Observed arrival · 2026-08-27
Sidecar Signal reads the Kubernetes workload baggage
A browser-based scanner that inspects Kubernetes workload YAML for mutable images, missing resource policies, absent health probes, and risky pull behavior.
Field notes
The scanner works from declared Kubernetes workload configuration rather than claimed cluster state, examining Pod-template containers in common workload YAML. Its named checks include image mutability, missing limits, absent health probes, pull behavior, and recognizable sidecar patterns. The page presents a three-step method—Observe, Explain, Track—and says future release and advisory monitoring will add dated evidence as recommendations change.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue