Skip to main content
This is a beta feature. Beta features provide early access to product functionality. These features may change between releases without warning, or can be removed in a future release. Please contact us to enable this feature for your organization.

Synopsis

Report a snapshot of running pods in GKE clusters to Kosli, read from Cloud Asset Inventory.
Reads the pods of every GKE cluster in a Google Cloud project, folder or organization from Cloud Asset Inventory, so it needs no kubeconfig, no Kubernetes RBAC and no network access to any cluster control plane. The reported data matches kosli snapshot k8s: container image digests, creation timestamps and owners of the Running and Failed pods.
GCP authentication uses Application Default Credentials. On a developer machine, run gcloud auth application-default login; in GCE/GKE/Cloud Run the metadata server / Workload Identity is used automatically. The Cloud Asset API (cloudasset.googleapis.com) must be enabled in the quota project of the caller’s credentials. The caller needs cloudasset.assets.listContainerPod and serviceusage.services.use on the project, folder or organization. Grant them through a custom role for least privilege: roles/cloudasset.viewer also works, but it can list every asset type, including k8s.io/Secret. Asset Inventory is eventually consistent, so a snapshot can lag behind recent pod changes. Skip --clusters, --clusters-regex and --locations to report the pods of every cluster in scope, and skip the namespace flags to report every namespace. Filters are case-sensitive. With --folder or --organization, --clusters and --clusters-regex match cluster names in every project under the scope. The snapshot captures every pod that matches the filters, across all selected clusters, and reports them to one environment. With no cluster or location filter, that is every GKE cluster in the scope. The report does not record which cluster a pod runs in, so pods with the same namespace and name in two clusters (e.g. StatefulSet pods such as web-0) cannot be told apart by name. To keep clusters apart, snapshot each one with --clusters to its own environment.

Flags

Flags inherited from parent commands

Examples Use Cases

These examples all assume that the flags --api-token, --org, --host, (and --flow, --trail when required), are set/provided.
Last modified on October 2, 2026