Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.

Lifecycle Watch

The Lifecycle Watch page spotlights pods, PVCs, and buckets that were deleted, were short-lived (ephemeral), or were recreated across your Kubernetes clusters. Resources that vanish, live only briefly, or churn repeatedly can indicate attacker cleanup, data loss, reconnaissance, data exfiltration, or crash-loops. The page surfaces them so you can investigate before the evidence ages out.

Where: Data Security Posture > K8 inventory · lifecycle security

The data is derived from the K8 inventory snapshots, so detection granularity is bounded by how often scans run and by the Snapshot Frequency setting. For a deeper explanation of each signal, see Ephemeral and Deleted Resources and Inventory Security Surface.

Page layout​

The page is a single scrolling console with these areas, top to bottom:

  • Header — the page title, a summary of the active window and ephemeral threshold, and the time of the last scan. A K8 Data Security link returns to the topology, Refresh re-runs the scan, and the Observatory radar shows one disc per registered cluster.
  • Range and scope row — the time-range selector, the ephemeral-threshold input, and the cluster scope chips.
  • Threat tiles — headline counts for Deleted, Ephemeral, and Recreated.
  • Security surface — three section cards (Deleted resources, Ephemeral resources, Recreated / churned), each with a resource-type filter and a table.
  • Secondary panels — Snapshot Timeline and Pod Lifecycle Search, both collapsed by default.

Time range and ephemeral threshold​

ControlDescription
RangePresets of Last 24h, Last 48h, Last 7d, and Last 30d. The range drives the whole security surface and re-runs the scan when changed. It also defines "deleted": a resource that existed within the window but stopped appearing is treated as deleted.
Ephemeral ≤ N minLifespan threshold, from 1 to 1440 minutes (default 120). Any pod or PVC whose total lifespan is below this value is classed as ephemeral. Raising it widens the net, and lowering it focuses on the most fleeting resources. Changing it re-runs the scan.

Cluster scope​

The Observatory radar and the scope chips let you choose All Clusters or a single registered cluster. Each chip shows the cluster's pod and node counts.

Snapshots are stored fleet-wide. Selecting a single cluster tags the page summary and the radar, but the lifecycle tables remain fleet-wide. A note appears below the security surface when a single cluster is selected.

Threat tiles​

TileCounts
DeletedPods, PVCs, and buckets that vanished from inventory within the window
EphemeralPods and PVCs whose lifespan was at or below the ephemeral threshold
RecreatedPods that were destroyed and re-spawned under a new UID (same name and owner, new incarnation)

A tile is highlighted when its count is above zero.

Security surface​

Three cards present the detail behind the tiles. Each card has a resource-type filter (Pods, PVCs, Buckets) with a live count per type. Switching the filter swaps the table.

  • Deleted resources — resources that existed in the window but stopped appearing, which means they were destroyed. This can indicate attacker cleanup or data loss. The table shows the namespace (or device, for buckets), resource name, first-seen and last-seen timestamps, and lifespan. When the deletion is attributable to a user, a ✕ user badge appears next to the name.
  • Ephemeral resources — pods and PVCs that lived under the threshold before being destroyed, a possible reconnaissance or exfiltration signal. The columns match the Deleted card, with short-lived rows highlighted.
  • Recreated / churned — pods that were destroyed and re-spawned under a new UID because of a redeploy, crash-loop, or re-spawn. Instead of a lifespan, this card shows an incarnations count such as 4×, the number of times the same workload name reappeared with a new UID.

Each card shows an empty-state message, such as "No deleted pods in the last 24h", when nothing matches, and a spinner while the report loads. If the query fails, an error message appears above the security surface.

Snapshot Timeline​

Expand this panel to see the point-in-time inventory snapshots, most recent first. Snapshots are captured after each K8 scan job completes. Each row shows the snapshot timestamp, its age, the pod, PVC, and node counts, and the capture duration. The newest snapshot carries a latest badge.

  • Click a snapshot row to expand it and see the pods (namespace, pod, node, status) and PVCs (namespace, PVC, storage class, capacity) captured at that moment.
  • Pin two snapshots with the pin button on each row to open the Snapshot diff drawer. The diff lists the pods and PVCs added and removed between the two snapshots. Use clear pins to reset, or press Esc to close the drawer.

For details, see Inventory - Snapshot Timeline and Snapshot Diff.

Expand this panel to look up the first-seen and last-seen history of specific pods.

  • Namespace — restricts the search to one namespace. Leave it blank for all namespaces.
  • Pod name contains — matches a substring of the pod name.

Click Search, or press Enter in either field. The results list each matching pod with its namespace, node, first-seen, last-seen, and total duration. Pods with a lifespan below the ephemeral threshold are highlighted and carry an ephemeral badge.

The page accepts a ?tab= URL parameter that scrolls the security surface into view and opens a secondary panel:

  • tab=snapshots or tab=diff opens the Snapshot Timeline.
  • tab=lifecycle opens Pod Lifecycle Search.

Workflows​

Investigate resources that disappeared overnight​

  1. Set Range to Last 24h, or the window of interest.
  2. Read the Deleted tile, then open the Deleted resources card.
  3. Switch the resource-type filter between Pods, PVCs, and Buckets to review each type.
  4. Look for a ✕ user badge to see who deleted a resource, and check the last-seen time to pin down when.

Hunt for short-lived pods​

  1. Set Ephemeral ≤ to the lifespan you consider suspicious, for example 15 minutes.
  2. Read the Ephemeral tile and open the Ephemeral resources card.
  3. To confirm a suspect workload, open Pod Lifecycle Search, enter its name, and check the durations and ephemeral badges.

Compare the cluster at two points in time​

  1. Expand Snapshot Timeline.
  2. Click pin on two snapshots, one earlier and one later.
  3. Review the Snapshot diff drawer to see which pods and PVCs were added or removed between them.

Tips​

  • Detection is only as fine-grained as the scan cadence. A pod that appeared and vanished entirely between two scans is not captured. Increase scan frequency if you need tighter resolution.
  • Snapshot history is bounded by the configured data retention. The timeline cannot reach further back than the oldest stored snapshot.
  • If all sections are empty and the Snapshot Timeline shows No snapshots yet, no K8 scan has completed. Run a scan from the Jobs page first.
  • A recreated count of 4× for a single pod name is normal for a frequently redeployed or crash-looping workload. Investigate when it appears for a workload you expect to be stable.