Description

SPIRE Agent Helm chart for AppMesh mTLS support on Kubernetes

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
spire-agentdefault31Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 spire-agent

Namespace: default  |  Automount:

🔑 Permissions (3)

RoleResourceVerbsRiskTags
ClusterRole spire-agent-rolecore/nodes/proxygetCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole spire-agent-rolecore/nodesgetLow
ClusterRole spire-agent-rolecore/podsgetLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
DaemonSetspire-agentappmesh-spire-agentgcr.io/spiffe-io/spire-agent:1.5.0