Kubernetes Managed
Visualize Kubernetes resources and monitor changes through queries and alerts.
- Installation
- Migration
- Authorization
- Data Model
- Types
- Release Notes
Installation
Prerequisites
See the Migration tab for the full cutover sequence, data model differences, and answers to common migration questions.
Before installing the Kubernetes Managed integration, you must have a Kubernetes collector running. For instructions on setting up the Kubernetes collector, see the Kubernetes collector documentation.
- Web
- Helm
Configuration in JupiterOne
-
Navigate to the Integrations tab in JupiterOne and select Kubernetes Managed.
-
Click New Instance to begin configuring your integration and provide the following:
-
The Account Name used to identify the Kubernetes account in JupiterOne. Ingested entities will have this value stored in
tag.AccountNamewhen theAccountNametoggle is enabled. -
Description to assist in identifying the integration instance, if desired.
-
When prompted about where should this run, select the Kubernetes collector you created in the prerequisites.
-
Use Default Kubernetes Configuration (optional): Enable when running the integration outside of a Kubernetes cluster, such as on a local machine. When disabled, the integration uses the cluster's built-in in-cluster authentication. Disabled by default.
-
Ingest All Node Images (optional): Enable to ingest every image cached on each node, instead of only the images in use by a running container. Required to ingest images at all if you are not ingesting pods. Disabled by default. See Image ingestion.
-
-
Click Create after all values are provided and your instance appears in the list of all your Kubernetes Managed instances.
Helm
The Helm-based install is for users that would like their integrations managed via Kubernetes resources.
- Ensure you have the repository set up and updated
helm repo add jupiterone https://jupiterone.github.io/helm-charts
helm repo update
- Find the name of your runner. The integration needs to know the name of the runner.
kubectl get integrationrunner -n jupiterone
Output
NAME STATE DETAIL REGISTRATION AGE
runner running registered 162m
- Configuration Options
Values:
collectorName- (Default "runner"). This is the name of the Runner/Collector you installed as part of the Kubernetes Operator installation.includeNamespaces- An array of namespace names to include. If specified, only these namespaces will be ingested.excludeNamespaces- An array of namespace names to exclude from ingestion.loadKubernetesConfigFromDefault- (Default false). Set totruewhen running the integration outside of a Kubernetes cluster (for example, on your local machine). Whenfalse, the integration uses the cluster's built-in in-cluster authentication.crdMappingConfig- Path to a YAML file containing the CRD mapping configuration (see Advanced: Configuring Custom Resource Definitions section below).ingestAllNodeImages- (Default false). Set totrueto ingest every image cached on each node, instead of only the images in use by a running container. Required to ingest images at all if you are not ingesting pods. See Image ingestion.pollingInterval- (Default ONE_WEEK). Specifies how often the integration runs to collect data. Options:- DISABLED
- THIRTY_MINUTES
- ONE_HOUR
- FOUR_HOURS
- EIGHT_HOURS
- TWELVE_HOURS
- ONE_DAY
- ONE_WEEK
pollingIntervalCron- (Default disabled). If setting this field, set pollingInterval to DISABLED. This option has two fields:houranddayOfWeek. Example:--set pollingInterval=DISABLED --set pollingIntervalCron.hour=2 --set pollingIntervalCron.dayOfWeek=0ingestionSources- (Default: integration defaults). Enables (true) or disables (false) individual resource types by ingestion source ID. Unlisted sources keep their default; Container Specs (container-specs) is the only source disabled by default. Runhelm show values jupiterone/kubernetes-managedfor the full list of IDs. Set it in a values file:Pass the file on every install and upgrade (ingestionSources:secrets: falsecontainer-specs: true-f values.yaml). Ahelm upgradethat passes other values (-for--set) but not this one resets it, which returns every source to its default, unless the upgrade uses--reuse-values.--set ingestionSources.secrets=falsealso works, but every later upgrade that passes values must repeat it.- Dependencies: some sources feed others. Disabling
podsalso stops containers and volumes, and the images used by containers. Disablingcontainersstops those images too. Disablingnodesstops all image ingestion. WithingestAllNodeImagesset totrue, images cached on nodes are still ingested whilepodsorcontainersis disabled. - Ownership: when set, this value owns the instance's ingestion source settings. Changes made in the JupiterOne UI are replaced the next time you change it. Account-level defaults configured for the integration are applied only when the instance is created, and the first change to this value replaces them, so list every non-default setting you want to keep. Removing the value returns every source to the integration's default.
- Validation: the operator applies only valid entries. An ID that is not one of the integration's ingestion sources, or a disable of a source that cannot be disabled, is not applied and is reported in the
IngestionSourcesAppliedcondition, as is an entry JupiterOne did not store. - Versions: requires Integration Operator v0.5.0 or later (operator chart 1.5.0 or later), and kubernetes-managed chart 1.0.9 or later (
helm show values jupiterone/kubernetes-managedlistsingestionSources). Older operators and older kubernetes-managed charts silently ignore it. After upgrading, runhelm repo update, thenhelm upgradethis chart again: an older CRD droppedingestionSourceswhen the resource was stored, so the value takes effect only once the chart is applied again.
- Dependencies: some sources feed others. Disabling
For a complete list of configuration options, run:
helm show values jupiterone/kubernetes-managed
- Install the Managed Kubernetes Helm chart Add in your configuration options from above into this command:
helm install kubernetes jupiterone/kubernetes-managed -n jupiterone --set collectorName=<runnerName>
- Verify Installation Check that the integration was successfully installed and registered with JupiterOne:
kubectl get integrationinstance -n jupiterone
Output
NAME READY REASON AGE
kubernetes True Success 176m
Data Volume Configuration
By default, the integration ingests all namespaces in your cluster. Use the options below to limit which namespaces are included.
Data Filtering Options
| Field | Description | Default |
|---|---|---|
| Include Specific Namespaces | Restrict ingestion to the listed namespaces only. Separate names with commas. If left empty, all namespaces are ingested (unless exclusions are specified). | All namespaces |
| Exclude Specific Namespaces | Skip the listed namespaces during ingestion. Useful for omitting system namespaces such as kube-system. Separate names with commas. | None |
Image ingestion
By default, kube_image entities are created only for images in use by a running container, and each container is linked to its image with a kube_container USES kube_image relationship. Images are derived from pods, so a cluster that does not ingest pods produces no images.
Enable Ingest All Node Images (ingestAllNodeImages) to also ingest the images cached on each node, whether or not a container is running them, and to relate each node to the images it holds with kube_node HAS kube_image. This is the option to use if you are not ingesting pods and still want image inventory.
| Field | Description | Default |
|---|---|---|
| Ingest All Node Images | Ingest every image in each node's local image cache in addition to the images in use by a running container. | Disabled |
A node reports its cached images through Node.status.images, which kubelet truncates at --node-status-max-images (default 50, -1 disables the limit) and which only covers images present in that node's local cache. Enabling this option therefore gives a best-effort inventory per node rather than a guaranteed complete one. Set --node-status-max-images=-1 on your kubelets if you need the full list.
RBAC
The Kubernetes collector installs with a ClusterRole that provides read-only access to Kubernetes resources. The collector has permissions to get, list, and watch the following:
Core Resources:
- Pods, namespaces, service accounts, config maps, nodes, services, secrets, and events
Application Workloads:
- Deployments, replica sets, stateful sets, daemon sets, jobs, and cron jobs
Networking:
- Ingresses and network policies
RBAC and Security:
- Cluster roles, cluster role bindings, roles, and role bindings
- Self-subject access reviews and subject access reviews
- Token reviews
Extensions:
- All resources in the extensions API group
Integration Management:
- Integration instance jobs, integration runners, and their status and finalizers (for managing integration workloads)
All permissions are read-only (get, list, watch) and do not allow modification of any cluster resources.
