Protection Platform (CNAPP)

Go cloud native with the experts!