Description

Datadog Agent

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
datadogdefault110Critical
datadog-cluster-agentdefault901Critical
datadog-datadog-operatordefault921Critical
datadog-kube-state-metricsdefault311Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 datadog-datadog-operator

Namespace: default  |  Automount:

🔑 Permissions (92)

RoleResourceVerbsRiskTags
ClusterRole datadog-datadog-operatorapiregistration.k8s.io/apiservices*CriticalAPIServiceManipulation ClusterWideAccess DenialOfService InformationDisclosure PrivilegeEscalation (+2 more)
ClusterRole datadog-datadog-operatorrbac.authorization.k8s.io/clusterrolebindingscreate · delete · deletecollection · get · list · patch · update · watchCriticalBindingToPrivilegedRole ClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation (+2 more)
ClusterRole datadog-datadog-operatorrbac.authorization.k8s.io/clusterrolescreate · delete · deletecollection · get · list · patch · update · watchCriticalClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole datadog-datadog-operatorcore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole datadog-datadog-operatorapps/daemonsetscreate · delete · deletecollection · get · list · patch · update · watchCriticalNodeAccess Persistence PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole datadog-datadog-operatorapps/deploymentscreate · delete · deletecollection · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole datadog-datadog-operatorcore/endpointscreate · delete · get · list · patch · update · watchCriticalDenialOfService ManInTheMiddle NetworkManipulation Tampering TrafficRedirection
ClusterRole datadog-datadog-operatorcoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService LeaderElectionAbuse Tampering
ClusterRole datadog-datadog-operatoradmissionregistration.k8s.io/mutatingwebhookconfigurations*CriticalClusterWideAccess DenialOfService InformationDisclosure PrivilegeEscalation Reconnaissance (+4 more)
ClusterRole datadog-datadog-operatornetworking.k8s.io/networkpoliciescreate · delete · get · list · patch · update · watchCriticalDenialOfService LateralMovement NetworkManipulation NetworkPolicyManagement Tampering
ClusterRole datadog-datadog-operatorcore/nodes/proxygetCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole datadog-datadog-operatorcore/podscreate · delete · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole datadog-datadog-operatorcore/secretscreate · delete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure Persistence (+4 more)
ClusterRole datadog-datadog-operatorcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole datadog-datadog-operatoradmissionregistration.k8s.io/validatingwebhookconfigurations*CriticalClusterWideAccess DenialOfService InformationDisclosure Reconnaissance Tampering (+3 more)
ClusterRole datadog-datadog-operatordatadoghq.com/*list · watchHighClusterWideAccess WildcardPermission
ClusterRole datadog-datadog-operatorexternal.metrics.k8s.io/*get · list · watchHighClusterWideAccess WildcardPermission
ClusterRole datadog-datadog-operatorkarpenter.azure.com/*list · watchHighClusterWideAccess WildcardPermission
ClusterRole datadog-datadog-operatorkarpenter.k8s.aws/*get · list · watchHighClusterWideAccess WildcardPermission
ClusterRole datadog-datadog-operatorkarpenter.sh/*create · delete · get · list · patch · update · watchHighClusterWideAccess WildcardPermission
ClusterRole datadog-datadog-operator//scaleget · updateHighClusterWideAccess WildcardPermission