Advanced: Configuring Custom Resource Definitions (CRDs)
By default, the Kubernetes Managed integration ingests standard Kubernetes resources. However, you can extend the integration to also collect and map Custom Resource Definitions (CRDs) that exist in your cluster. This is particularly useful for capturing custom resources created by operators, such as IntegrationRunners and IntegrationInstanceJobs from the JupiterOne Kubernetes Operator.
Overview
The CRD configuration allows you to:
- Define which custom resources to ingest: Specify the CRD resources you want to collect from your cluster
- Map resource properties: Transform CRD fields into JupiterOne entity properties
- Create relationships: Define how custom resources relate to other entities in your JupiterOne graph
Configuration File Structure
The CRD configuration is defined in a YAML file with two main sections: resources and relationships. This configuration file can be provided when setting up your integration instance.
Resources Section
The resources section defines which custom resources to ingest and how to map their properties to JupiterOne entities.
Each resource entry contains:
-
name(required): The fully qualified name of the CRD resource type, following the format<plural>.<group>. For example,integrationrunners.integrations.jupiterone.iorefers to theIntegrationRunnerCRD in theintegrations.jupiterone.ioAPI group. -
version(optional): The API version of the resource. For example,v1indicates the resource uses version 1 of the API. If not provided, all versions will be ingested. -
_type(required): The entity type that will be assigned to ingested resources in JupiterOne. This is a custom identifier that you'll use to query and reference these entities. It should follow the patternkube_cr_<resource_name>(e.g.,kube_cr_integration_runner). -
_class(required): The entity class that categorizes the resource in JupiterOne's data model. All supported entity classes can be found in the JupiterOne Data Model documentation. -
propertyToFieldMap(required): A mapping that defines how fields from the Kubernetes resource are transformed into JupiterOne entity properties. This is where you specify which Kubernetes resource fields map to which JupiterOne properties._key(required): Maps to the unique identifier for the entity in JupiterOne. It's recommended to usemetadata.uidto ensure uniqueness.- Standard properties: Common mappings include:
name: Usually maps tometadata.namenamespace: Usually maps tometadata.namespacecreatedOn: Usually maps tometadata.creationTimestamp
- Custom properties: You can map any field from the resource's
specorstatussections to custom properties. For example,accountId: spec.accountIdmaps theaccountIdfield from the resource's spec to a property calledaccountIdon the JupiterOne entity.
Relationships Section
The relationships section defines how custom resources relate to other entities in your JupiterOne graph. This allows you to create meaningful connections between resources, such as showing which secrets an IntegrationRunner uses or which runner an IntegrationInstanceJob runs on.
Each relationship entry contains:
-
_class(required): The type of relationship. All supported relationship classes can be found in the JupiterOne Data Model documentation. -
sourceType(required): The entity type of the source entity in the relationship. This should match the_typeyou defined in the resources section (e.g.,kube_cr_integration_runner). -
targetType(required): The entity type of the target entity in the relationship. This can be:- Another custom resource type you've defined (e.g.,
kube_cr_integration_instance_job) - A standard Kubernetes resource type (e.g.,
kube_secret,kube_pod,kube_namespace)
- Another custom resource type you've defined (e.g.,
-
matchBy(required): Defines how to match the source and target entities to create the relationship. This is a key-value mapping where:- The key is a property name on the source entity (e.g.,
secretName) - The value is a property name on the target entity (e.g.,
name)
The relationship is created when the source entity's property value matches the target entity's property value. You can specify multiple match conditions, and all must be satisfied (AND logic). For example:
matchBy:secretName: namenamespace: namespaceThis creates a relationship when both the
secretNameon the source matches thenameon the target, AND thenamespaceon the source matches thenamespaceon the target.noteIf a property is not defined for either the source or the target, the relationship won't be created. Undefined doesn't match with undefined.
- The key is a property name on the source entity (e.g.,
Example Configuration
Here's a complete example configuration that ingests IntegrationRunners and IntegrationInstanceJobs and creates relationships between them and their associated secrets:
resources:
- name: integrationrunners.integrations.jupiterone.io
version: v1
_type: kube_cr_integration_runner
_class: Process
propertyToFieldMap:
_key: metadata.uid
name: metadata.name
namespace: metadata.namespace
createdOn: metadata.creationTimestamp
accountId: spec.accountId
collectorId: spec.collectorId
collectorPoolId: spec.collectorPoolId
jupiterOneEnvironment: spec.jupiterOneEnvironment
secretAPITokenName: spec.secretAPITokenName
secretName: spec.secretName
syncIntervalSeconds: spec.syncIntervalSeconds
- name: integrationinstancejobs.integrations.jupiterone.io
_type: kube_cr_integration_instance_job
_class: Task
propertyToFieldMap:
_key: metadata.uid
name: metadata.name
namespace: metadata.namespace
createdOn: metadata.creationTimestamp
accountId: spec.accountId
certificateIdentity: spec.certificateIdentity
image: spec.image
integrationDefinitionName: spec.integrationDefinitionName
integrationInstanceId: spec.integrationInstanceId
integrationInstanceJobId: spec.integrationInstanceJobId
integrationRunnerName: spec.integrationRunnerName
secretName: spec.secretName
relationships:
- _class: HAS
sourceType: kube_cr_integration_runner
targetType: kube_secret
matchBy:
secretName: name
namespace: namespace
- _class: HAS
sourceType: kube_cr_integration_instance_job
targetType: kube_secret
matchBy:
secretName: name
namespace: namespace
- _class: HAS
sourceType: kube_cr_integration_instance_job
targetType: kube_cr_integration_runner
matchBy:
integrationRunnerName: name
namespace: namespace
Understanding the Example
Resources Explained:
-
IntegrationRunner Resource:
- Ingested as
kube_cr_integration_runnerentities with classProcess - Maps standard Kubernetes metadata (uid, name, namespace, creationTimestamp)
- Maps custom spec fields like
accountId,collectorId, andsyncIntervalSecondsto entity properties - The
secretNameproperty is used later to create relationships with secrets
- Ingested as
-
IntegrationInstanceJob Resource:
- Ingested as
kube_cr_integration_instance_jobentities with classTask - Similar metadata mapping
- Maps job-specific fields like
integrationInstanceId,image, andintegrationRunnerName - The
integrationRunnerNameproperty links jobs to their runners
- Ingested as
Relationships Explained:
-
IntegrationRunner → Secret:
- Creates a
HASrelationship from each IntegrationRunner to the secret it uses - Matches when the runner's
secretNameequals the secret'snameAND they're in the samenamespace
- Creates a
-
IntegrationInstanceJob → Secret:
- Creates a
HASrelationship from each IntegrationInstanceJob to its associated secret - Uses the same matching logic as above
- Creates a
-
IntegrationInstanceJob → IntegrationRunner:
- Creates a
HASrelationship showing which runner executes each job - Matches when the job's
integrationRunnerNameequals the runner'snameAND they're in the samenamespace
- Creates a
Next steps
Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.
Migrating from Kubernetes Native
The Kubernetes Native integration is deprecated. It is deployed as a CronJob from the graph-kubernetes Helm chart, and its job lifecycle is controlled by that chart rather than by JupiterOne, so JupiterOne has no visibility into its job logs or failures. No further development is planned for it.
This section covers moving an existing Native instance to this integration.
Migration overview
The migration is additive: you stand up the new integration alongside the old one, confirm the new data, and only then remove the old one.
- Install the Kubernetes collector in the cluster.
- Create a Kubernetes Managed instance and assign it to that collector.
