Skip to main content
The Network Map draws your estate as a graph: Kubernetes ingresses, services and workloads, and AWS VPCs, ECS clusters and services, EC2 instances, Lambda functions, RDS instances, load balancers, target groups and Elastic IPs. Use it to see what sits next to what before you change or investigate something. The map fills in once you have connected a Kubernetes cluster or an AWS data source. Every role can open it.

Explore the map

1

Open the Network Map

Click Network Map in the Infrastructure section of the sidebar. The counters above the graph show how many nodes are Visible, how many are Kubernetes and AWS, and how many Edges are drawn.
2

Filter by type

Below the counters, each type has a swatch in its own colour and shape: round for Kubernetes, square for AWS. Click a type to take it off the map and click it again to bring it back. Click a family name, Kubernetes or AWS, to switch every type in that family together. Pods start hidden because a cluster has so many of them.
3

Narrow by namespace

Use the namespace menu, All Namespaces by default, to focus on one Kubernetes namespace.
4

Select a node

Click a node to highlight its neighbours and open a detail panel with its attributes, such as namespace, image, replicas, region, engine, ports and tags.
5

Refresh

Click Refresh to reload the page’s copy of the data. It does not re-scan your estate. The map shows the last data collected from your estate.

Read the edges

Not every line carries the same weight. Hover a line to see how it was drawn: observed, inferred or may connect. A may connect line is labelled “allowed by” and the group name. A missing line does not mean traffic is not allowed. Where connections are too many to draw, the page says how many were left off and the resource’s panel names the rule that allows them.

Read the markers

  • A red dot on a resource means a security group admits 0.0.0.0/0. The detail panel lists it under Open to 0.0.0.0/0 with the ports. This describes the rule, not whether anything can route there.
  • A green dot means the workload was deployed in the last 24 hours and the deploy succeeded. Amber means it did not, or has not yet. Only deploys and rollbacks count. The panel shows Last deploy, Version, Commit and Deployed by when known.

Jump to findings

When a node has related findings, the panel ends with a Findings section. Efficiency and Security each show how many are open and link to the page that owns them. A line that says there is no completed scan, or that some images are unscanned, means the check has not run for that resource. It does not mean the resource is clean.

What you see

An empty map tells you why: either nothing has been connected yet, or the current filters hide everything. Clear the namespace and re-enable the types to tell the two apart.