Explore the map
1
Open the Network Map
Click Network Map in the Infrastructure section of the sidebar. The counters above the
graph show how many nodes are Visible, how many are Kubernetes and AWS, and how many
Edges are drawn.
2
Filter by type
Below the counters, each type has a swatch in its own colour and shape: round for Kubernetes,
square for AWS. Click a type to take it off the map and click it again to bring it back. Click a
family name, Kubernetes or AWS, to switch every type in that family together. Pods start
hidden because a cluster has so many of them.
3
Narrow by namespace
Use the namespace menu, All Namespaces by default, to focus on one Kubernetes namespace.
4
Select a node
Click a node to highlight its neighbours and open a detail panel with its attributes, such as
namespace, image, replicas, region, engine, ports and tags.
5
Refresh
Click Refresh to reload the page’s copy of the data. It does not re-scan your estate. The
map shows the last data collected from your estate.
Read the edges
Not every line carries the same weight. Hover a line to see how it was drawn: observed, inferred or may connect.
A may connect line is labelled “allowed by” and the group name. A missing line does not mean traffic is not allowed. Where connections are too many to draw, the page says how many were left off and the resource’s panel names the rule that allows them.
Read the markers
- A red dot on a resource means a security group admits
0.0.0.0/0. The detail panel lists it under Open to 0.0.0.0/0 with the ports. This describes the rule, not whether anything can route there. - A green dot means the workload was deployed in the last 24 hours and the deploy succeeded. Amber means it did not, or has not yet. Only deploys and rollbacks count. The panel shows Last deploy, Version, Commit and Deployed by when known.
Jump to findings
When a node has related findings, the panel ends with a Findings section. Efficiency and Security each show how many are open and link to the page that owns them. A line that says there is no completed scan, or that some images are unscanned, means the check has not run for that resource. It does not mean the resource is clean.What you see
An empty map tells you why: either nothing has been connected yet, or the current filters hide everything. Clear the namespace and re-enable the types to tell the two apart.Related
- Review security findings: the findings behind the red dots.
- Find and reclaim cloud waste: the cost of what the map shows.
- Connect your data: connect a source so the map fills in.

