Multi-cloud honesty
Service coverage
Every individual service across Azure, AWS, GCP, Kubernetes, identity systems, and hybrid connectivity — with a fully / partially / planned / not-supported grade per capability. We do not pretend coverage we haven't built. See the guide.
- ○Azure Container Instancesazure.compute.aci· computePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Functionsazure.compute.functions· computePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Batchazure.compute.batch· computePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Managed Disksazure.compute.disks· computePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Spring Appsazure.compute.springapps· computePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Service Fabricazure.compute.servicefabric· computePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Public IPazure.network.publicip· networkingPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Front Doorazure.network.frontdoor· networkingPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure CDNazure.network.cdn· networkingPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Private DNS Zoneazure.network.privatedns· networkingPlannedSupported: discovery · inventory · topology · posture · identity · observability · cost
- ○Azure DNSazure.network.publicdns· networkingPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ◐ExpressRouteazure.network.expressroute· hybridCommon case coveredSupported: discovery · inventory · topology · posture · identity · observability · cost · recommendationsCircuit + peering visible. Has a hybridConnectivity playbook for chain validation.
- ○VPN Gatewayazure.network.vpngateway· hybridPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Virtual WANazure.network.virtualwan· hybridPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Route Table / UDRazure.network.routetable· networkingPlannedSupported: discovery · inventory · topology · posture · identity · observability · cost
- ○Network Watcherazure.network.networkwatcher· observabilityPlannedSupported: discovery · inventory · posture · identity · observability · costFlow logs + topology snapshots + IP flow verify. Used as evidence source by NSG playbooks.
- ○Azure Bastionazure.network.bastion· securityPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○DDoS Protectionazure.network.ddos· securityPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure NetApp Filesazure.storage.netapp· storagePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Data Box Edgeazure.storage.databoxedge· storagePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○SQL Managed Instanceazure.db.sqlmi· databasePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Database for PostgreSQLazure.db.postgres· databasePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Database for MySQLazure.db.mysql· databasePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Database for MariaDBazure.db.mariadb· databasePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Cosmos DBazure.db.cosmos· databasePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Cache for Redisazure.db.redis· databasePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Synapse Analyticsazure.db.synapse· analyticsPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Data Explorerazure.db.kusto· analyticsPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure AI Searchazure.db.search· ai_mlPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Microsoft Entra IDazure.identity.entraid· identityPlannedSupported: discovery · inventory · posture · identity · observability · cost · recommendationsUsers, groups, app regs, service principals, role assignments via Graph + ARM RBAC.
- ○User-Assigned Managed Identityazure.identity.uami· identityPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Privileged Identity Managementazure.identity.pim· identityPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure AD B2Cazure.identity.b2c· identityPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Microsoft Defender for Cloudazure.security.defender· securityPlannedSupported: discovery · inventory · posture · identity · observability · cost · recommendationsFindings + secure score + plans. Defender for Servers/Containers/Storage/SQL all surface via assessments.
- ○Microsoft Sentinelazure.security.sentinel· securityPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Policyazure.security.policy· managementPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○App Configurationazure.security.appconfig· managementPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Application Gateway WAF v2azure.security.appgateway_waf· securityPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Front Door WAFazure.security.frontdoor_waf· securityPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Cognitive Servicesazure.ai.cognitiveservices· ai_mlPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Machine Learningazure.ai.ml· ai_mlPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Bot Serviceazure.ai.bot· ai_mlPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Monitorazure.obs.monitor· observabilityPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Log Analyticsazure.obs.loganalytics· observabilityPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Application Insightsazure.obs.appinsights· observabilityPlannedSupported: discovery · inventory · posture · identity · observability · costTrace data only if the app is instrumented. Service map from App Insights is partial; full topology benefits from Dynatrace/Datadog.
