KubeChecker: Detecting Configuration Bugs in Container Orchestration

Yilin Sun, Dian Lyu, Cheng Cui, Hui Xu · 2025

Container orchestration is essential for deploying and managing cloud-native software, enabling applications built from multiple microservices. While this architecture enables continuous integration and autoscaling, it also introduces complex configuration challenges. As a result, even well-deployed applications may have latent configuration defects that emerge only under specific runtime conditions, such as autoscaling. In this paper, we investigate configuration bugs in container orchestration and propose a hybrid detection approach. We begin by constructing a knowledge base of defect patterns through a thorough analysis of official configuration manuals and a survey of related issues reported online. We compare our knowledge base against a dataset of trouble tickets from one of the largest cloud service providers, Huawei Cloud. The results show that our knowledge base successfully covers all tickets related to container orchestration configuration issues. Building on this foundation, we developed a scanning method to identify service configuration vulnerabilities and validate them through fault injection. Evaluation results show that our approach outperforms baseline tools in detecting orchestration defects, and has been successfully validated within an online system.

Read the paper · More papers on PaperTik