> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sreagent.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Read the Network Map

> Explore your Kubernetes and AWS topology, filter it by type, and tell observed links from guesses and permitted paths.

export const Plan = ({tier}) => <Badge color="blue">{tier} plan</Badge>;

The **Network Map** draws your estate as a graph: Kubernetes ingresses, services and workloads, and AWS VPCs, ECS clusters and services, EC2 instances, Lambda functions, RDS instances, load balancers, target groups and Elastic IPs. Use it to see what sits next to what before you change or investigate something.

<Plan tier="Business" />

The map fills in once you have connected a Kubernetes cluster or an AWS data source. Every role can open it.

## Explore the map

<Steps>
  <Step title="Open the Network Map">
    Click **Network Map** in the **Infrastructure** section of the sidebar. The counters above the
    graph show how many nodes are **Visible**, how many are **Kubernetes** and **AWS**, and how many
    **Edges** are drawn.
  </Step>

  <Step title="Filter by type">
    Below the counters, each type has a swatch in its own colour and shape: round for Kubernetes,
    square for AWS. Click a type to take it off the map and click it again to bring it back. Click a
    family name, **Kubernetes** or **AWS**, to switch every type in that family together. Pods start
    hidden because a cluster has so many of them.
  </Step>

  <Step title="Narrow by namespace">
    Use the namespace menu, **All Namespaces** by default, to focus on one Kubernetes namespace.
  </Step>

  <Step title="Select a node">
    Click a node to highlight its neighbours and open a detail panel with its attributes, such as
    namespace, image, replicas, region, engine, ports and tags.
  </Step>

  <Step title="Refresh">
    Click **Refresh** to reload the page's copy of the data. It does not re-scan your estate. The
    map shows the last data collected from your estate.
  </Step>
</Steps>

## Read the edges

Not every line carries the same weight. Hover a line to see how it was drawn: observed, inferred or may connect.

| Line | What it tells you |
| - | - |
| Observed | Read directly from your AWS account or your cluster. Hovering names where the line came from. |
| Inferred | Worked out rather than read directly, such as a workload and its pods. Right almost always, but not a certainty. |
| Dashed line, labelled **may connect** | A security group rule allows the traffic. Nothing has watched any traffic: a database group letting an app group in on its port means a connection would be permitted. |

A **may connect** line is labelled "allowed by" and the group name. A missing line does not mean traffic is not allowed. Where connections are too many to draw, the page says how many were left off and the resource's panel names the rule that allows them.

## Read the markers

* A **red dot** on a resource means a security group admits `0.0.0.0/0`. The detail panel lists it under **Open to 0.0.0.0/0** with the ports. This describes the rule, not whether anything can route there.
* A **green dot** means the workload was deployed in the last 24 hours and the deploy succeeded. **Amber** means it did not, or has not yet. Only deploys and rollbacks count. The panel shows **Last deploy**, **Version**, **Commit** and **Deployed by** when known.

## Jump to findings

When a node has related findings, the panel ends with a **Findings** section. **Efficiency** and **Security** each show how many are open and link to the page that owns them. A line that says there is no completed scan, or that some images are unscanned, means the check has not run for that resource. It does not mean the resource is clean.

## What you see

An empty map tells you why: either nothing has been connected yet, or the current filters hide everything. Clear the namespace and re-enable the types to tell the two apart.

## Related

* [Review security findings](/guides/security-cost/security): the findings behind the red dots.
* [Find and reclaim cloud waste](/guides/security-cost/finops): the cost of what the map shows.
* [Connect your data](/guides/get-started/connect-your-data): connect a source so the map fills in.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.