Skip to content
Spinoza

Features

Cluster insight

The questions that are not about a single object.

128 checks decided against the live cluster, not a parsed manifest. Each rule carries its framework label, its severity and the objects that tripped it.

Spinoza cluster checks: 709 findings across 35 workloads, each rule labelled PSS baseline or NSA/CISA, with a severity and a finding count per rule, and one Configure control for scope, baseline and imports
  • What is broken right now

    A ranked queue of live failures, rather than a list you read looking for red.

  • Cluster overview

    Version, node readiness, allocatable against usage, pods by phase, recent warnings.

  • Live usage in the tables

    CPU and memory from metrics-server, in the list itself.

  • Usage history

    CPU and memory over time, not only the current sample.

  • Best-practice checks

    A scan for the usual security, reliability and waste problems, leading with what it found. Findings from another scanner can be imported alongside.

    128 checks, with baselines, mutes, custom CEL rules and imported scanner findings

  • RBAC visibility

    Who can do what across the cluster, resolved from roles and bindings.

    Admin-only in cluster mode

  • A cluster that stops answering

    Named in a banner with how long it has been quiet and why, rather than reading as healthy.

  • Topology graph

    Resource relationships drawn as a graph.

  • Event timeline

    Events and resource changes on one time axis.

    Resource changes are recorded; Kubernetes events stay separate

  • Service traffic map

    Live traffic between services, read from a mesh or an eBPF source.

    Cilium Hubble flow metrics through Prometheus

  • Upgrade impact

    What a control-plane minor bump would break.

  • MCP server for AI agents

    An agent queries the cluster through the tool.

    A separate binary with 21 tools and 3 resources

Being built

  • Reachability diagnosis
  • Cost
  • Image filesystem browser

In the documentation