Skip to content

#62 · New Kubernetes Integration: Discover APIs in Kubernetes

As organizations scale their Kubernetes deployments, the number of services and APIs grows rapidly. Maintaining visibility into these resources is critical for securing the API attack surface and ensuring compliance.

Escape now supports Kubernetes integration, enabling users to discover services running in their Kubernetes clusters.

This integration simplifies the process of discovering undocumented and shadow APIs within your clusters, reducing operational risks and improving governance.

How it works?

Escape will read the services and ingresses defined in your cluster, determine if they are APIs, and will make them visible in the Escape Inventory.

Getting started

Step 1: Set Up a Private Location

You need to configure a Private Location as a Kubernetes deployment for Escape to interact with your cluster.

Step 2: Create Service Account and ClusterRoleBinding

To allow this deployment to access resources in your Kubernetes cluster, you need to create a Service Account and a ClusterRoleBinding.

You can use the sample YAML from the Escape documentation to create these authorizations (replace default with the right namespace if needed).

Step 3: Bind the Service Account

Add the following line to the spec section of your deployment YAML to bind the Service Account to the pod: serviceAccountName: escape-repeater

Step 4: Monitor Discovered APIs

Once the integration is enabled, Escape will automatically identify and display APIs in the All Services section of your inventory, allowing you to take further actions like securing, auditing, or analyzing them.

Not sure if your Kubernetes clusters have APIs? Now's the perfect time to find out! Integrate your Kubernetes with Escape and enrich your API inventory.