- ○Activity Logazure.obs.activitylog· observabilityPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Service Healthazure.obs.servicehealth· observabilityPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure DevOpsazure.devops.devops· devopsPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Container Registryazure.devops.acr· devopsPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Service Busazure.integration.servicebus· integrationPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Event Hubsazure.integration.eventhub· integrationPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Event Gridazure.integration.eventgrid· integrationPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Logic Appsazure.integration.logicapps· integrationPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○API Managementazure.integration.apim· integrationPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Notification Hubsazure.integration.notificationhubs· integrationPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Relayazure.integration.relay· integrationPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Resource Managerazure.mgmt.arm· managementPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Policyazure.mgmt.policy· managementPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Blueprints (legacy)azure.mgmt.blueprints· managementPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Cost Managementazure.mgmt.cost· managementPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Automation Accountazure.mgmt.automation· managementPlannedSupported: discovery · inventory · posture · identity · observability · cost · recommendationsHas a deep playbook (automationHybridWorker) for hybrid worker + module CVE analysis.
- ○Azure Arcazure.mgmt.arc· hybridPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Lighthouseazure.mgmt.lighthouse· managementPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Advisorazure.mgmt.advisor· managementPlannedSupported: discovery · inventory · posture · identity · observability · cost · recommendations
- ○Resource Graphazure.mgmt.resourcegraph· managementPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○IoT Hubazure.iot.hub· iot_edgePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○IoT Centralazure.iot.central· iot_edgePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Digital Twinsazure.iot.digitaltwins· iot_edgePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Device Provisioning Serviceazure.iot.dps· iot_edgePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Sphereazure.iot.sphere· iot_edgePlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Communication Servicesazure.media.acs· mediaPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Mapsazure.media.maps· mediaPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Recovery Services Vaultazure.migration.recoveryvault· migrationPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Azure Migrateazure.migration.databoxedge· migrationPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○Database Migration Serviceazure.migration.dms· migrationPlannedSupported: discovery · inventory · posture · identity · observability · cost
- ○EC2aws.compute.ec2· computePlannedSupported: discovery · inventory · cost
- ○Auto Scaling Groupsaws.compute.asg· computePlannedSupported: discovery · inventory · cost
- ○ECSaws.compute.ecs· computePlannedSupported: discovery · inventory · cost
- ○EKSaws.compute.eks· computePlannedSupported: discovery · inventory · cost
- ○Fargateaws.compute.fargate· computePlannedSupported: discovery · inventory · cost
- ○Lambdaaws.compute.lambda· computePlannedSupported: discovery · inventory · cost · recommendationsawsLambdaVpc playbook exists for VPC + IAM posture.
- ○Batchaws.compute.batch· computePlannedSupported: discovery · inventory · cost
- ○App Runneraws.compute.apprunner· computePlannedSupported: discovery · inventory · cost
- ○VPCaws.network.vpc· networkingPlannedSupported: discovery · inventory · cost
- ○Subnetaws.network.subnet· networkingPlannedSupported: discovery · inventory · cost
- ○Security Groupaws.network.sg· networkingPlannedSupported: discovery · inventory · cost · recommendationsawsSgBroadSource playbook computes SG tier + flags 0.0.0.0/0 ingress.
- ○Network ACLaws.network.nacl· networkingPlannedSupported: discovery · inventory · cost
- ○Route Tableaws.network.routetable· networkingPlannedSupported: discovery · inventory · cost
- ○Internet Gatewayaws.network.igw· networkingPlannedSupported: discovery · inventory · cost
- ○NAT Gatewayaws.network.natgw· networkingPlannedSupported: discovery · inventory · cost
- ○Transit Gatewayaws.network.tgw· hybridPlannedSupported: discovery · inventory · cost
- ○VPN Gatewayaws.network.vpngw· hybridPlannedSupported: discovery · inventory · cost
- ○Direct Connectaws.network.directconnect· hybridPlannedSupported: discovery · inventory · cost
- ○ELB (classic)aws.network.elb· networkingPlannedSupported: discovery · inventory · cost
- ○Application Load Balanceraws.network.alb· networkingPlannedSupported: discovery · inventory · cost
- ○Network Load Balanceraws.network.nlb· networkingPlannedSupported: discovery · inventory · cost
- ○CloudFrontaws.network.cloudfront· networkingPlannedSupported: discovery · inventory · cost
- ○Route 53aws.network.route53· networkingPlannedSupported: discovery · inventory · cost
- ○PrivateLinkaws.network.privatelink· networkingPlannedSupported: discovery · inventory · cost
- ○S3aws.storage.s3· storagePlannedSupported: discovery · inventory · cost · recommendationsawsS3CrossAccount playbook computes cross-account access + Block Public Access posture.
