Run a scan
Scan status
Bulk scan — entire organisation
Results
| Severity | Title | Resource | Check | Recommendation |
|---|
Welcome
Select a target above and click Run scan for an on-demand check, or open the Misconfigurations tab to see the most recent scheduled results across every configured account.
| Severity | Account | Title | Resource | Check | Recommendation | User Review |
|---|
No findings match the current filters.
Asset Inventory
Compute Engine VMs and Cloud SQL instances captured on each scheduled scan. Run an on-demand scan below to refresh now.
On-demand inventory scan
Runs a full scan against an account (or every account in the organisation) and refreshes the inventory below. Results are stored in the local database so the data survives restarts.
| Kind | Project | Name | Region | Zone | Family | Machine | vCPU | Memory | Disk | Status |
|---|
No assets yet. Run a scan (or wait for the next scheduled cycle) to populate the inventory.
| Name | Project | Region | Storage class | Public | UBLA | Versioning |
|---|
No GCS buckets in the inventory yet. Run a scan to populate it.
| Name | Project | Location | Version | Nodes | Endpoint | Release | Network | Status |
|---|
No GKE clusters in the inventory yet. Run a scan to populate it.
Asset Report
Compute, storage and Kubernetes footprint across the organisation.
Compute & Databases
VMs and Cloud SQL instances within the selected scope.
Compute by account
| Account | Assets | VMs | DBs | vCPU | Memory (GB) | Disk (GB) |
|---|---|---|---|---|---|---|
| Loading… | ||||||
Compute by region
| Region | Assets | VMs | DBs | vCPU | Memory (GB) | Disk (GB) |
|---|---|---|---|---|---|---|
| Loading… | ||||||
Compute by family
| Family | Kind | Count | vCPU | Memory (GB) | Disk (GB) |
|---|---|---|---|---|---|
| Loading… | |||||
By status
Compute by region × family
| Region | Family | Kind | Servers | vCPU | Memory (GB) | Disk (GB) |
|---|---|---|---|---|---|---|
| Loading… | ||||||
Cloud Storage (GCS)
Bucket inventory and security posture across the selected scope. Public / UBLA / versioning rely on the most recent full scan with IAM enabled.
Buckets by account
| Account | Buckets |
|---|---|
| Loading… | |
Buckets by location
| Location | Buckets |
|---|---|
| Loading… | |
Buckets by storage class
| Storage class | Buckets |
|---|---|
| Loading… | |
Kubernetes (GKE)
Cluster inventory across the selected scope. Node counts sum
the currentNodeCount of each cluster's node pools
(Autopilot uses the cluster-level count).
Clusters by account
| Account | Clusters | Nodes |
|---|---|---|
| Loading… | ||
Clusters by location
| Location | Placement | Clusters | Nodes |
|---|---|---|---|
| Loading… | |||
Clusters by version
| Version | Clusters | Nodes |
|---|---|---|
| Loading… | ||
Clusters by release channel
| Channel | Clusters | Nodes |
|---|---|---|
| Loading… | ||
Committed Use Discount analysis
Maps active CUDs against the running Compute & Cloud SQL inventory captured by the latest scans.
Per-commitment utilisation
One row per (account, region, family). Multiple overlapping CUDs are summed; hover the Expires cell to see the individual subscriptions.
| Account | Region | Family | Committed vCPU | Used vCPU | CPU util % | Committed GB | Used GB | Mem util % | VMs | Expires |
|---|---|---|---|---|---|---|---|---|---|---|
| Loading… | ||||||||||
By account
| Account | Committed vCPU | Used vCPU | CPU util % | Committed GB | Used GB | Mem util % |
|---|---|---|---|---|---|---|
| Loading… | ||||||
By region
| Region | Committed vCPU | Used vCPU | CPU util % | Committed GB | Used GB | Mem util % |
|---|---|---|---|---|---|---|
| Loading… | ||||||
By family
| Family | Committed vCPU | Used vCPU | CPU util % | Committed GB | Used GB | Mem util % |
|---|---|---|---|---|---|---|
| Loading… | ||||||
Running usage with no CUD coverage
Live VMs in (account, region, family) combinations where no resource-based CUD exists — these run at on-demand rates.
| Account | Region | Family | Used vCPU | Used GB | VMs |
|---|---|---|---|---|---|
| Loading… | |||||
Cloud SQL CUDs are spend-based at the BillingAccount level, so they can't be mapped one-to-one to running instances. The commitments table shows what's been pre-paid, and the inventory tables show what's running against it.
Active Cloud SQL commitments
| Billing container | Region | $/hour | Term | Starts | Expires |
|---|---|---|---|---|---|
| Loading… | |||||
Running Cloud SQL by region
| Region | Instances | vCPU | Memory (GB) |
|---|---|---|---|
| Loading… | |||
Running Cloud SQL by account
| Account | Instances | vCPU | Memory (GB) |
|---|---|---|---|
| Loading… | |||
Memorystore for Redis CUDs are spend-based at the BillingAccount level. The scanner does not currently inventory Memorystore instances, so only the commitment list is shown.
| Billing container | Region | $/hour | Term | Starts | Expires |
|---|---|---|---|---|---|
| Loading… | |||||
Next 3 commitments to expire
All active commitments by expiry
Active CUDs only, sorted by status (expired → soon → ok) then by soonest end-date. Rows past expiry are highlighted in red.
| Status | Type | Account | Region | Family | Committed | Term | Starts | Expires | Days left |
|---|---|---|---|---|---|---|---|---|---|
| Loading… | |||||||||
Kubernetes pod usage
Per-pod assigned vs. average CPU/memory over the selected
window. Reads live from Cloud Monitoring
(kubernetes.io/container/*) — no per-cluster
auth needed.
Node back-fill:
By namespace
| Namespace | Pods | Deployments | Req vCPU | Avg vCPU | Req Mem | Avg Mem |
|---|
By deployment
| Namespace | Deployment | Kind | Pods | Req vCPU | Avg vCPU | Req Mem | Avg Mem |
|---|
Node spread by deployment
Ratio of distinct nodes carrying a workload to its pod count. 1:1 means every pod sits on its own node (best for high-availability); 1:N means N replicas crammed onto a single node (a single node outage takes the whole deployment down). Node type / vCPU / Memory describe the machine-type spec of each node the workload runs on (per-node, not summed). When a deployment lands on more than one machine type the dominant one is shown with a hint about additional types.
| Namespace | Deployment | Kind | Pods | Nodes | Node : Pod | Node type | vCPU | Memory | Nodes used |
|---|
Pods
| Namespace | Pod | Deployment | Node | Containers | Req vCPU | Avg vCPU | CPU util % | Req Mem | Avg Mem | Mem util % |
|---|