Containers in the asset inventory: the platform counts, not the pod
A pod often lives for minutes. Whoever inventories every single one produces noise; whoever leaves the container layer out entirely has a blind spot exactly where production runs. Why the right question is not whether but at which level, and what belongs in the inventory for good.
Containers have reframed the inventory problem. A pod is created, does its work and disappears, sometimes within minutes. Whoever tries to record every single one as an IT system produces noise instead of oversight. Whoever leaves the container layer out entirely has a blind spot exactly where production runs these days. Both are common, and both are wrong.
The question is not whether but at which level
A useful inventory distinguishes between what stays and what comes and goes. The platform is durable: the Kubernetes cluster, its nodes, the Docker hosts. They carry owners, patch levels and risks, they belong in the inventory as assets. Pods are short-lived: they are execution, not stock. Whoever inventories them individually documents a state that is already gone by the time it is read.
The middle: images and workloads
Between platform and pod sits the level that carries the most security weight: which container images actually run, and which workloads are permanently in use? The image carries the vulnerabilities, the workload carries the responsibility. This level belongs in a lightweight inventory, visible and assessable, without turning every pod into an object.
By hand this cannot be kept up
Clusters change with every deployment, nodes join under load, images are rebuilt several times a week. A hand-maintained list goes stale faster here than any other documentation in the house. The only sustainable way is to ask the platform itself and take the result into the inventory automatically, at exactly the granularity described above.
How isidaten does it
The isidaten agent detects Kubernetes clusters and Docker hosts automatically during the scan. Clusters and nodes become assets in the inventory, container images and running workloads are kept by the container inventory as a lightweight layer, and short-lived pods are deliberately not inflated into IT systems. The inventory stays readable, and the container layer is visible nonetheless, connected to vulnerability and compliance processes.
If you want to know how your container platform gets into the asset inventory without flooding it, talk to us.
Questions about this update?
Talk to us – we are happy to show you this feature in a demo.