- ○EBSaws.storage.ebs· storagePlannedSupported: discovery · inventory · cost
- ○EFSaws.storage.efs· storagePlannedSupported: discovery · inventory · cost
- ○FSxaws.storage.fsx· storagePlannedSupported: discovery · inventory · cost
- ○S3 Glacieraws.storage.glacier· storagePlannedSupported: discovery · inventory · cost
- ○RDSaws.db.rds· databasePlannedSupported: discovery · inventory · cost · recommendationsawsRdsPublic playbook detects publicly-accessible instances.
- ○Auroraaws.db.aurora· databasePlannedSupported: discovery · inventory · cost
- ○DynamoDBaws.db.dynamodb· databasePlannedSupported: discovery · inventory · cost
- ○ElastiCacheaws.db.elasticache· databasePlannedSupported: discovery · inventory · cost
- ○DocumentDBaws.db.documentdb· databasePlannedSupported: discovery · inventory · cost
- ○Neptuneaws.db.neptune· databasePlannedSupported: discovery · inventory · cost
- ○Redshiftaws.db.redshift· analyticsPlannedSupported: discovery · inventory · cost
- ○OpenSearchaws.db.opensearch· ai_mlPlannedSupported: discovery · inventory · cost
- ○IAMaws.identity.iam· identityPlannedSupported: discovery · inventory · identity · cost · recommendationsRole/Policy/User enumeration native via IAM API; least-privilege analyzer roadmap.
- ○Cognitoaws.identity.cognito· identityPlannedSupported: discovery · inventory · cost
- ○AWS SSO / IAM Identity Centeraws.identity.sso· identityPlannedSupported: discovery · inventory · cost
- ○Secrets Manageraws.identity.secretsmanager· securityPlannedSupported: discovery · inventory · cost
- ○KMSaws.identity.kms· securityPlannedSupported: discovery · inventory · cost
- ○Security Hubaws.security.securityhub· securityPlannedSupported: discovery · inventory · posture · costFinding ingestion stub exists; full enrichment roadmap.
- ○GuardDutyaws.security.guardduty· securityPlannedSupported: discovery · inventory · cost
- ○Inspectoraws.security.inspector· securityPlannedSupported: discovery · inventory · cost
- ○Macieaws.security.macie· securityPlannedSupported: discovery · inventory · cost
- ○Detectiveaws.security.detective· securityPlannedSupported: discovery · inventory · cost
- ○AWS Configaws.security.config· managementPlannedSupported: discovery · inventory · posture · cost
- ○CloudTrailaws.security.cloudtrail· observabilityPlannedSupported: discovery · inventory · cost
- ○WAFaws.security.waf· securityPlannedSupported: discovery · inventory · cost
- ○Shieldaws.security.shield· securityPlannedSupported: discovery · inventory · cost
- ○Firewall Manageraws.security.firewallmgr· securityPlannedSupported: discovery · inventory · cost
- ○CloudWatch Metricsaws.obs.cloudwatch· observabilityPlannedSupported: discovery · inventory · observability · cost
- ○CloudWatch Logsaws.obs.cwlogs· observabilityPlannedSupported: discovery · inventory · observability · cost
- ○X-Rayaws.obs.xray· observabilityPlannedSupported: discovery · inventory · cost
- ○EventBridgeaws.obs.eventbridge· integrationPlannedSupported: discovery · inventory · cost
- ○SQSaws.integration.sqs· integrationPlannedSupported: discovery · inventory · cost
- ○SNSaws.integration.sns· integrationPlannedSupported: discovery · inventory · cost
- ○Step Functionsaws.integration.stepfn· integrationPlannedSupported: discovery · inventory · cost