- Verify that the Managed instance completes a job and ingests the expected data.
- Decommission the Native integration.
Each cluster has its own collector and its own integration instance, as with Native. That does not mean migrating one cluster at a time by hand — both Helm charts are designed to be templated across clusters, so a GitOps tool can roll the whole fleet out from a single source. See Migrating many clusters at once.
Between steps 2 and 4, both integrations are ingesting the same cluster, and their entities are not merged. See Will I see duplicate entities during the migration?. Keep this window short.
Before you begin
Meet the collector prerequisites — Kubernetes and Helm versions, and an account API token with Collector and Graph Data access. Integration create/update permission is needed only if you create the Managed instance with the Helm chart rather than the UI.
One requirement is specific to migrating: the collector runner pods are a different set of pods from the Native CronJob, so confirm that any NetworkPolicy, egress proxy, or firewall rule that allowed the CronJob to reach your JupiterOne API endpoint also applies to them.
Record your current Native configuration
Three Native settings have no equivalent that carries over automatically, so capture them before you start:
- Namespace scope. Native limits ingestion through RBAC — a namespace-scoped
Roleingests one namespace, aClusterRoleingests the whole cluster. Managed instead uses theincludeNamespacesandexcludeNamespacesconfiguration options, so translate your scope deliberately. - Schedule. Native runs on the CronJob schedule defined in your chart values. Managed uses
pollingInterval, which defaults toONE_WEEK— set it explicitly, or the integration can appear to have stopped running. The interval must be one your account includes; otherwise creating the instance fails withInvalid or unauthorized polling interval. - Resource types you skip. If you removed permissions from the Native ClusterRole to stop collecting a resource type, do not carry that over. Managed treats a permission error the same as an empty result, so a missing permission and a temporary API failure both look like "no resources" and can remove those entities from your graph. Use ingestion sources instead.
Both are documented under Configuration Options on the Installation tab.
Note the Native instance ID and name as well, so you can find it again when it is time to delete it.
Inventory what depends on your Kubernetes data
The Managed integration does not produce an identical graph. Review the changes to the data model below, then check your account for content that will be affected:
- Saved questions, queries, and alert rules that filter on
_integrationInstanceIdor_source, or that reference the Native instance by name. - Dashboards, compliance mappings, and tags built on Kubernetes entities.
- Anything that selects Kubernetes secrets by the
Vaultclass, or that relies on thekube_custom_resourceorkube_custom_resource_definitionentity types. - Anything that references
kube_container_specorkube_volumeentities by_key. Both are keyed differently in Managed.
Update these after cutover.
Step 1: Install the Kubernetes collector
Follow the Kubernetes collector installation guide to install the JupiterOne Integration Operator and Integration Runner, then confirm the runner registered using Verification. Note the runner's name — you will need it in step 2. If you are migrating a fleet, see Migrating many clusters at once before doing this by hand.
Two things to watch for when the cluster already ran the Native integration:
- Do not reuse the Native ServiceAccount or RBAC objects. The Managed collector requires a different permission set, including read access to the operator's own CRDs and to resources such as
ingressesthat Native did not collect. It installs its own, all read-only. - Remove any previous operator installation first. If the operator or runner was installed in this cluster before and left in place, remove it before reinstalling. A stale installation can cause every backlogged job to be scheduled at once when it resumes, creating thousands of job pods and exhausting cluster resources. Make sure
jobResourcesis set in your values so job pods have explicit resource requests and limits.
Step 2: Create the Kubernetes Managed instance
Create one instance per cluster and assign it to the collector from step 1, using either the JupiterOne UI or the Helm chart. The commands, values, and verification step are on the Installation tab — set collectorName to the runner from step 1, and apply the namespace scope and polling interval you recorded earlier.
Unlike Native, the Managed integration authenticates through the collector. There is no per-instance integration API key to create, store in a Kubernetes Secret, or rotate.
The operator sends instance settings only when it first creates the instance. The exception is ingestionSources: changes to it are applied to the existing instance. When it is set, it owns the instance's ingestion source settings: changes made in the UI, and account-level defaults applied at creation, are replaced the next time you change the value. Removing it returns every source to the integration's default. Changing pollingInterval or other values on an existing IntegrationInstance resource has no effect. Change them in the JupiterOne UI or API instead. Deleting and re-applying the resource creates a new instance, and its entities are ingested again as new entities.
Step 3: Verify the Managed instance
Wait for the first job to complete, then confirm the data before removing anything.
-
In JupiterOne, open Integrations > Kubernetes Managed > your instance and confirm the most recent job status is successful. If a job fails, JupiterOne can access the job logs to help troubleshoot.
-
Compare entity counts between the two instances in a single query, substituting both instance IDs:
FIND * WITH _integrationInstanceId = ("<native-instance-id>" OR "<managed-instance-id>") AS eRETURN e._integrationInstanceId, e._type, count(e) ORDER BY e._type -
Confirm the namespaces you expect are present, and that excluded namespaces are absent:
FIND kube_namespace WITH _integrationInstanceId = "<managed-instance-id>" AS nRETURN n.name
Expect differences in the type-by-type comparison — see changes to the data model. What matters is that the resources you rely on are present with the counts you expect.
Step 4: Decommission the Native integration
Do this only after the Managed instance is verified.
In the cluster, remove the Native deployment. If you installed it with Helm, helm uninstall the release; if you deployed it with raw YAML manifests, remove each object as described under Uninstall in the Native installation guide. Then delete the Kubernetes Secret holding the JupiterOne API key, and revoke that integration API key in JupiterOne. The uninstall steps do not do either.
In JupiterOne, delete the Native integration instance. This deletes all data tied to that instance, which is what removes the duplicate entities.
Finally, update the saved questions, alert rules, dashboards, and mappings you inventoried earlier.
Choosing what to ingest
Native had no way to turn off a resource type other than removing RBAC permissions. Managed has ingestion sources: one per Kubernetes resource type, toggled on the instance in the JupiterOne UI or API, or with the chart's ingestionSources value (Integration Operator v0.5.0 or later, operator chart 1.5.0 or later, kubernetes-managed chart 1.0.9 or later). After upgrading the operator, run helm repo update and helm upgrade the integration chart again for the value to take effect; kubernetes-managed charts older than 1.0.9 do not have the value. See Configuration Options on the Installation tab.
- Container Specs is disabled by default. Every other source is enabled.
- Clusters and Namespaces cannot be disabled.
- Some sources feed others. Disabling Pods also stops containers, volumes, the images derived from running containers, and the relationships between pods and other resources. Disabling Nodes also stops all image ingestion. Disabling a source such as Secrets or ConfigMaps removes the relationships that point at it.
Ingestion sources require a recent Integration Operator and runner image. Older versions ignore these settings.
Changes to the data model
The Managed integration collects more overall, but it is not a superset of Native. Review these differences before cutover.
Entity classes that changed
One entity class differs: kube_secret is classed Vault, NHI in Native and Secret, NHI in Managed. A query, rule, or compliance mapping that selects Kubernetes secrets by the Vault class will stop matching them — select by Secret instead.
Entity types only in Native
Entity _type | Notes |
|---|---|
kube_custom_resource | Replaced by configurable CRD ingestion. |
kube_custom_resource_definition | Replaced by configurable CRD ingestion. |
Managed ingests custom resources through the crdMappingConfig option instead, which lets you choose which CRDs to collect and define their own _type, _class, property mappings, and relationships. See Advanced: Configuring Custom Resource Definitions on the Installation tab.
Entity types only in Managed
Managed adds kube_ingress (class Gateway), and a mapped kube_cluster IS aws_eks_cluster relationship alongside the existing Azure and Google Cloud cluster mappings.
