Skip to content

lookout audit cluster

Cluster-level security configuration posture, read from the cloud provider: Workload Identity off cluster-wide or bypassed by a node pool, node pools still serving the legacy metadata endpoints, and a control-plane endpoint the internet can reach with nothing narrowing it. Reads the provider’s cluster record, not Kubernetes objects, so it takes no —namespace/-A/—workload; scanned counts the cluster plus its node pools. Without a provider capability it reports an explicit unavailable rather than silence.

MCP tool: k8s_audit_cluster (MCP profile: audit)

Terminal window
lookout audit cluster [flags]
FlagTypeDefaultMeaning
--namespacestring—limit the scan to one namespace
-Abool—scan all namespaces
--workloadstring—target one workload as <Kind>/<namespace>/<name>, e.g. Deployment/prod/api
--sinceduration—how far back to look (0 = command default)
--formatstringlogfmtoutput format: logfmt|json (one record per line either way)
--timeoutduration10sabort the invocation after this long (exit 1)
--kubeconfigstring—path to a kubeconfig file, instead of $KUBECONFIG / ~/.kube/config
--contextstring—kubeconfig context to read, instead of its current-context. Selects a cluster for THIS invocation only — nothing is written back — so concurrent invocations can target different clusters. Reported as context=<name> in the summary line
--exemptionsstring—path to a git-reviewed exemption file (YAML); covered findings are ANNOTATED with their reason and expiry and counted as exempt=<n> in the summary, never dropped

Every kind= this command can emit, and the severities it carries them at. Nothing else appears in its output; a kind absent from a run means the check looked and found nothing. See the finding-kind glossary for the whole vocabulary.

KindSeverityClaim
audit.workload_identity_offwarningWorkload Identity is off cluster-wide, or a node pool bypasses it — pods authenticate to the cloud as the node
audit.legacy_metadatawarninga node pool still serves the pre-v1 instance-metadata endpoints, which any pod can read
audit.public_control_planewarning, infothe control-plane endpoint is reachable from the internet; info when authorized networks narrow it
cloud.unavailableinfothe cloud capability this check needs is unavailable, so nothing was examined — an explicit degradation record, never silence

Beyond the shared envelope fields (kind, severity, namespace, kind_of_object, name, reason, message, fingerprint, exempt_reason, exempt_expires):

FieldMeaning
clusteron a node-pool finding: the cluster the pool belongs to, so the record stands alone
workload_poolthe cluster-wide workload identity pool that this node pool’s pods bypass
metadata_modehow the node pool exposes instance metadata to pods: node-identity means any pod can mint tokens for the node’s service account
disable_legacy_endpointsthe pool’s legacy-metadata setting as the provider records it: enabled when someone turned the pre-v1 endpoints back on, unset when the pool was never configured either way
node_poolssummary note: node pools examined — the cluster itself is the other unit scanned counts
endpointthe control plane’s internet-facing address
authorized_networkshow many source ranges the allow-list permits
authorized_network_cidrsthose ranges, sorted as the provider returned them and capped at 8 with a +N more tail
gcp_public_cidrswhether the provider’s own public ranges are admitted in addition to the allow-list
capabilitycloud.unavailable: the provider capability this command needed (cluster-config)
providercloud.unavailable: the provider that was asked
unavailablesummary-line note: why the cloud read could not be served

Output: one finding per line (logfmt; —format=json for one JSON object per line), keys in fixed order; healthy resources emit nothing. The final line is always the summary: scanned= findings= elapsed= — findings=0 with a summary present means “scanned and healthy”; a stream without a summary line is void. Exit 0 data, 1 runtime error (diagnostics on stderr only), 2 usage.

Terminal window
lookout audit cluster
lookout audit cluster --format=json
lookout audit cluster --exemptions=exemptions.yaml