- ○API Gatewayaws.integration.apigw· integrationPlannedSupported: discovery · inventory · cost
- ○AppSyncaws.integration.appsync· integrationPlannedSupported: discovery · inventory · cost
- ○Organizationsaws.mgmt.organizations· managementPlannedSupported: discovery · inventory · cost
- ○Control Toweraws.mgmt.controltower· managementPlannedSupported: discovery · inventory · cost
- ○Service Catalogaws.mgmt.servicecatalog· managementPlannedSupported: discovery · inventory · cost
- ○CloudFormationaws.mgmt.cfn· devopsPlannedSupported: discovery · inventory · cost
- ○Systems Manageraws.mgmt.ssm· managementPlannedSupported: discovery · inventory · cost
- ○ECRaws.devops.ecr· devopsPlannedSupported: discovery · inventory · cost
- ○CodeBuildaws.devops.codebuild· devopsPlannedSupported: discovery · inventory · cost
- ○CodePipelineaws.devops.codepipeline· devopsPlannedSupported: discovery · inventory · cost
- ○CodeArtifactaws.devops.codeartifact· devopsPlannedSupported: discovery · inventory · cost
- ○Compute Enginegcp.compute.gce· computePlannedSupported: discovery · inventory · cost
- ○GKEgcp.compute.gke· computePlannedSupported: discovery · inventory · cost · recommendationsgcpGkeNetworking playbook for control-plane + nodepool posture.
- ○Cloud Rungcp.compute.cloudrun· computePlannedSupported: discovery · inventory · cost
- ○Cloud Functionsgcp.compute.functions· computePlannedSupported: discovery · inventory · cost · recommendationsgcpCloudFunctionIngress playbook checks ingress posture.
- ○App Enginegcp.compute.appengine· computePlannedSupported: discovery · inventory · cost
- ○GCP Batchgcp.compute.batch· computePlannedSupported: discovery · inventory · cost
- ○VPCgcp.network.vpc· networkingPlannedSupported: discovery · inventory · cost
- ○Subnetworkgcp.network.subnet· networkingPlannedSupported: discovery · inventory · cost
- ○Firewall Rulegcp.network.firewall· networkingPlannedSupported: discovery · inventory · cost
- ○Routesgcp.network.routes· networkingPlannedSupported: discovery · inventory · cost
- ○Cloud NATgcp.network.cloudnat· networkingPlannedSupported: discovery · inventory · cost
- ○Cloud Load Balancinggcp.network.lb· networkingPlannedSupported: discovery · inventory · cost
- ○Cloud CDNgcp.network.cdn· networkingPlannedSupported: discovery · inventory · cost
- ○Private Service Connectgcp.network.psc· networkingPlannedSupported: discovery · inventory · cost
- ○Cloud DNSgcp.network.dns· networkingPlannedSupported: discovery · inventory · cost
- ○Cloud Armorgcp.network.cloudarmor· securityPlannedSupported: discovery · inventory · cost
- ○Interconnectgcp.network.interconnect· hybridPlannedSupported: discovery · inventory · cost
- ○Cloud VPNgcp.network.vpn· hybridPlannedSupported: discovery · inventory · cost
- ○Cloud Storagegcp.storage.gcs· storagePlannedSupported: discovery · inventory · cost · recommendationsgcpCloudStoragePublicAccess playbook detects publicly-accessible buckets.
- ○Persistent Diskgcp.storage.disk· storagePlannedSupported: discovery · inventory · cost
- ○Filestoregcp.storage.filestore· storagePlannedSupported: discovery · inventory · cost
- ○Cloud SQLgcp.db.cloudsql· databasePlannedSupported: discovery · inventory · cost · recommendationsgcpCloudSqlPublic playbook detects publicly-accessible instances.