Where images come from
Native derives kube_image from each node's cached image list (Node.status.images). Managed derives it from running containers by default, so after cutover kube_image reflects what is in use rather than what is pulled: images cached on a node but not running are no longer present, and images that Native missed because kubelet truncated a node's list now appear.
If you relied on Native's behavior, or you are not ingesting pods, enable Ingest All Node Images (ingestAllNodeImages) on the Managed instance. That restores the node-cached inventory alongside the in-use images, and adds kube_node HAS kube_image. See Image ingestion on the Installation tab.
Container specs
Managed produces kube_container_spec only when the Container Specs ingestion source is enabled, and it is disabled by default. Specs are built from workload pod templates — Deployments, DaemonSets, StatefulSets, Jobs, CronJobs and ReplicaSets — so they do not require pods to be ingested. The <workload> USES kube_container_spec relationships and the spec property names match Native.
Differences from Native:
_keyiscontainer-spec:<namespace>/<containerName>, using the namespace name. Native used the namespace UID, so queries that select specs by_keyneed updating.- Specs are deduplicated per namespace and container name. When two workloads in one namespace declare a container with the same name, one spec is kept and the other workload's image, resource and security settings are not recorded.
- Pods not owned by a workload produce no spec, and there is no
kube_podUSESkube_container_specrelationship.
Volumes
Native created kube_volume only for Deployments, one per Deployment and volume name. Managed creates volumes for every pod, keyed by the workload that owns the pod: <namespace>/<ownerKind>/<ownerName>/<volumeName>, for example default/Deployment/web/config. Replicas of a workload share one volume entity, and pods of a Deployment are attributed to the Deployment rather than to its ReplicaSet.
Some volumes are not shared across replicas:
- Volumes backed by a PersistentVolumeClaim are keyed by claim,
<namespace>/pvc/<claimName>, so each StatefulSet replica keeps its own volume. - The service-account token volume Kubernetes adds to each pod has a generated name (
kube-api-access-…), so it remains one entity per pod. - Pods created by a Job are keyed on that Job; runs of a CronJob are not grouped under the CronJob.
- A pod with no owner is keyed on itself. A pod missing the
pod-template-hashlabel is attributed to its ReplicaSet instead of its Deployment.
Because Native covered Deployments only, expect more volumes than Native, but far fewer than one per pod.
With Container Specs enabled, volumes are also created from workload pod templates using the same keys, so they appear without ingesting pods, and kube_container_spec USES kube_volume is added, as in Native.
Relationships
Relationship coverage differs as well. Notably, kube_node RUNS kube_pod in Native is kube_node CONTAINS kube_pod in Managed, and Managed adds kube_ingress CONNECTS kube_service and kube_service CONNECTS kube_pod. Rules of both Roles and ClusterRoles produce kube_role_rule, with kube_role and kube_cluster_role ENFORCES kube_role_rule, as in Native. Compare the full lists in the Data Model tab of this page and of the Kubernetes Native integration.
Migrating many clusters at once
You do not have to migrate cluster by cluster. Both the collector and the integration instance are installed from Helm charts, so they can be templated and delivered by a GitOps tool such as Argo CD or Flux, and a fleet-wide migration becomes a single change to your source of truth.
With Argo CD, the usual shape is an ApplicationSet that generates one Application per destination cluster, each deploying the same three charts — jupiterone-integration-operator, the Integration Runner, and kubernetes-managed — with sync waves ordering the operator and runner ahead of the instance. The per-cluster values are typically just the cluster name and the collector name.
Two things make this work across a fleet:
- One shared token. Every runner authenticates with the same account API token, so you can reference one existing Kubernetes Secret, or pull it into each cluster with the External Secrets Operator, instead of minting a credential per cluster.
pollingIntervaland namespace filters are chart values. They are set the same way in every cluster, so schedule and scope stay consistent without per-instance UI edits.
CRD mapping is also a chart value, so crdMappingConfig changes ship with the same commit rather than being re-entered per instance. Editing CRD mapping through the UI, by contrast, is per instance.
Argo CD applies with server-side apply. Omit the config: block entirely when you have no configuration sub-values to set — an empty config: {} is serialized as null and rejected by the CRD when it merges over an existing instance.
Frequently asked questions
Will I see duplicate entities during the migration?
Yes. Every entity in JupiterOne belongs to the integration instance that ingested it. While both instances are active, each Kubernetes resource is ingested twice — once by each instance — and the two copies are independent entities. They are not merged or deduplicated, so entity counts and query results that span both instances will be roughly doubled for the overlap period.
Plan for this if you have alert rules that trigger on entity counts, and keep the overlap to the time needed to verify the new data.
Do I have to clean up the duplicate data manually?
No. Deleting the Native integration instance deletes all data in JupiterOne tied to it, the same as for any other integration, and that removes the duplicates. The entities stop appearing in queries, dashboards, and alert rule evaluations. There is no separate deduplication or cleanup step. See Instance management.
Will my Kubernetes entities keep their history?
No. Managed entities are ingested by a new integration instance, so they are new entities in the graph. Properties such as _createdOn reflect when the Managed integration first ingested them, not the age of the underlying Kubernetes resource. Anything that trends on entity age resets at cutover.
Can one instance cover more than one cluster?
No. Each cluster has its own collector and its own Kubernetes Managed instance, the same as with Native. Unlike Native, though, a single account API token serves the runners in every cluster, so there is no per-cluster integration API key to create or rotate — which is what makes a templated, fleet-wide rollout practical. See Migrating many clusters at once.
Permissions
IAM permissions that must be granted to the integration principal for data ingestion.
Show Permissions (20)
list certificatesigningrequestslist clusterrolebindingslist clusterroleslist configmapslist cronjobslist daemonsetslist deploymentslist ingresseslist jobslist namespaceslist networkpolicieslist nodeslist podslist replicasetslist rolebindingslist roleslist secretslist serviceaccountslist serviceslist statefulsets
Endpoints
API endpoints that the integration makes requests to.
Show Endpoints (26)
/api/v1/namespaces/api/v1/namespaces/{namespace}/configmaps/api/v1/namespaces/{namespace}/pods/api/v1/namespaces/{namespace}/secrets/api/v1/namespaces/{namespace}/serviceaccounts/api/v1/namespaces/{namespace}/services/api/v1/nodes/apis/apiextensions.k8s.io/v1/customresourcedefinitions/apis/apps/v1/namespaces/{namespace}/daemonsets/apis/apps/v1/namespaces/{namespace}/deployments/apis/apps/v1/namespaces/{namespace}/replicasets/apis/apps/v1/namespaces/{namespace}/statefulsets/apis/batch/v1/namespaces/{namespace}/cronjobs/apis/batch/v1/namespaces/{namespace}/jobs/apis/certificates.k8s.io/v1/certificatesigningrequests/apis/networking.k8s.io/v1/namespaces/{namespace}/ingresses/apis/networking.k8s.io/v1/namespaces/{namespace}/networkpolicies/apis/rbac.authorization.k8s.io/v1/clusterrolebindings/apis/rbac.authorization.k8s.io/v1/clusterroles/apis/rbac.authorization.k8s.io/v1/namespaces/{namespace}/rolebindings/apis/rbac.authorization.k8s.io/v1/namespaces/{namespace}/roles/apis/{group}/{version}/namespaces/{namespace}/{plural}/apis/{group}/{version}/{plural}http://169.254.169.254/latest/meta-data/placement/regionhttp://169.254.169.254/latest/meta-data/services/ekshttp://metadata.google.internal/computeMetadata/v1/instance/attributes/cluster-uid
Documentation Links
Links to provider documentation relevant to setup and configuration.
