Abstract design featuring large overlapping circles in shades of blue, with hexagonal patterns and a grid background. The word Upwind is in the upper left corner.

Easily Query Kubernetes Objects with Upwind’s Runtime Topology Map 

Denise Ashur January 16, 2025

Easily Query Kubernetes Objects with Upwind’s Runtime Topology Map 

We’re excited to introduce a powerful new container security capability that makes it easier than ever to view and query Kubernetes objects while exploring the entire exposure path with Upwind’s runtime topology map.

Upwind has always provided deep visibility into containerized resources, showing traffic by port, process, and protocol, as well as details into an individual resource’s exposure path.

Screenshot of a network dashboard from Upwind. It shows a network map with nodes labeled Internet and several services like ReverseProxy and Service Discovery. The sidebar includes options for Map, Risks, and Configurations.

With this enhancement, you can now also view, query, and filter Kubernetes (K8s) resources directly in the Upwind Topology Map, including details such as:

  • Kubernetes service names, service ports, and service types
  • Kubernetes ingress names and communication to Kubernetes clusters
  • Connected cloud provider load balancers 

These advanced search capabilities make it effortless to filter cloud topology automatically and pinpoint relevant Kubernetes resources and risk parameters. You can view the complete request path, including services, Internet connections, load balancers and more – helping you identify potential risks faster by:

  • Pinpointing misconfigurations that could lead to vulnerabilities
  • Identifying exposed services that may be unintentionally accessible
  • Tracing unintended communication paths to mitigate risks effectively

These new query capabilities empower you to gain deeper visibility into resource communication, validate infrastructure changes, and proactively secure containerized environments. To learn more, schedule a demo today.

Contents

Further Reading

Let Me Speak to Your Manager (Account)

Let Me Speak to Your Manager (Account)

The management account is the most privileged account in any AWS Organization. It controls SCPs, creates and deletes member accounts, manages IAM Identity Center, and is itself exempt from SCPs. Getting its 12-digit account ID is the first step in targeting it. The documented way to get it is organizations:DescribeOrganization - but security-conscious environments restrict…
Configuration-Focus

Introducing the new Configurations experience in Upwind

Compliance should not be a fire drill! Ask a security team how audit season goes and you will often hear a version of the same story. Someone pulls a list of cloud accounts. Someone else exports findings into a spreadsheet that is already outdated by the time it is shared. Screenshots get pasted into a…
What You Could Build If IAM Let You

What You Could Build If IAM Let You: New Policies From Undocumented Condition Keys

In the previous post, we mapped 36 condition keys that the IAM engine evaluates but has never documented. The decomposition model, the service-specific resource identifiers, the organizational metadata - all of it sitting in the request context, invisible unless you probe for it. That post was about discovery. This one is about what you can…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS