This checks the file you paste. A running cluster contains rather
more than that: workloads deployed by a Helm chart nobody maintains,
a namespace created for a proof of concept two years ago, node pools
sized for a traffic peak that never came back.
It also cannot see what the file does not say. Whether a
NetworkPolicy exists, whether the ServiceAccount this pod uses is
bound to something powerful, whether the image tag you pinned has a
critical CVE, and whether the nodes it lands on are half empty. Those
answers live in the cluster.
Our scanner connects with a read-only ServiceAccount and answers
them, alongside the cost of every node, volume and load balancer
keeping the cluster alive.