Show Documentation Links (27)
- https://cloud.google.com/compute/docs/metadata/default-metadata-values
- https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html
- https://kubernetes.io/docs/concepts/configuration/organize-cluster-access-kubeconfig/
- https://kubernetes.io/docs/concepts/workloads/pods/#pod-templates
- https://kubernetes.io/docs/reference/access-authn-authz/rbac/
- https://kubernetes.io/docs/reference/kubernetes-api/authentication-resources/certificate-signing-request-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/authentication-resources/service-account-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/authorization-resources/cluster-role-binding-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/authorization-resources/cluster-role-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/authorization-resources/role-binding-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/authorization-resources/role-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/cluster-resources/node-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/config-and-storage-resources/config-map-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/config-and-storage-resources/secret-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/core/namespace-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/core/node-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/extend-resources/custom-resource-definition-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/policy-resources/network-policy-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/service-resources/ingress-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/service-resources/service-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/cron-job-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/daemon-set-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/deployment-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/job-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/replica-set-v1/
- https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/stateful-set-v1/
Per-Step Breakdown
Detailed authorization requirements for each ingestion step.
Show all steps (53)
| Step | Permissions | Endpoints |
|---|---|---|
| Build Certificate Signing Request Relationships | - | - |
| Build Cluster AKS Relationships | - | - |
| Build Cluster EKS Relationships | - | http://169.254.169.254/latest/meta-data/services/eks, http://169.254.169.254/latest/meta-data/placement/region |
| Build Cluster GKE Relationships | - | http://metadata.google.internal/computeMetadata/v1/instance/attributes/cluster-uid |
| Build Cluster Role Binding Assigned Service Account Relationships | - | - |
| Build Cluster Role Binding Relationships | - | - |
| Build Container ConfigMap Relationships | - | - |
| Build Container Secret Relationships | - | - |
| Build Container Uses Volume Relationships | - | - |
| Build CronJob MANAGES Job relationship | - | - |
| Build DaemonSet-Pod Relationships | - | - |
| Build Deployment-ReplicaSet Relationships | - | - |
| Build Ingress-Service Relationships | - | - |
| Build Job MANAGES Pod relationship | - | - |
| Build Node Contains Pod Relationships | - | - |
| Build Pod Service Account Relationships | - | - |
| Build Pod-Secret Relationships | - | - |
| Build ReplicaSet-Pod Relationships | - | - |
| Build Role Binding Assigned Service Account Relationships | - | - |
| Build Role Binding Cluster Role Relationships | - | - |
| Build Role Binding Role Relationships | - | - |
| Build Service Account-Secret Relationships | - | - |
| Build Service-Pod Relationships | - | - |
| Build StatefulSet MANAGES Pod relationship | - | - |
| Build Volume to ConfigMap Relationships | - | - |
| Fetch Certificate Signing Requests | list certificatesigningrequests | /apis/certificates.k8s.io/v1/certificatesigningrequests |
| Fetch Cluster Role Bindings | list clusterrolebindings | /apis/rbac.authorization.k8s.io/v1/clusterrolebindings |
| Fetch Cluster Role Rules | - | - |
| Fetch Cluster Roles | list clusterroles | /apis/rbac.authorization.k8s.io/v1/clusterroles |
| Fetch ConfigMaps | list configmaps | /api/v1/namespaces/{namespace}/configmaps |
| Fetch Containers | - | - |
| Fetch CronJobs | list cronjobs | /apis/batch/v1/namespaces/{namespace}/cronjobs |
| Fetch Custom Resource Entities | - | /apis/apiextensions.k8s.io/v1/customresourcedefinitions, /apis/{group}/{version}/namespaces/{namespace}/{plural}, /apis/{group}/{version}/{plural} |
| Fetch DaemonSets | list daemonsets | /apis/apps/v1/namespaces/{namespace}/daemonsets |
| Fetch Deployments | list deployments | /apis/apps/v1/namespaces/{namespace}/deployments |
| Fetch Images | - | - |
| Fetch Ingress | list ingresses | /apis/networking.k8s.io/v1/namespaces/{namespace}/ingresses |
| Fetch Jobs | list jobs | /apis/batch/v1/namespaces/{namespace}/jobs |
| Fetch Namespaces | list namespaces | /api/v1/namespaces |
| Fetch Network Policies | list networkpolicies | /apis/networking.k8s.io/v1/namespaces/{namespace}/networkpolicies |
| Fetch Node Images | - | - |
| Fetch Nodes | list nodes | /api/v1/nodes |
| Fetch Pods | list pods | /api/v1/namespaces/{namespace}/pods |
| Fetch ReplicaSets | list replicasets | /apis/apps/v1/namespaces/{namespace}/replicasets |
| Fetch Role Bindings | list rolebindings | /apis/rbac.authorization.k8s.io/v1/namespaces/{namespace}/rolebindings |
| Fetch Role Rules | - | - |
| Fetch Roles | list roles | /apis/rbac.authorization.k8s.io/v1/namespaces/{namespace}/roles |
| Fetch Secrets | list secrets | /api/v1/namespaces/{namespace}/secrets |
| Fetch Service Accounts | list serviceaccounts | /api/v1/namespaces/{namespace}/serviceaccounts |
| Fetch Services | list services | /api/v1/namespaces/{namespace}/services |
| Fetch StatefulSets | list statefulsets | /apis/apps/v1/namespaces/{namespace}/statefulsets |
| Fetch Users | - | - |
| Fetch Volumes | - | - |
Entities
The following entities are created:
| Resources | Entity _type | Entity _class |
|---|---|---|
| Kubernetes Certificate Signing Request | kube_certificate_signing_request | Certificate, NHI |
| Kubernetes Cluster | kube_cluster | Cluster |
| Kubernetes Cluster Role | kube_cluster_role | AccessRole |
| Kubernetes Cluster Role Binding | kube_cluster_role_binding | AccessPolicy |
| Kubernetes ConfigMap | kube_config_map | Configuration |
| Kubernetes Container | kube_container | Container |
| Kubernetes Container Spec | kube_container_spec | Configuration |
| Kubernetes CronJob | kube_cron_job | Task |
| Kubernetes DaemonSet | kube_daemon_set | Deployment |
| Kubernetes Deployment | kube_deployment | Deployment |
| Kubernetes Image | kube_image | Image |
| Kubernetes Ingress | kube_ingress | Gateway |
| Kubernetes Job | kube_job | Task |
| Kubernetes Namespace | kube_namespace | Group |
| Kubernetes Network Policy | kube_network_policy | Configuration |
| Kubernetes Node | kube_node | Host |
| Kubernetes Pod | kube_pod | Task |
| Kubernetes ReplicaSet | kube_replica_set | Deployment |
| Kubernetes Role | kube_role | AccessRole |
| Kubernetes Role Binding | kube_role_binding | AccessPolicy |
| Kubernetes Role Rule | kube_role_rule | Rule |
| Kubernetes Secret | kube_secret | Secret, NHI |
| Kubernetes Service | kube_service | Service |
| Kubernetes Service Account | kube_service_account | User, NHI |
| Kubernetes StatefulSet | kube_stateful_set | Deployment |
| Kubernetes User | kube_user | User |
| Kubernetes Volume | kube_volume | Disk |
