Works everywhere
The Kubernetes provider only ever talks to the cluster's own API server over a bearer token — there's no cloud-specific assumption anywhere in it. On-premises, air-gapped, or any managed Kubernetes offering all work the same way.
What's collected
Nodes, namespaces, Pods, Deployments, StatefulSets, DaemonSets, ServiceAccounts, and ClusterRoleBindings — plus Prometheus metrics and OpenCost namespace cost allocation, both optional and gracefully skipped if not installed.
Security & reliability rules
Privileged or root containers, host namespace sharing, dangerous capabilities, missing liveness/readiness probes, and single-replica production workloads. System namespaces (kube-system, etc.) are inventoried but never rule-evaluated.