Description

A Helm chart to deploy aws-cloudwatch-metrics project

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
aws-cloudwatch-metricsdefault131Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 aws-cloudwatch-metrics

Namespace: default  |  Automount:

🔑 Permissions (13)

RoleResourceVerbsRiskTags
ClusterRole aws-cloudwatch-metricscore/nodes/proxygetCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole aws-cloudwatch-metricscore/configmapscreateLow
ClusterRole aws-cloudwatch-metricsapps/daemonsetslist · watchLow
ClusterRole aws-cloudwatch-metricsapps/deploymentslist · watchLow
ClusterRole aws-cloudwatch-metricscore/endpointslist · watchLow
ClusterRole aws-cloudwatch-metricscore/eventscreateLow
ClusterRole aws-cloudwatch-metricsbatch/jobslist · watchLow
ClusterRole aws-cloudwatch-metricscore/nodeslist · watchLow
ClusterRole aws-cloudwatch-metricscore/nodes/statscreateLow
ClusterRole aws-cloudwatch-metricscore/podslist · watchLow
ClusterRole aws-cloudwatch-metricsapps/replicasetslist · watchLow
ClusterRole aws-cloudwatch-metricsapps/statefulsetslist · watchLow
ClusterRole aws-cloudwatch-metricscore/configmaps (restricted to: cwagent-clusterleader)get · updateLowResourceNameRestricted

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
DaemonSetaws-cloudwatch-metricsaws-cloudwatch-metricsamazon/cloudwatch-agent:1.300032.2b361