Relationships
The following relationships are created:
Source Entity _type | Relationship _class | Target Entity _type |
|---|---|---|
kube_cluster | CONTAINS | kube_node |
kube_cluster | CONTAINS | kube_namespace |
kube_cluster | CONTAINS | kube_cluster_role |
kube_cluster | CONTAINS | kube_cluster_role_binding |
kube_cluster | CONTAINS | kube_user |
kube_cluster | CONTAINS | kube_certificate_signing_request |
kube_cluster | CONTAINS | ANY_RESOURCE |
kube_cluster_role | ENFORCES | kube_role_rule |
kube_cluster_role | ASSIGNED | kube_role_binding |
kube_cluster_role | ASSIGNED | kube_cluster_role_binding |
kube_cluster_role_binding | ASSIGNED | kube_service_account |
kube_container | USES | kube_secret |
kube_container | USES | kube_config_map |
kube_container | USES | kube_volume |
kube_container | USES | kube_image |
kube_container_spec | USES | kube_volume |
kube_cron_job | MANAGES | kube_job |
kube_cron_job | USES | kube_container_spec |
kube_daemon_set | MANAGES | kube_pod |
kube_daemon_set | USES | kube_container_spec |
kube_deployment | USES | kube_container_spec |
kube_deployment | MANAGES | kube_replica_set |
kube_ingress | CONNECTS | kube_service |
kube_job | USES | kube_container_spec |
kube_job | CONTAINS | kube_namespace |
kube_job | MANAGES | kube_pod |
kube_namespace | CONTAINS | kube_role |
kube_namespace | CONTAINS | kube_role_binding |
kube_namespace | CONTAINS | kube_cron_job |
kube_namespace | CONTAINS | kube_pod |
kube_namespace | CONTAINS | kube_daemon_set |
kube_namespace | CONTAINS | kube_config_map |
kube_namespace | CONTAINS | kube_secret |
kube_namespace | CONTAINS | kube_deployment |
kube_namespace | CONTAINS | kube_replica_set |
kube_namespace | CONTAINS | kube_network_policy |
kube_namespace | CONTAINS | kube_ingress |
kube_namespace | CONTAINS | kube_service |
kube_namespace | CONTAINS | ANY_RESOURCE |
kube_node | CONTAINS | kube_pod |
kube_node | HAS | kube_image |
kube_pod | USES | kube_service_account |
kube_pod | USES | kube_secret |
kube_pod | CONTAINS | kube_container |
kube_pod | USES | kube_volume |
kube_pod | HAS | kube_certificate_signing_request |
kube_replica_set | USES | kube_container_spec |
kube_replica_set | MANAGES | kube_pod |
kube_role | ENFORCES | kube_role_rule |
kube_role | ASSIGNED | kube_role_binding |
kube_role_binding | ASSIGNED | kube_service_account |
kube_service | CONNECTS | kube_pod |
kube_service_account | CONTAINS | kube_namespace |
kube_service_account | USES | kube_secret |
kube_stateful_set | USES | kube_container_spec |
kube_stateful_set | CONTAINS | kube_namespace |
kube_stateful_set | MANAGES | kube_pod |
kube_volume | USES | kube_config_map |
Mapped Relationships
The following mapped relationships are created:
Source Entity _type | Relationship _class | Target Entity _type | Direction |
|---|---|---|---|
kube_cluster | IS | azure_kubernetes_cluster | FORWARD |
kube_cluster | IS | google_container_cluster | FORWARD |
kube_cluster | IS | aws_eks_cluster | FORWARD |
Kube Certificate Signing Request
kube_certificate_signing_request inherits from Certificate, NHI
| Property | Type | Description | Specifications |
|---|---|---|---|
groups | array of strings | ||
signerName | string | ||
status.lastUpdatedOn | number | ||
status.message | string | ||
status.reason | string | ||
status.type | string | ||
subject.commonName | string | ||
subject.dnsSAN | array of strings | ||
subject.organization | string | ||
uid * | string | ||
usages | array of strings | ||
userId | string | ||
username | string |
Kube Cluster
kube_cluster inherits from Cluster
| Property | Type | Description | Specifications |
|---|---|---|---|
server * | string | ||
skipTlsVerify * | boolean |
Kube Cluster Role
kube_cluster_role inherits from AccessRole
| Property | Type | Description | Specifications |
|---|---|---|---|
apiVersion | string | ||
deletionGracePeriodSeconds | number | ||
deletionOn | number | ||
kind | string | ||
namespace | string | ||
resourceVersion | string |
Kube Cluster Role Binding
kube_cluster_role_binding inherits from AccessPolicy
| Property | Type | Description | Specifications |
|---|---|---|---|
apiVersion | string | ||
deletionGracePeriodSeconds | number | ||
deletionOn | number | ||
kind | string | ||
namespace | string | ||
resourceVersion | string |
Kube Config Map
kube_config_map inherits from Configuration
| Property | Type | Description | Specifications |
|---|---|---|---|
apiVersion | string | ||
binaryDataKeys | array of strings | ||
dataKeys | array of strings | ||
deletionGracePeriodSeconds | number | ||
deletionOn | number | ||
immutable | boolean | ||
kind | string | ||
namespace | string | ||
resourceVersion | string |
Kube Container
kube_container inherits from Container
| Property | Type | Description | Specifications |
|---|---|---|---|
allowPrivilegeEscalation | boolean | ||
appArmorProfile.localhostProfile | string | ||
appArmorProfile.type | string | ||
args | array of strings | ||
command | array of strings | ||
containerId | string | ||
cpuLimit | string | ||
cpuRequest | string | ||
finishedAt | number | ||
hasStarted | boolean | ||
image | string | ||
imagePullPolicy | string | ||
isReady | boolean | ||
isUsingEnvironmentVariableSecrets | boolean | ||
memoryLimit | string | ||
memoryRequest | string | ||
namespace | string | ||
normalizedCpuLimit | number | ||
normalizedCpuRequest | number | ||
normalizedMemoryLimit | number | ||
normalizedMemoryRequest | number | ||
podUid | string | ||
privileged | boolean | ||
procMount | string | ||
readOnlyRoolFilesystem | boolean | ||
restartCount | number | ||
runAsGroup | number | ||
runAsNonRoot | boolean | ||
runAsUser | number | ||
running | boolean | ||
seccompProfile.localhostProfile | string | ||
seccompProfile.type | string | ||
seLinuxOptions.level | string | ||
seLinuxOptions.role | string | ||
seLinuxOptions.type | string | ||
seLinuxOptions.user | string | ||
startedAt | number | ||
terminated | boolean | ||
terminatedExitCode | number | ||
terminationMessagePath | string | ||
terminationMessagePolicy | string | ||
type | string | ||
waiting | boolean | ||
waitingMessage | string | ||
waitingReason | string | ||
windowsOptions.gmsaCredentialSpec | string | ||
windowsOptions.gmsaCredentialSpecName | string | ||
windowsOptions.hostProcess | boolean | ||
windowsOptions.runAsUserName | string |
Kube Container Spec
kube_container_spec inherits from Configuration
| Property | Type | Description | Specifications |
|---|---|---|---|
containerPorts | array of numbers | ||
hasSecurityContext | boolean | ||
hostPorts | array of numbers | ||
image | string | ||
imagePullPolicy | string | ||
namespace | string | ||
portProtocols | array of strings | ||
securityContext.allowPrivilegeEscalation | boolean | ||
securityContext.capabilities.add | array of strings | ||
securityContext.capabilities.drop | array of strings | ||
securityContext.privileged | boolean | ||
securityContext.procMount | string | ||
securityContext.readOnlyRootFilesystem | boolean | ||
securityContext.runAsGroup | number | ||
securityContext.runAsNonRoot | boolean | ||
securityContext.runAsUser | number | ||
securityContext.seccompProfile.localhostProfile | string | ||
securityContext.seccompProfile.type | string | ||
securityContext.seLinuxOptions.level | string | ||
securityContext.seLinuxOptions.role | string | ||
securityContext.seLinuxOptions.type | string | ||
securityContext.seLinuxOptions.user | string | ||