- ○Spannergcp.db.spanner· databasePlannedSupported: discovery · inventory · cost
- ○Firestoregcp.db.firestore· databasePlannedSupported: discovery · inventory · cost
- ○Bigtablegcp.db.bigtable· databasePlannedSupported: discovery · inventory · cost
- ○AlloyDBgcp.db.alloydb· databasePlannedSupported: discovery · inventory · cost
- ○Memorystoregcp.db.memorystore· databasePlannedSupported: discovery · inventory · cost
- ○Cloud IAMgcp.identity.iam· identityPlannedSupported: discovery · inventory · identity · cost
- ○Identity-Aware Proxygcp.identity.iap· identityPlannedSupported: discovery · inventory · cost
- ○Secret Managergcp.identity.secretmanager· securityPlannedSupported: discovery · inventory · cost
- ○Cloud KMSgcp.identity.kms· securityPlannedSupported: discovery · inventory · cost
- ○Cloud Identitygcp.identity.cloudidentity· identityPlannedSupported: discovery · inventory · cost
- ○Security Command Centergcp.security.scc· securityPlannedSupported: discovery · inventory · posture · cost
- ○Binary Authorizationgcp.security.binaryauth· securityPlannedSupported: discovery · inventory · cost
- ○Access Context Managergcp.security.accesscontext· securityPlannedSupported: discovery · inventory · cost
- ○VPC Service Controlsgcp.security.vpcsc· securityPlannedSupported: discovery · inventory · cost
- ○Chroniclegcp.security.chronicle· securityPlannedSupported: discovery · inventory · cost
- ○Cloud Logginggcp.obs.logging· observabilityPlannedSupported: discovery · inventory · observability · cost
- ○Cloud Monitoringgcp.obs.monitoring· observabilityPlannedSupported: discovery · inventory · observability · cost
- ○Cloud Tracegcp.obs.trace· observabilityPlannedSupported: discovery · inventory · cost
- ○Error Reportinggcp.obs.errorrep· observabilityPlannedSupported: discovery · inventory · cost
- ○BigQuerygcp.analytics.bigquery· analyticsPlannedSupported: discovery · inventory · cost
- ○Dataflowgcp.analytics.dataflow· analyticsPlannedSupported: discovery · inventory · cost
- ○Dataprocgcp.analytics.dataproc· analyticsPlannedSupported: discovery · inventory · cost
- ○Pub/Subgcp.integration.pubsub· integrationPlannedSupported: discovery · inventory · cost
- ○Cloud Tasksgcp.integration.cloudtasks· integrationPlannedSupported: discovery · inventory · cost
- ○Workflowsgcp.integration.workflows· integrationPlannedSupported: discovery · inventory · cost
- ○Eventarcgcp.integration.eventarc· integrationPlannedSupported: discovery · inventory · cost
- ○Cloud Endpointsgcp.integration.endpoints· integrationPlannedSupported: discovery · inventory · cost
- ○Organizationgcp.mgmt.org· managementPlannedSupported: discovery · inventory · costgcpOrgHierarchy playbook walks org→folder→project tree.
- ○Foldergcp.mgmt.folder· managementPlannedSupported: discovery · inventory · cost
- ○Projectgcp.mgmt.project· managementPlannedSupported: discovery · inventory · cost
- ○Marketplacegcp.mgmt.marketplace· managementPlannedSupported: discovery · inventory · cost
- ○Podk8s.workload.pod· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○Deploymentk8s.workload.deployment· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○StatefulSetk8s.workload.statefulset· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○DaemonSetk8s.workload.daemonset· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○Jobk8s.workload.job· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○CronJobk8s.workload.cronjob· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○ReplicaSetk8s.workload.rs· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○ConfigMapk8s.config.configmap· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○Secretk8s.config.secret· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○Servicek8s.net.service· networkingPlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○Ingressk8s.net.ingress· networkingPlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○NetworkPolicyk8s.net.netpol· networkingPlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○Endpointsk8s.net.endpoint· networkingPlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○EndpointSlicek8s.net.endpointslice· networkingPlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○Rolek8s.rbac.role· identityPlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○ClusterRolek8s.rbac.clusterrole· identityPlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○RoleBindingk8s.rbac.rb· identityPlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○ClusterRoleBindingk8s.rbac.crb· identityPlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○ServiceAccountk8s.rbac.sa· identityPlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○PodSecurityAdmissionk8s.policy.psp· securityPlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○Namespacek8s.namespace· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○Nodek8s.node· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○PersistentVolumek8s.storage.pv· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○PersistentVolumeClaimk8s.storage.pvc· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○StorageClassk8s.storage.sc· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○HorizontalPodAutoscalerk8s.autoscaling.hpa· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○VerticalPodAutoscalerk8s.autoscaling.vpa· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○CustomResourceDefinitionk8s.crd· computePlannedSupported: discovery · inventory · topology · posture · network · identity · observability
- ○Microsoft Entra IDidentity.entra· identityPlannedSupported: observabilityDiscovery: MS Graph + ARM. Auth: OAuth client credentials + User-Assigned Managed Identity. Reads: Users, groups, app regs, service principals, role assignments, group memberships, sign-in logs.
