Container inventoryKnow every cluster, registry, workload, and administrative path.
Inventory production and non-production clusters, orchestrator versions, node operating systems, registries, image repositories, namespaces, ingress controllers, service meshes, public endpoints, CI/CD systems, admission controllers, secret stores, backup tools, and cluster-management platforms. Assign an accountable platform or service owner for each cluster.
Track the workloads that matter most: internet-facing services, workloads with privileged host access, identity components, payment or regulated-data services, security tooling, CI runners, databases, and applications with broad service credentials. A cluster may host hundreds of deployments, but a small number often create most of the security consequence.
Record support status and upgrade ownership. Container platforms move quickly; unsupported Kubernetes versions, stale node images, abandoned Helm charts, and old admission policies can quietly preserve vulnerable components even when application images are current.