ClusterRole datadog-datadog-operatordatadoghq.com/datadogpodautoscalers*HighClusterWideAccess WildcardPermission
ClusterRole datadog-datadog-operatordatadoghq.com/datadogpodautoscalers/status*HighClusterWideAccess WildcardPermission
ClusterRole datadog-datadog-operatorrbac.authorization.k8s.io/rolebindingscreate · delete · get · list · patch · update · watchHighBindingToPrivilegedRole InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole datadog-datadog-operatorrbac.authorization.k8s.io/rolescreate · delete · get · list · patch · update · watchHighInformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery Reconnaissance
ClusterRole datadog-datadog-operatorcore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole datadog-datadog-operatorcore/componentstatusesget · list · watchMediumControlPlaneDisruption InformationDisclosure Reconnaissance
ClusterRole datadog-datadog-operatorcore/eventscreate · delete · get · list · patch · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole datadog-datadog-operatorpolicy/poddisruptionbudgetscreate · delete · get · list · patch · update · watchMediumAvailabilityImpact DenialOfService Tampering
ClusterRole datadog-datadog-operatorcore/resourcequotasget · list · watchMediumInformationDisclosure QuotaTampering Reconnaissance ResourceConfiguration
ClusterRole datadog-datadog-operatorauthorization.k8s.io/subjectaccessreviewscreate · getMediumInformationDisclosure RBACQuery
ClusterRole datadog-datadog-operatorauthentication.k8s.io/tokenreviewscreate · get · list · watchMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole datadog-datadog-operatorauto.gke.io/allowlistsynchronizerscreate · get · list · watchLow
ClusterRole datadog-datadog-operatorcertificates.k8s.io/certificatesigningrequestsget · list · watchLow
ClusterRole datadog-datadog-operatorcilium.io/ciliumnetworkpoliciescreate · delete · get · list · patch · update · watchLow
ClusterRole datadog-datadog-operatorquota.openshift.io/clusterresourcequotasget · listLow
ClusterRole datadog-datadog-operatorapps/controllerrevisionslist · watchLow
ClusterRole datadog-datadog-operatorbatch/cronjobsget · list · watchLow
ClusterRole datadog-datadog-operatorapiextensions.k8s.io/customresourcedefinitionsget · list · watchLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadogagentinternalscreate · delete · get · list · patch · update · watchLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadogagentinternals/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadogagentinternals/statusget · patch · updateLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadogagentscreate · delete · get · list · patch · update · watchLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadogagents/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadogagents/statusget · patch · updateLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadoggenericresourcescreate · delete · get · list · patch · update · watchLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadoggenericresources/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadoggenericresources/statusget · patch · updateLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadogmetricscreate · delete · get · list · watchLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadogmetrics/statusupdateLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadogmonitorscreate · delete · get · list · patch · update · watchLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadogmonitors/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadogmonitors/statusget · patch · updateLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadogsloscreate · delete · get · list · patch · update · watchLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadogslos/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole datadog-datadog-operatordatadoghq.com/datadogslos/statusget · patch · updateLow
ClusterRole datadog-datadog-operatorcore/deploymentsget · list · watchLow
ClusterRole datadog-datadog-operatordiscovery.k8s.io/endpointsliceslist · watchLow
ClusterRole datadog-datadog-operatorgateway.envoyproxy.io/envoyextensionpoliciescreate · delete · getLow
ClusterRole datadog-datadog-operatornetworking.istio.io/envoyfilterscreate · delete · getLow
ClusterRole datadog-datadog-operatordatadoghq.com/extendeddaemonsetreplicasetsget · list · watchLow
ClusterRole datadog-datadog-operatordatadoghq.com/extendeddaemonsetscreate · delete · get · list · patch · update · watchLow
ClusterRole datadog-datadog-operatorgateway.networking.k8s.io/gatewayclassesget · list · patch · watchLow
ClusterRole datadog-datadog-operatorgateway.networking.k8s.io/gatewaysget · list · patch · watchLow
ClusterRole datadog-datadog-operatorautoscaling/horizontalpodautoscalerslist · watchLow
ClusterRole datadog-datadog-operatorgateway.networking.k8s.io/httproutesget · list · patch · watchLow
ClusterRole datadog-datadog-operatornetworking.k8s.io/ingressesget · list · patch · watchLow
ClusterRole datadog-datadog-operatorbatch/jobsget · list · watchLow
ClusterRole datadog-datadog-operatormetrics.eks.amazonaws.com/kcm/metricsgetLow
ClusterRole datadog-datadog-operatormetrics.eks.amazonaws.com/ksh/metricsgetLow
ClusterRole datadog-datadog-operatorcore/limitrangesget · list · watchLowInformationDisclosure Reconnaissance ResourceConfiguration
ClusterRole datadog-datadog-operatorcore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole datadog-datadog-operatorcore/nodesget · list · watchLow
ClusterRole datadog-datadog-operatorcore/nodes/configzgetLow
ClusterRole datadog-datadog-operatorcore/nodes/healthzgetLow
ClusterRole datadog-datadog-operatorcore/nodes/logsgetLow
ClusterRole datadog-datadog-operatorcore/nodes/metricsgetLow
ClusterRole datadog-datadog-operatorcore/nodes/podsgetLow
ClusterRole datadog-datadog-operatorcore/nodes/specgetLow
ClusterRole datadog-datadog-operatorcore/nodes/statsgetLow
ClusterRole datadog-datadog-operatorcore/persistentvolumeclaimsget · list · watchLow
ClusterRole datadog-datadog-operatorcore/persistentvolumesget · list · watchLow
ClusterRole datadog-datadog-operatorgateway.networking.k8s.io/referencegrantscreate · delete · get · patchLow
ClusterRole datadog-datadog-operatorapps/replicasetsget · list · watchLow
ClusterRole datadog-datadog-operatorcore/replicationcontrollersget · list · watchLow
ClusterRole datadog-datadog-operatorargoproj.io/rolloutslist · patch · watchLow
ClusterRole datadog-datadog-operatorapps/statefulsetsget · list · watchLow
ClusterRole datadog-datadog-operatorstorage.k8s.io/storageclassesget · list · watchLow
ClusterRole datadog-datadog-operatorautoscaling.k8s.io/verticalpodautoscalerslist · watchLow
ClusterRole datadog-datadog-operatorstorage.k8s.io/volumeattachmentsget · list · watchLow
ClusterRole datadog-datadog-operatordatadoghq.com/watermarkpodautoscalersget · list · watchLow
ClusterRole datadog-datadog-operatorsecurity.openshift.io/securitycontextconstraints (restricted to: restricted)useLowResourceNameRestricted

⚠️ Potential Abuse (48)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentdatadog-datadog-operatordatadog-operatorgcr.io/datadoghq/operator:1.22.0

🤖 datadog-cluster-agent

Namespace: default  |  Automount:

🔑 Permissions (90)

RoleResourceVerbsRiskTags
ClusterRole datadog-ksm-corecore/secretslist · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
Role datadog-cluster-agent-maincore/secretscreate · get · list · update · watchCriticalCredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole datadog-cluster-agentdatadoghq.com/*list · watchHighClusterWideAccess WildcardPermission
ClusterRole datadog-cluster-agentkarpenter.azure.com/*list · watchHighClusterWideAccess WildcardPermission
ClusterRole datadog-cluster-agentkarpenter.k8s.aws/*list · watchHighClusterWideAccess WildcardPermission
ClusterRole datadog-cluster-agentkarpenter.sh/*list · watchHighClusterWideAccess WildcardPermission
ClusterRole datadog-ksm-corecore/configmapslist · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole datadog-cluster-agentrbac.authorization.k8s.io/clusterrolebindingsget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole datadog-cluster-agentrbac.authorization.k8s.io/clusterrolesget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole datadog-cluster-agentcore/componentstatusesget · list · watchMediumControlPlaneDisruption InformationDisclosure Reconnaissance
ClusterRole datadog-cluster-agentcore/eventscreate · get · list · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole datadog-ksm-corecore/eventslist · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole datadog-ksm-corecore/resourcequotaslist · watchMediumInformationDisclosure QuotaTampering Reconnaissance ResourceConfiguration
ClusterRole datadog-cluster-agentrbac.authorization.k8s.io/rolebindingsget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole datadog-cluster-agentrbac.authorization.k8s.io/rolesget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole datadog-cluster-agentargoproj.io/applicationsget · list · watchLow
ClusterRole datadog-cluster-agentargoproj.io/applicationsetsget · list · watchLow
ClusterRole datadog-cluster-agentsource.toolkit.fluxcd.io/bucketsget · list · watchLow
ClusterRole datadog-cluster-agentquota.openshift.io/clusterresourcequotasget · listLow
ClusterRole datadog-cluster-agentcore/configmapscreateLow
Role datadog-dca-flarecore/configmapsget · listLow
ClusterRole datadog-ksm-coreapps/controllerrevisionslist · watchLow
ClusterRole datadog-cluster-agentbatch/cronjobsget · list · watchLow
ClusterRole datadog-ksm-corebatch/cronjobslist · watchLow
ClusterRole datadog-cluster-agentapiextensions.k8s.io/customresourcedefinitionsget · list · watchLow
ClusterRole datadog-ksm-coreapiextensions.k8s.io/customresourcedefinitionslist · watchLow
ClusterRole datadog-cluster-agentapps/daemonsetsget · list · watchLow
ClusterRole datadog-ksm-coreapps/daemonsetslist · watchLow
ClusterRole datadog-ksm-coreextensions/daemonsetslist · watchLow
ClusterRole datadog-cluster-agentapps/deploymentsget · list · watchLow
ClusterRole datadog-ksm-coreapps/deploymentslist · watchLow
ClusterRole datadog-ksm-coreextensions/deploymentslist · watchLow
ClusterRole datadog-cluster-agentcore/endpointsget · list · watchLow
ClusterRole datadog-ksm-corecore/endpointslist · watchLow
ClusterRole datadog-cluster-agentdiscovery.k8s.io/endpointslicesget · list · watchLow
ClusterRole datadog-cluster-agentsource.toolkit.fluxcd.io/externalartifactsget · list · watchLow
ClusterRole datadog-cluster-agentsource.toolkit.fluxcd.io/gitrepositoriesget · list · watchLow
ClusterRole datadog-cluster-agentsource.toolkit.fluxcd.io/helmchartsget · list · watchLow
ClusterRole datadog-cluster-agentsource.toolkit.fluxcd.io/helmrepositoriesget · list · watchLow
ClusterRole datadog-cluster-agentautoscaling/horizontalpodautoscalerslist · watchLow
ClusterRole datadog-ksm-coreautoscaling/horizontalpodautoscalerslist · watchLow
ClusterRole datadog-cluster-agentnetworking.k8s.io/ingressesget · list · watchLow
ClusterRole datadog-ksm-corenetworking.k8s.io/ingresseslist · watchLow
ClusterRole datadog-cluster-agentbatch/jobsget · list · watchLow
ClusterRole datadog-ksm-corebatch/jobslist · watchLow
ClusterRole datadog-cluster-agentkustomize.toolkit.fluxcd.io/kustomizationsget · list · watchLow
ClusterRole datadog-cluster-agentcoordination.k8s.io/leasescreateLow
ClusterRole datadog-cluster-agentcore/limitrangesget · list · watchLowInformationDisclosure Reconnaissance ResourceConfiguration
ClusterRole datadog-ksm-corecore/limitrangeslist · watchLowInformationDisclosure Reconnaissance ResourceConfiguration
ClusterRole datadog-cluster-agentadmissionregistration.k8s.io/mutatingwebhookconfigurationscreateLow
ClusterRole datadog-cluster-agentcore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole datadog-ksm-corecore/namespaceslist · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole datadog-cluster-agentnetworking.k8s.io/networkpoliciesget · list · watchLow
ClusterRole datadog-cluster-agentcore/nodesget · list · watchLow
ClusterRole datadog-ksm-corecore/nodeslist · watchLow
ClusterRole datadog-cluster-agentsource.toolkit.fluxcd.io/ocirepositoriesget · list · watchLow
ClusterRole datadog-cluster-agentcore/persistentvolumeclaimsget · list · watchLow
ClusterRole datadog-ksm-corecore/persistentvolumeclaimslist · watchLow
ClusterRole datadog-cluster-agentcore/persistentvolumesget · list · watchLow
ClusterRole datadog-ksm-corecore/persistentvolumeslist · watchLow
ClusterRole datadog-cluster-agentpolicy/poddisruptionbudgetsget · list · watchLow
ClusterRole datadog-ksm-corepolicy/poddisruptionbudgetslist · watchLow
ClusterRole datadog-cluster-agentcore/podsget · list · watchLow
ClusterRole datadog-ksm-corecore/podslist · watchLow
ClusterRole datadog-cluster-agentapps/replicasetsget · list · watchLow
ClusterRole datadog-ksm-coreapps/replicasetslist · watchLow
ClusterRole datadog-ksm-coreextensions/replicasetslist · watchLow
ClusterRole datadog-cluster-agentcore/replicationcontrollersgetLow
ClusterRole datadog-ksm-corecore/replicationcontrollerslist · watchLow
ClusterRole datadog-cluster-agentargoproj.io/rolloutsget · list · watchLow
Role datadog-dca-flarecore/secretsget · listLow
ClusterRole datadog-cluster-agentcore/serviceaccountsget · list · watchLow
ClusterRole datadog-cluster-agentcore/servicesget · list · watchLow
ClusterRole datadog-ksm-corecore/serviceslist · watchLow
ClusterRole datadog-cluster-agentapps/statefulsetsget · list · watchLow
ClusterRole datadog-ksm-coreapps/statefulsetslist · watchLow
ClusterRole datadog-cluster-agentstorage.k8s.io/storageclassesget · list · watchLow
ClusterRole datadog-ksm-corestorage.k8s.io/storageclasseslist · watchLow
ClusterRole datadog-cluster-agentadmissionregistration.k8s.io/validatingwebhookconfigurationscreateLow
ClusterRole datadog-cluster-agentautoscaling.k8s.io/verticalpodautoscalersget · list · watchLow
ClusterRole datadog-ksm-corestorage.k8s.io/volumeattachmentslist · watchLow
ClusterRole datadog-cluster-agentsecurity.openshift.io/securitycontextconstraints (restricted to: datadog-cluster-agent)useLowResourceNameRestricted
ClusterRole datadog-cluster-agentcore/configmaps (restricted to: datadog-cluster-id)create · get · updateLowResourceNameRestricted
ClusterRole datadog-cluster-agentcore/configmaps (restricted to: datadog-leader-election)get · updateLowResourceNameRestricted
ClusterRole datadog-cluster-agentcoordination.k8s.io/leases (restricted to: datadog-leader-election)get · updateLowResourceNameRestricted
ClusterRole datadog-cluster-agentadmissionregistration.k8s.io/mutatingwebhookconfigurations (restricted to: datadog-webhook)delete · get · list · update · watchLowInformationDisclosure Reconnaissance ResourceNameRestricted WebhookReconnaissance
ClusterRole datadog-cluster-agentadmissionregistration.k8s.io/validatingwebhookconfigurations (restricted to: datadog-webhook)delete · get · list · update · watchLowInformationDisclosure Reconnaissance ResourceNameRestricted WebhookReconnaissance
ClusterRole datadog-cluster-agentcore/configmaps (restricted to: datadogtoken)get · updateLowResourceNameRestricted
ClusterRole datadog-cluster-agentsecurity.openshift.io/securitycontextconstraints (restricted to: hostnetwork)useLowResourceNameRestricted
ClusterRole datadog-cluster-agentcore/namespaces (restricted to: kube-system)getLowResourceNameRestricted

⚠️ Potential Abuse (15)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentdatadog-cluster-agentcluster-agentgcr.io/datadoghq/cluster-agent:7.75.0

🤖 datadog-kube-state-metrics

Namespace: default  |  Automount:

🔑 Permissions (31)

RoleResourceVerbsRiskTags
ClusterRole datadog-kube-state-metricscore/secretslist · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole datadog-kube-state-metricscore/configmapslist · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole datadog-kube-state-metricsadmissionregistration.k8s.io/mutatingwebhookconfigurationslist · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole datadog-kube-state-metricscore/resourcequotaslist · watchMediumInformationDisclosure QuotaTampering Reconnaissance ResourceConfiguration
ClusterRole datadog-kube-state-metricsadmissionregistration.k8s.io/validatingwebhookconfigurationslist · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole datadog-kube-state-metricscertificates.k8s.io/certificatesigningrequestslist · watchLow
ClusterRole datadog-kube-state-metricsbatch/cronjobslist · watchLow
ClusterRole datadog-kube-state-metricsapps/daemonsetslist · watchLow
ClusterRole datadog-kube-state-metricsextensions/daemonsetslist · watchLow
ClusterRole datadog-kube-state-metricsapps/deploymentslist · watchLow
ClusterRole datadog-kube-state-metricsextensions/deploymentslist · watchLow
ClusterRole datadog-kube-state-metricscore/endpointslist · watchLow
ClusterRole datadog-kube-state-metricsautoscaling/horizontalpodautoscalerslist · watchLow
ClusterRole datadog-kube-state-metricsextensions/ingresseslist · watchLow
ClusterRole datadog-kube-state-metricsnetworking.k8s.io/ingresseslist · watchLow
ClusterRole datadog-kube-state-metricsbatch/jobslist · watchLow
ClusterRole datadog-kube-state-metricscore/limitrangeslist · watchLowInformationDisclosure Reconnaissance ResourceConfiguration
ClusterRole datadog-kube-state-metricscore/namespaceslist · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole datadog-kube-state-metricsnetworking.k8s.io/networkpolicieslist · watchLow
ClusterRole datadog-kube-state-metricscore/nodeslist · watchLow
ClusterRole datadog-kube-state-metricscore/persistentvolumeclaimslist · watchLow
ClusterRole datadog-kube-state-metricscore/persistentvolumeslist · watchLow
ClusterRole datadog-kube-state-metricspolicy/poddisruptionbudgetslist · watchLow
ClusterRole datadog-kube-state-metricscore/podslist · watchLow
ClusterRole datadog-kube-state-metricsapps/replicasetslist · watchLow
ClusterRole datadog-kube-state-metricsextensions/replicasetslist · watchLow
ClusterRole datadog-kube-state-metricscore/replicationcontrollerslist · watchLow
ClusterRole datadog-kube-state-metricscore/serviceslist · watchLow
ClusterRole datadog-kube-state-metricsapps/statefulsetslist · watchLow
ClusterRole datadog-kube-state-metricsstorage.k8s.io/storageclasseslist · watchLow
ClusterRole datadog-kube-state-metricsstorage.k8s.io/volumeattachmentslist · watchLow

⚠️ Potential Abuse (11)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentdatadog-kube-state-metricskube-state-metricsregistry.k8s.io/kube-state-metrics/kube-state-metrics:v1.9.8

🤖 datadog

Namespace: default  |  Automount:

🔑 Permissions (11)

RoleResourceVerbsRiskTags
ClusterRole datadogcore/nodes/proxygetCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole datadogcore/endpointsgetLow
ClusterRole datadogmetrics.eks.amazonaws.com/kcm/metricsgetLow
ClusterRole datadogmetrics.eks.amazonaws.com/ksh/metricsgetLow
ClusterRole datadogcoordination.k8s.io/leasesgetLow
ClusterRole datadogcore/nodes/metricsgetLow
ClusterRole datadogcore/nodes/specgetLow
ClusterRole datadogcore/nodes/statsgetLow
ClusterRole datadogsecurity.openshift.io/securitycontextconstraints (restricted to: datadog)useLowResourceNameRestricted
ClusterRole datadogsecurity.openshift.io/securitycontextconstraints (restricted to: hostaccess)useLowResourceNameRestricted
ClusterRole datadogsecurity.openshift.io/securitycontextconstraints (restricted to: privileged)useLowResourceNameRestricted

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.