Description

A Helm chart to deploy aws-for-fluent-bit project

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
aws-for-fluent-bitdefault61Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 aws-for-fluent-bit

Namespace: default  |  Automount:

🔑 Permissions (6)

RoleResourceVerbsRiskTags
ClusterRole aws-for-fluent-bitcore/nodes/proxyget · list · watchCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole aws-for-fluent-bitcore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole aws-for-fluent-bitcore/nodesget · list · watchLow
ClusterRole aws-for-fluent-bitcore/podsget · list · watchLow
ClusterRole aws-for-fluent-bitcore/pods/logsget · list · watchLow
ClusterRole aws-for-fluent-bitpolicy/podsecuritypolicies (restricted to: aws-for-fluent-bit)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (4)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
DaemonSetaws-for-fluent-bitaws-for-fluent-bitpublic.ecr.aws/aws-observability/aws-for-fluent-bit:2.32.2.20240516