- ○Microsoft Entra B2Cidentity.entra_b2c· identityPlannedSupported: observabilityDiscovery: Graph. Auth: OAuth. Reads: Custom policies, user flows, tenant config.
- ○Entra Domain Servicesidentity.entra_ds· identityPlannedSupported: observabilityDiscovery: ARM. Auth: OAuth (UAMI). Reads: Domain config, replication state.
- ○Active Directory Federation Services (ADFS)identity.adfs· identityPlannedSupported: observabilityDiscovery: Read Entra federation settings (we infer ADFS presence from external federation config). Auth: n/a — read Entra side only. Reads: Federation trust metadata, claim mappings.
- ○Active Directory (on-prem)identity.active_directory· identityPlannedSupported: observabilityDiscovery: Azure AD Connect sync state via Entra; on-prem LDAP optional via agent. Auth: Read sync state from Entra; on-prem agent for direct read. Reads: Hybrid join state, sync errors, stale objects (via Entra sync metrics).
- ○LDAP / OpenLDAPidentity.ldap· identityPlannedSupported: observabilityDiscovery: LDAP bind (on-prem connector or jump host). Auth: Bind DN + service-account password. Reads: OU tree, user/group attributes.
- ○Oktaidentity.okta· identityPlannedSupported: observabilityDiscovery: Okta Management API. Auth: API token (read scopes: users:read, groups:read, apps:read, logs:read). Reads: Users, groups, apps, role assignments, MFA enrollments, system log, policies.
- ○Ping Identityidentity.ping· identityPlannedSupported: observabilityDiscovery: PingOne API. Auth: OAuth client credentials. Reads: Users, populations, applications, role assignments, MFA.
- ○OneLoginidentity.onelogin· identityPlannedSupported: observabilityDiscovery: OneLogin API. Auth: API credentials. Reads: Users, apps, roles, sign-in events.
- ○ForgeRock Identity Cloudidentity.forgerock· identityPlannedSupported: observabilityDiscovery: AM/IDM REST. Auth: Service account / OAuth client credentials. Reads: Users, identities, journeys, federation config.
- ○Auth0 (Okta)identity.auth0· identityPlannedSupported: observabilityDiscovery: Management API. Auth: M2M token (audience: management API). Reads: Users, applications, connections, rules/actions, logs.
- ○JumpCloudidentity.jumpcloud· identityPlannedSupported: observabilityDiscovery: JumpCloud API. Auth: API key (read scopes). Reads: Users, systems, system bindings, SSO apps, MFA enrollment.
- ○Google Cloud Identityidentity.gcp_identity· identityPlannedSupported: observabilityDiscovery: Google Admin SDK Directory API. Auth: OAuth (workforce identity federation preferred). Reads: Users, groups, OUs, role assignments, sign-in events.
- ○Amazon Cognitoidentity.cognito· identityPlannedSupported: observabilityDiscovery: AWS SDK (Cognito IDP). Auth: Cross-account IAM role (read-only). Reads: User pools, app clients, identity providers, federation config.
