Abstract design featuring large overlapping circles in shades of blue, with hexagonal patterns and a grid background. The word Upwind is in the upper left corner.

Easily Query Kubernetes Objects with Upwind’s Runtime Topology Map 

Denise Ashur January 16, 2025

Easily Query Kubernetes Objects with Upwind’s Runtime Topology Map 

We’re excited to introduce a powerful new container security capability that makes it easier than ever to view and query Kubernetes objects while exploring the entire exposure path with Upwind’s runtime topology map.

Upwind has always provided deep visibility into containerized resources, showing traffic by port, process, and protocol, as well as details into an individual resource’s exposure path.

Screenshot of a network dashboard from Upwind. It shows a network map with nodes labeled Internet and several services like ReverseProxy and Service Discovery. The sidebar includes options for Map, Risks, and Configurations.

With this enhancement, you can now also view, query, and filter Kubernetes (K8s) resources directly in the Upwind Topology Map, including details such as:

  • Kubernetes service names, service ports, and service types
  • Kubernetes ingress names and communication to Kubernetes clusters
  • Connected cloud provider load balancers 

These advanced search capabilities make it effortless to filter cloud topology automatically and pinpoint relevant Kubernetes resources and risk parameters. You can view the complete request path, including services, Internet connections, load balancers and more – helping you identify potential risks faster by:

  • Pinpointing misconfigurations that could lead to vulnerabilities
  • Identifying exposed services that may be unintentionally accessible
  • Tracing unintended communication paths to mitigate risks effectively

These new query capabilities empower you to gain deeper visibility into resource communication, validate infrastructure changes, and proactively secure containerized environments. To learn more, schedule a demo today.

Contents

Further Reading

behind-the-curtain-part-02

What’s Behind the Curtain? AWS Bedrock AgentCore Runtime Tear Down – Part II

Recap In Part I, we explored the AgentCore Runtime microVM from the inside and discovered we weren't alone - four platform binaries were running alongside our code, and one of them was quietly shipping logs to an AWS-internal S3 bucket. We left off with a question: what can we learn from these internal components, and…
behind-the-curtain-part-01

What’s Behind the Curtain? AWS Bedrock AgentCore Runtime Tear Down – Part I

Introduction When you deploy an AI agent to AWS Bedrock AgentCore Runtime, your code runs inside a Firecracker microVM - but it doesn't run alone. In this three-part series, we tear down the platform internals, document what we found, and assess how well the isolation holds up. Setting the Stage AWS Bedrock AgentCore Runtime is…
upwind-code

Upwind Code Expands Enterprise Coverage to Azure DevOps and Bitbucket Cloud

Modern development organizations rarely keep all their code in one place. Teams may use different version control platforms because of acquisitions, business-unit preferences, regional requirements, or existing development workflows. But when code is spread across multiple providers, application security coverage can become fragmented too. Today, Upwind Code adds support for Azure DevOps and Bitbucket Cloud.…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS