Exploring Kubernetes Visibility Agent

  • Release version: Zurich
  • Updated March 12, 2026
  • 3 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Exploring Kubernetes Visibility Agent

    The Kubernetes Visibility Agent (KVA) enables ServiceNow customers to gain real-time visibility into both on-premises and cloud-based Kubernetes clusters. It continuously discovers and detects changes in Kubernetes resources, reporting these updates to your ServiceNow instance and maintaining accurate Configuration Management Database (CMDB) records. This ensures your CMDB reflects the current state of your Kubernetes environment.

    Show full answer Show less

    How It Works

    • Deployment: KVA deploys a Kubernetes Deployment resource containing an Informer pod, which connects to the Kubernetes API server to receive resource event updates.
    • Data Reporting: The Informer sends collected data to ServiceNow via the External Communication Channel (ECC) Queue, utilizing the Table API.
    • CMDB Updates: The backend processes these events to update the relevant CMDB tables with the latest Kubernetes resource information.
    • Resilience: If network issues prevent immediate reporting, added resources sync during the next full discovery; removed resources are marked as Absent and deleted after two full cycles.

    Discovery and Monitoring

    • Initial Discovery: The Informer performs a full discovery of all Kubernetes resources and reports them to ServiceNow.
    • Continuous Updates: Every 30 seconds, the Informer sends incremental updates (up to 1 MB) to keep the CMDB current.
    • Scalability: One Informer pod can handle clusters with tens of thousands of pods efficiently.
    • Automatic Restart: Kubernetes automatically restarts the Informer pod if it exits unexpectedly.
    • Resource Cleanup: Deleted resources are marked Absent and removed from the CMDB within hours.

    Auto-Retirement of Inactive Clusters

    KVA supports automatic retirement of inactive Kubernetes clusters to maintain CMDB hygiene. A cluster is considered inactive if its Informer is down and no updates have been recorded for a configurable period (default 60 days). When these conditions are met, the cluster and associated resources are marked accordingly in the CMDB. This feature can be enabled and configured to suit organizational policies.

    Performance and Impact

    • The Informer minimizes load on the Kubernetes API server by fetching the full resource list once and then maintaining synchronization without repeated full pulls.
    • Periodic full discovery cycles resend saved resource lists for consistency without overloading the API server.
    • Performance benchmarks demonstrate KVA’s capability to efficiently handle large-scale Kubernetes environments.

    Practical Benefits for ServiceNow Customers

    • Maintains accurate, up-to-date Kubernetes resource data in the CMDB.
    • Enables proactive management of Kubernetes clusters with visibility into resource changes.
    • Supports hybrid cloud and on-premises Kubernetes deployments seamlessly.
    • Automates lifecycle management of inactive clusters, reducing manual maintenance efforts.
    • Ensures minimal performance impact on Kubernetes infrastructure.

    Kubernetes Visibility Agent enables you to gain visibility into on-premises Kubernetes clusters as well as the various Cloud deployments.

    Kubernetes Visibility Agent detects changes on resources in a Kubernetes cluster. It performs continuous discovery, reports any changes back to your instance, and updates the Configuration Management Database (CMDB) with the latest data. For the latest information on supported cloud deployments, see the Kubernetes Visibility Agent (formerly CNO for Visibility) Support Matrix [KB1700730] article in the Now Support Knowledge Base.

    How it works

    When you deploy Kubernetes Visibility Agent, Kubernetes creates a Deployment resource in the cluster with the latest data. This resource uses a secret stored in Kubernetes to connect to your ServiceNow instance.

    The Kubernetes Visibility Agent Deployment resource contains a pod called Informer, which connects to the Kubernetes API server and receives events on the resources in the cluster from it. The Informer sends the collected data to the instance through the External Communication Channel (ECC) Queue table, using the ServiceNow Table API to read from and write to the queue. The backend part of Kubernetes Visibility Agent (KVA) then updates the appropriate tables in the CMDB.

    Note:
    If the Informer is unable to report the changes, for example due to a network problem, the resources that were added to the cluster during the event are added to the CMDB after the next full discovery cycle. The resources that were removed from the cluster during the event are marked as Absent and deleted after two full discovery cycles.

    For more information about the Kubernetes resources on which the Informer collects data and the CMDB tables it populates, see Data collected by Kubernetes Visibility Agent.

    Initial and periodic discovery

    In its initial discovery, the Informer finds all the resources in the Kubernetes cluster and reports them to your instance. Every 30 seconds, the Informer sends up to 1 MB of data to the instance. It typically takes up to two minutes to report data on a cluster containing 1,000 pods and another minute for every additional 1,000 pods. A single Informer pod can handle a cluster with tens of thousands of pods. If the Informer exits for any reason, Kubernetes restarts it automatically.

    After the initial discovery, the Informer continuously monitors the addition, updating, and deletion of resources in the cluster. Resources that were deleted from the cluster are marked with install_status=Absent and deleted from the CMDB within hours in a regular cleanup.

    During each full discovery cycle, the system can optionally check for inactive clusters and automatically update their status. When the auto-retirement feature is enabled, clusters that meet specific conditions are retired. A cluster is considered inactive when its associated Informer is in the Down state and the cluster CI has not been touched for a configured period (default: 60 days). The system determines this based on the sys_updated_on field, which indicates when the cluster was last observed by ServiceNow tools, regardless of whether any field values changed. When these conditions are met, the system updates the install_status field on the Kubernetes cluster CI and all associated CIs (pods, namespaces, deployments, containers, and other resources). For information about configuring auto-retirement, see Enable automatic retirement for inactive Kubernetes cluster CIs. For details about the configuration properties, see Kubernetes cluster auto-retirement properties.

    Impact of the Informer on the Kubernetes API server

    The Informer has minimal impact on the Kubernetes API server. It fetches the complete list of relevant resources only once and saves it to memory. From then on, it synchronizes with the Kubernetes API server and never pulls the complete list again. During the periodic and on-demand full discovery cycles, the Informer resends the saved list of resources to the instance.

    Kubernetes Visibility Agent performance and scalability benchmark

    For Kubernetes Visibility Agent benchmarks, see the Performance results for Kubernetes Visibility Agent [KB1555851] article in the Now Support Knowledge Base.