- ○SailPoint IdentityNowidentity.sailpoint· identityPlannedSupported: observabilityDiscovery: IdentityNow API. Auth: OAuth client credentials (read scopes). Reads: Identities, entitlements, access reviews, certifications, sources.
- ○Saviynt Identity Cloudidentity.saviynt· identityPlannedSupported: observabilityDiscovery: Saviynt REST. Auth: Service account. Reads: Users, accounts, entitlements, requests, certifications.
- ○CyberArkidentity.cyberark· identityPlannedSupported: observabilityDiscovery: Conjur API + EPM API + Privilege Cloud API. Auth: API authentication. Reads: Safes, accounts, applications, privileged session audit.
- ○Delinea (Thycotic + Centrify)identity.delinea· identityPlannedSupported: observabilityDiscovery: Secret Server REST + Privilege Manager API. Auth: API key + service account. Reads: Secret templates, folders, permissions, audit logs.
- ○Duo Security (Cisco)identity.duo· identityPlannedSupported: observabilityDiscovery: Duo Admin API. Auth: hostkey + skey + IKey (read). Reads: Users, integrations, authentication logs, enrollment status, policies.
- ○RSA SecurIDidentity.rsa_securid· identityPlannedSupported: observabilityDiscovery: SecurID Cloud Authentication API. Auth: service account. Reads: Users, tokens, authentication policies, sign-in events.
- ○Keycloakidentity.keycloak· identityPlannedSupported: observabilityDiscovery: Keycloak Admin REST API. Auth: OIDC client_credentials. Reads: Realms, users, groups, clients, role mappings, identity providers.
- ✕ExpressRoute (Azure)hybrid.azure.expressroute· hybridNot in scopeSupported: discovery · inventory · topology · networkAzure side discovered via Resource Graph; hybridConnectivity playbook validates the chain. On-prem peer + carrier device not visible.
- ✕VPN Gateway (Azure)hybrid.azure.vpngateway· hybridNot in scopeSupported: discovery · inventory · topology · networkAzure side discovered. On-prem peer requires CMDB or agent.
- ✕Direct Connect (AWS)hybrid.aws.directconnect· hybridNot in scopeSupported: discovery · inventory · topology · networkAWS side enumerable via aiobotocore. On-prem peer not visible.
- ✕Site-to-Site VPN (AWS)hybrid.aws.sitevpn· hybridNot in scopeSupported: discovery · inventory · topology · networkTunnel state visible AWS-side.
- ✕Cloud Interconnect (GCP)hybrid.gcp.interconnect· hybridNot in scopeSupported: discovery · inventory · topology · networkGCP side enumerable via google-cloud-resource-manager.
- ✕Cloud VPN (GCP)hybrid.gcp.cloudvpn· hybridNot in scopeSupported: discovery · inventory · topology · networkGCP side enumerable.
- ✕Hybrid DNS resolutionhybrid.dns.resolver· hybridNot in scopeSupported: discovery · inventory · topology · networkPrivate DNS Zones (Azure/AWS/GCP) plus conditional forwarders. Resolution chain validated end-to-end by privateEndpointImpact playbook for Azure only.
- ✕Identity federationhybrid.identity.federation· hybridNot in scopeSupported: discovery · inventory · topology · networkEntra ↔ ADFS / Entra ↔ Okta / Entra ↔ Ping. Discovery requires reading Entra federation settings + the peer IdP via its API.
- ✕ServiceNow CMDBhybrid.cmdb.servicenow· hybridNot in scopeSupported: discovery · inventory · topology · networkBusiness services from cmdb_ci_service ingested. Reconciliation against live cloud inventory is roadmap.
- ✕Webhook integration bridgehybrid.webhook.bridge· hybridNot in scopeSupported: discovery · inventory · topology · networkOutbound webhooks fire on recommendation status changes. Inbound webhooks (receiving from external systems) are roadmap.
Read-only and advisory by design — we never modify cloud resources. The grades describe what we can observe, not what we can change.