securityContext.windowsOptions.gmsaCredentialSpec | string | ||
securityContext.windowsOptions.gmsaCredentialSpecName | string | ||
securityContext.windowsOptions.hostProcess | boolean | ||
securityContext.windowsOptions.runAsUserName | string |
Kube Cron Job
kube_cron_job inherits from Task
| Property | Type | Description | Specifications |
|---|---|---|---|
apiVersion | string | ||
concurrencyPolicy | string | ||
deletionGracePeriodSeconds | number | ||
deletionOn | number | ||
failedJobsHistoryLimit | number | ||
kind | string | ||
lastScheduledOn | number | ||
lastSuccessfulOn | number | ||
namespace | string | ||
resourceVersion | string | ||
schedule | string | ||
startingDeadlineSeconds | number | ||
successfulJobsHistoryLimit | number | ||
suspend | boolean | ||
timeZone | string |
Kube Daemon Set
kube_daemon_set inherits from Deployment
| Property | Type | Description | Specifications |
|---|---|---|---|
apiVersion | string | ||
collisionCount | number | ||
currentNumberScheduled | number | ||
deletionGracePeriodSeconds | number | ||
deletionOn | number | ||
desiredNumberScheduled | number | ||
kind | string | ||
minReadySeconds | number | ||
namespace | string | ||
numberAvailable | number | ||
numberMisscheduled | number | ||
numberReady | number | ||
numberUnavailable | number | ||
observedGeneration | number | ||
resourceVersion | string | ||
revisionHistoryLimit | number | ||
updatedNumberScheduled | number | ||
updateStrategyType | string |
Kube Deployment
kube_deployment inherits from Deployment
| Property | Type | Description | Specifications |
|---|---|---|---|
apiVersion | string | ||
availableReplicas | number | ||
collisionCount | number | ||
deletionGracePeriodSeconds | number | ||
deletionOn | number | ||
kind | string | ||
minReadySeconds | number | ||
namespace | string | ||
observedGeneration | number | ||
paused | boolean | ||
progressDeadlineSeconds | number | ||
readyReplicas | number | ||
replicas | number | ||
resourceVersion | string | ||
revisionHistoryLimit | number | ||
statusReplicas | number | ||
strategyType | string | ||
unavailableReplicas | number | ||
updatedReplicas | number |
Kube Image
kube_image inherits from Image
| Property | Type | Description | Specifications |
|---|---|---|---|
digest | string | ||
imageId | string | ||
names | array of strings | ||
sizeInBytes | number |
Kube Ingress
kube_ingress inherits from Gateway
| Property | Type | Description | Specifications |
|---|---|---|---|
category * | array of strings | ||
deletionOn | number | ||
finalizers | array of strings | ||
function * | array of strings | ||
generation | number | ||
hasDefaultBackend | boolean | ||
hosts | array of strings | ||
ingressClassName | string | ||
namespace | string | ||
paths | array of strings | ||
public * | boolean | ||
resourceVersion | string | ||
status.loadBalancer.ingress | array of strings | ||
tlsEnabled | boolean | ||
tlsHosts | array of strings | ||
tlsSecretNames | array of strings |
Kube Job
kube_job inherits from Task
| Property | Type | Description | Specifications |
|---|---|---|---|
activeDeadlineSeconds | number | ||
backoffLimit | number | ||
completions | number | ||
createdOn | number | ||
deletedOn | number | ||
deletionGracePeriodSeconds | number | ||
generation | number | ||
manualSelector | boolean | ||
namespace | string | ||
parallelism | number | ||
resourceVersion | string | ||
status.active | number | ||
status.completionTime | number | ||
status.failed | number | ||
status.startTime | number | ||
status.succeeded | number | ||
ttlSecondsAfterFinished | number |
Kube Namespace
kube_namespace inherits from Group
| Property | Type | Description | Specifications |
|---|---|---|---|
createdOn | number | ||
deletionGracePeriodSeconds | number | ||
finalizers | array of strings | ||
generation | number | ||
ownerNames | array of strings | ||
resourceVersion | string | ||
status.phase | string |
Kube Network Policy
kube_network_policy inherits from Configuration
| Property | Type | Description | Specifications |
|---|---|---|---|
apiVersion | string | ||
deletionGracePeriodSeconds | number | ||
deletionOn | number | ||
kind | string | ||
namespace | string | ||
podSelectorMatchExpressions | string | ||
policyTypes | array of strings | ||
resourceVersion | string |
Kube Node
kube_node inherits from Host
| Property | Type | Description | Specifications |
|---|---|---|---|
architecture | string | ||
capacity.cpu | string | ||
capacity.memory | string | ||
capacity.pods | string | ||
containerRuntimeVersion | string | ||
kernelVersion | string | ||
kubeletVersion | string | ||
operatingSystem | string | ||
osImage | string | ||
osKernel | string | ||
providerID | string | ||
unschedulable * | boolean |
Kube Pod
kube_pod inherits from Task
| Property | Type | Description | Specifications |
|---|---|---|---|
activeDeadlineSeconds | number | ||
automountServiceAccountToken | boolean | ||
cpuLimit | string | ||
cpuRequest | string | ||
deletionGracePeriodSeconds | number | ||
dnsPolicy | string | ||
enableServiceLinks | boolean | ||
finalizers | array of strings | ||
generation | number | ||
hasSecurityContext | boolean | ||
hostIPC | boolean | ||
hostname | string | ||
hostNetwork | boolean | ||
hostPID | boolean | ||
imagePullSecrets | array of strings | ||
memoryLimit | string | ||
memoryRequest | string | ||
namespace | string | ||
nodeName | string | ||
normalizedCpuLimit | number | ||
normalizedCpuRequest | number | ||
normalizedMemoryLimit | number | ||
normalizedMemoryRequest | number | ||
podAnnotations | array of strings | ||
preemptionPolicy | string | ||
priority | number | ||
priorityClassName | string | ||
resourceVersion | string | ||
restartPolicy | string | ||
runtimeClassName | string | ||
schedulerName | string | ||
securityContext.apparmorProfile.localhostProfile | string | ||
securityContext.apparmorProfile.type | string | ||
securityContext.fsGroup | number | ||
securityContext.fsGroupChangePolicy | string | ||
securityContext.runAsGroup | number | ||
securityContext.runAsNonRoot | boolean | ||
securityContext.runAsUser | number | ||
securityContext.seccompProfile.localhostProfile | string | ||
securityContext.seccompProfile.type | string | ||
securityContext.seLinuxChangePolicy | string | ||
securityContext.seLinuxOptions.level | string | ||
securityContext.seLinuxOptions.role | string | ||
securityContext.seLinuxOptions.type | string | ||
securityContext.seLinuxOptions.user | string | ||
securityContext.supplementalGroups | array of numbers | ||
securityContext.supplementalGroupsPolicy | string | ||
securityContext.sysctls | array of strings | ||
securityContext.windowsOptions.gmsaCredentialSpec | string | ||
securityContext.windowsOptions.gmsaCredentialSpecName | string | ||
securityContext.windowsOptions.hostProcess | boolean | ||
securityContext.windowsOptions.runAsUserName | string | ||
serviceAccount | string | ||
serviceAccountName | string | ||
setHostnameAsFQDN | boolean | ||
shareProcessNamespace | boolean | ||
status.hostIP | string | ||
status.hostIPs | array of strings | ||
status.message | string | ||
status.nominatedNodeName | string | ||
status.phase | string | ||
status.podIP | string | ||
status.podIPs | array of strings | ||
status.qosClass | string | ||
status.reason | string | ||
status.startTime | number | ||
subdomain | string | ||
terminationGracePeriodSeconds | number |
Kube Replica Set
kube_replica_set inherits from Deployment
