Synopsis
Reads the pods of every GKE cluster in a Google Cloud project, folder or organization from Cloud Asset Inventory, so it needs no kubeconfig, no Kubernetes RBAC and no network access to any cluster control plane. The reported data matches
kosli snapshot k8s: container image digests,
creation timestamps and owners of the Running and Failed pods.
GCP authentication uses Application Default Credentials. On a developer machine, run
gcloud auth application-default login; in GCE/GKE/Cloud Run the metadata server / Workload
Identity is used automatically. The Cloud Asset API (cloudasset.googleapis.com) must be enabled
in the quota project of the caller’s credentials.
The caller needs cloudasset.assets.listContainerPod and serviceusage.services.use on the
project, folder or organization. Grant them through a custom role for least privilege:
roles/cloudasset.viewer also works, but it can list every asset type, including k8s.io/Secret.
Asset Inventory is eventually consistent, so a snapshot can lag behind recent pod changes.
Skip --clusters, --clusters-regex and --locations to report the pods of every cluster in
scope, and skip the namespace flags to report every namespace. Filters are case-sensitive.
With --folder or --organization, --clusters and --clusters-regex match cluster names in
every project under the scope.
The snapshot captures every pod that matches the filters, across all selected clusters, and
reports them to one environment. With no cluster or location filter, that is every GKE cluster
in the scope. The report does not record which cluster a pod runs in, so pods with the same
namespace and name in two clusters (e.g. StatefulSet pods such as web-0) cannot be told apart
by name. To keep clusters apart, snapshot each one with --clusters to its own environment.
Flags
Flags inherited from parent commands
Examples Use Cases
These examples all assume that the flags--api-token, --org, --host, (and --flow, --trail when required), are set/provided.
report the pods of every GKE cluster in a project
report the pods of every GKE cluster in a project
report the pods of every GKE cluster in all projects under a folder
report the pods of every GKE cluster in all projects under a folder
report the pods of one cluster to its own environment, excluding system namespaces
report the pods of one cluster to its own environment, excluding system namespaces