Multi-cloud honesty
Service coverage
Every individual service across Azure, AWS, GCP, Kubernetes, identity systems, and hybrid connectivity — with a fully / partially / planned / not-supported grade per capability. We do not pretend coverage we haven't built. See the guide.
- ◐Azure Virtual Machinesazure.compute.virtualmachines· computeCommon case coveredSupported: discovery · inventory · topology · posture · network · identity · observability · cost · recommendationsNIC → Subnet → NSG join is native. Process telemetry is partial via Defender for Servers; full process tree needs CrowdStrike/Dynatrace agent.
- ◐Azure Kubernetes Service (AKS)azure.compute.aks· computeCommon case coveredSupported: discovery · inventory · topology · posture · network · identity · observability · cost · recommendationsCluster surface + nodepool config is native. In-cluster object inventory (Pods, Services, NetworkPolicies) needs the Kubernetes connector with kubeconfig.
- ○Microsoft Entra IDazure.identity.entraid· identityPlannedSupported: discovery · inventory · posture · identity · observability · cost · recommendationsUsers, groups, app regs, service principals, role assignments via Graph + ARM RBAC.
Read-only and advisory by design — we never modify cloud resources. The grades describe what we can observe, not what we can change.