Kubernetes
The Kubernetes Analyzer provides insights into the state and performance of your Kubernetes clusters, nodes, pods, containers, storage, and events. It enables monitoring of workloads, resource utilization, and detection of potential issues across cluster operations.
Required Blueprints: Kubernetes, Kubernetes GKE

Sightlines
| Sightline | Description |
|---|---|
| Kubernetes Clusters | High-level overview of cluster infrastructure, focusing on clusters, nodes, and pods. |
| Kubernetes Pods | Detailed information about pod usage and statuses within clusters. |
| Kubernetes Nodes | Health and distribution of nodes within clusters. |
| Kubernetes Containers | Visibility into container usage trends and containerized workloads. |
| Kubernetes Storage | Insights into persistent volumes within clusters for tracking storage allocation and usage. |
| Kubernetes Events | Tracks events generated within clusters, providing actionable insights into activity trends and potential issues. |
Explorer Node Types
Use these node types in Explorer or KAI to query resources surfaced by this analyzer:
kubernetes.cluster.Cluster, kubernetes.cluster.Container, kubernetes.cluster.Service, kubernetes.Vulnerability
Related Analyzers
- AWS Compute — Container orchestration on ECS and EKS
- Software Composition Analysis — Container image scanning
- Secrets and PII — Secret management in clusters
- Artifact — Container image vulnerabilities
Insight Feed Alerts
-
Node Resource Usage Alert: Detects nodes approaching resource limits (CPU, memory) to prevent workload failures and ensure cluster stability.
-
Pod CrashLoopBackOff Alert: Flags pods stuck in a CrashLoopBackOff state, indicating potential deployment or configuration issues.
-
Persistent Volume Utilization Alert: Tracks storage volumes nearing full capacity, ensuring smooth operation and avoiding data loss.
-
Event Surge Alert: Highlights a sudden increase in Kubernetes events, which could indicate cluster-wide issues or malicious activity.
-
Inactive Containers Alert: Identifies containers running but not actively performing tasks, helping optimize resource allocation.