| Property | Type | Description | Specifications |
|---|---|---|---|
annotations | array of strings | ||
apiVersion | string | ||
currentSize | number | ||
desiredSize | number | ||
generation | number | ||
kind | string | ||
labels | array of strings | ||
minReadySeconds | number | ||
namespace | string | ||
ownerReferences | array of strings | ||
resourceVersion | string | ||
selector | string | ||
status.availableReplicas | number | ||
status.fullyLabeledReplicas | number | ||
status.observedGeneration | number | ||
status.readyReplicas | number |
Kube Role
kube_role inherits from AccessRole
| Property | Type | Description | Specifications |
|---|---|---|---|
apiVersion | string | ||
deletionGracePeriodSeconds | number | ||
deletionOn | number | ||
kind | string | ||
namespace * | string | ||
resourceVersion | string |
Kube Role Binding
kube_role_binding inherits from AccessPolicy
| Property | Type | Description | Specifications |
|---|---|---|---|
admin | boolean | ||
apiVersion | string | ||
deletionGracePeriodSeconds | number | ||
deletionOn | number | ||
kind | string | ||
namespace * | string | ||
resourceVersion | string | ||
roleRefApiGroup | string | ||
roleRefKind | string | ||
roleRefName | string | ||
subjectCount | number | ||
subjects | array of strings |
Kube Role Rule
kube_role_rule inherits from Rule
| Property | Type | Description | Specifications |
|---|---|---|---|
apiGroups | array of strings | ||
namespace | string | ||
resourceNames | array of strings | ||
resources | array of strings | ||
verbs * | array of strings |
Kube Secret
kube_secret inherits from Secret, NHI
| Property | Type | Description | Specifications |
|---|---|---|---|
apiVersion | string | ||
deletionGracePeriodSeconds | number | ||
deletionOn | number | ||
immutable | boolean | ||
kind | string | ||
namespace | string | ||
resourceVersion | string | ||
type | string |
Kube Service
kube_service inherits from Service
| Property | Type | Description | Specifications |
|---|---|---|---|
allocateLoadBalancerNodePorts | boolean | ||
category * | array of strings | ||
clusterIP | string | ||
clusterIPs | array of strings | ||
deletionGracePeriodSeconds | number | ||
endpoints | array of strings | ||
externalIPs | array of strings | ||
externalName | string | ||
externalTrafficPolicy | string | ||
function * | array of strings | ||
healthCheckNodePort | number | ||
ipFamilies | array of strings | ||
ipFamilyPolicy | string | ||
loadBalancerIP | string | ||
loadBalancerSourceRanges | array of strings | ||
namespace | string | ||
portName | array of strings | ||
portNumber | array of numbers | ||
protocol | array of strings | ||
publishNotReadyAddresses | boolean | ||
resourceVersion | string | ||
selectors | array of strings | ||
sessionAffinity | string | ||
targetPort | array of strings | ||
type | string |
Kube Service Account
kube_service_account inherits from User, NHI
| Property | Type | Description | Specifications |
|---|---|---|---|
deletionGracePeriodSeconds | integer | ||
generation | integer | ||
namespace | string | ||
resourceVersion | string | ||
secretIds | array of strings | ||
secretNames | array of strings |
Kube Stateful Set
kube_stateful_set inherits from Deployment
| Property | Type | Description | Specifications |
|---|---|---|---|
deletionGracePeriodSeconds | number | ||
generation | number | ||
namespace | string | ||
podManagementPolicy | string | ||
replicas | number | ||
resourceVersion | string | ||
revisionHistoryLimit | number | ||
serviceName | string | ||
status.collisionCount | number | ||
status.currentReplicas | number | ||
status.currentRevision | string | ||
status.observedGeneration | number | ||
status.readyReplicas | number | ||
status.replicas | number | ||
status.updatedReplicas | number | ||
status.updateRevision | string | ||
strategy.partition | number | ||
strategy.type | string |
Kube User
kube_user inherits from User
| Property | Type | Description | Specifications |
|---|---|---|---|
certFile | string | ||
keyFile | string |
Kube Volume
kube_volume inherits from Disk
| Property | Type | Description | Specifications |
|---|---|---|---|
awsVolumeID | string | ||
azureDiskName | string | ||
azureDiskURI | string | ||
claimName | string | ||
configMapName | string | ||
csiDriver | string | ||
csiFsType | string | ||
csiReadOnly | boolean | ||
emptyDirMedium | string | ||
emptyDirSizeLimit | string | ||
gcePdName | string | ||
hostPath | string | ||
hostPathType | string | ||
namespace | string | ||
nfsPath | string | ||
nfsServer | string | ||
readOnly | boolean | ||
secretName | string | ||
volumeName * | string | ||
volumeType * | string |
Release Notes
- 2026-09-21 — Added the Ingest All Node Images option, which ingests every image cached on each node and relates nodes to the images they hold. Images can now be collected without ingesting pods.
- 2026-03-31 — Added OS kernel version to managed Kubernetes node entities.
- 2025-12-01 — Added support for Custom Resource Definitions (CRDs), enabling ingestion of custom Kubernetes resource types.
- 2025-11-20 — Added mapped relationships linking Kubernetes clusters to their underlying cloud provider resources in Azure AKS, Google GKE, and AWS EKS.
- 2025-11-20 — Added Kubernetes role rules ingestion as individual rule entities, each linked to their parent role.
- 2025-11-20 — Added relationships linking Kubernetes pods to their assigned service accounts and nodes, containers to their referenced secrets, config maps, and volumes, and deployments to their replica sets.
- 2025-11-19 — Added ingestion of Kubernetes Services with namespace and selector relationships.
- 2025-11-19 — Added ingestion of Kubernetes Secrets (metadata only, data fields are not ingested).
- 2025-11-12 — Added ingestion of Kubernetes Role Bindings and Cluster Role Bindings with subject relationships.
- 2025-11-11 — Added Kubernetes container image ingestion with configuration options for image scanning.
- 2025-11-10 — Added ingestion of Kubernetes Replica Sets with pod template relationships.
- 2025-11-10 — Added ingestion of Kubernetes StatefulSets as new entity types.
- 2025-11-07 — Added ingestion of container images, Jobs, and Service Accounts.
- 2025-11-07 — Added ingestion of Kubernetes Volumes with pod relationships.
- 2025-11-07 — Added ingestion of Kubernetes Ingress resources as new entity types.
- 2025-11-06 — Added ingestion of Kubernetes Roles as new entity types.
- 2025-11-06 — Added ingestion of Kubernetes Containers within pods as new entity types.
- 2025-11-06 — Added ingestion of Kubernetes Network Policies as new entity types.
- 2025-11-05 — Added ingestion of Kubernetes Users with RBAC relationships.
- 2025-11-05 — Added ingestion of Kubernetes Deployments with replica set relationships.
- 2025-11-05 — Added ingestion of Kubernetes Nodes as new entity types.
- 2025-11-05 — Added ingestion of Kubernetes Cluster Role Bindings.
- 2025-11-04 — Added ingestion of Kubernetes ConfigMaps as new entity types.
- 2025-11-04 — Added ingestion of Kubernetes Daemon Sets as new entity types.
- 2025-11-03 — Added ingestion of Kubernetes Pods with container relationships.
- 2025-10-31 — Added ingestion of Kubernetes CronJobs as new entity types.
- 2025-10-31 — Added ingestion of Kubernetes Namespaces as new entity types.
- 2025-10-30 — Added Kubernetes Cluster Roles ingestion.
- 2025-10-29 — Added Kubernetes Cluster ingestion as the foundation entity for all Kubernetes-managed resources.