Snapshot Diff
The Snapshot Diff drawer compares two K8 inventory snapshots and shows which pods and PVCs appeared or disappeared between them. Use it for change-management review, incident timelines, and confirming that an expected deploy or teardown took effect across the fleet.
Where: Data Security Posture > K8 inventory · lifecycle security > Snapshot Timeline
Overview
Each row in the Snapshot Timeline panel on the Lifecycle Watch page is a point-in-time inventory capture taken after a K8 scan completes. When you select two snapshots, the diff compares the pods and PVCs present in each and classifies every entity as added or removed. The result opens in a drawer pinned to the bottom of the screen.
Pin two snapshots
Each snapshot row in the timeline has a Pin button. Pin two snapshots to choose the pair to compare:
- The first snapshot you pin becomes A, the baseline.
- The second snapshot you pin becomes B, the comparison point.
- Pinning a third snapshot replaces B and keeps A fixed.
- Clicking a pinned snapshot's button again unpins it.
When both A and B are pinned, the diff runs automatically and the drawer opens. In the drawer header, Clear pins resets the selection. Close (or Esc) hides the drawer without clearing the pins.
Diff categories
The drawer shows four columns. The count beside each column title is the number of rows in that category, and an empty column shows — none —.
| Column | Contents | Row details |
|---|---|---|
| Added pods | Pods in snapshot B that were not in snapshot A | Namespace, pod name, node |
| Removed pods | Pods in snapshot A that are gone in snapshot B (struck through) | Namespace, pod name, node |
| Added PVCs | PersistentVolumeClaims in B but not in A | Namespace, PVC name, capacity |
| Removed PVCs | PVCs in A that are gone in B (struck through) | Namespace, PVC name, capacity |
Workflows
Confirm a deploy added the expected pods
- In the Snapshot Timeline panel, pin the snapshot taken just before the deploy as A.
- Pin the snapshot taken just after the deploy completed as B.
- Review the Added pods column to confirm the expected workload pods, and any new PVCs, appear.
Audit changes during a maintenance window
- Pin the snapshot taken just before the maintenance window started as A.
- Pin the snapshot taken just after the window ended as B.
- Review Added pods and Added PVCs to see what was created, and Removed pods and Removed PVCs to see what was torn down.
Investigate a suspected teardown
- Pin a snapshot from before the suspected event as A and a recent snapshot as B.
- Check the Removed pods and Removed PVCs columns for entities that vanished.
- Cross-reference them in the Deleted resources section of Lifecycle Watch to see who deleted them and when.
Tips
- The diff reflects inventory as seen by the scanner, so its granularity is bounded by scan cadence and the Snapshot Frequency setting. A pod created and destroyed entirely between two snapshots appears in neither and does not show in the diff. Use the Deleted and Ephemeral sections of Lifecycle Watch to catch short-lived churn.
- Snapshots cover the whole fleet. The diff compares the fleet's inventory between the two captures, not a single cluster.
- The diff compares pods and PVCs only. For object-level file events, use the File Activity page.