Description

Grafana Agent

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
grafana-agentdefault362Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 grafana-agent

Namespace: default  |  Automount:

🔑 Permissions (36)

RoleResourceVerbsRiskTags
ClusterRole grafana-agentcore/nodes/proxyget · list · watchCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole grafana-agentcore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole grafana-agentcore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole grafana-agentcore/pods/logget · list · watchHighClusterWideLogAccess DataExposure InformationDisclosure LogAccess
ClusterRole grafana-agentcore/eventsget · list · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole grafana-agentcore/endpointsget · list · watchLow
ClusterRole grafana-agentdiscovery.k8s.io/endpointsget · list · watchLow
ClusterRole grafana-agentnetworking.k8s.io/endpointsget · list · watchLow
ClusterRole grafana-agentcore/endpointslicesget · list · watchLow
ClusterRole grafana-agentdiscovery.k8s.io/endpointslicesget · list · watchLow
ClusterRole grafana-agentnetworking.k8s.io/endpointslicesget · list · watchLow
ClusterRole grafana-agentcore/ingressesget · list · watchLow
ClusterRole grafana-agentdiscovery.k8s.io/ingressesget · list · watchLow
ClusterRole grafana-agentnetworking.k8s.io/ingressesget · list · watchLow
ClusterRole grafana-agentcore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole grafana-agentcore/nodesget · list · watchLow
ClusterRole grafana-agentdiscovery.k8s.io/nodesget · list · watchLow
ClusterRole grafana-agentnetworking.k8s.io/nodesget · list · watchLow
ClusterRole grafana-agentcore/nodes/metricsget · list · watchLow
ClusterRole grafana-agentdiscovery.k8s.io/nodes/metricsget · list · watchLow
ClusterRole grafana-agentnetworking.k8s.io/nodes/metricsget · list · watchLow
ClusterRole grafana-agentdiscovery.k8s.io/nodes/proxyget · list · watchLow
ClusterRole grafana-agentnetworking.k8s.io/nodes/proxyget · list · watchLow
ClusterRole grafana-agentmonitoring.grafana.com/podlogsget · list · watchLow
ClusterRole grafana-agentmonitoring.coreos.com/podmonitorsget · list · watchLow
ClusterRole grafana-agentcore/podsget · list · watchLow
ClusterRole grafana-agentdiscovery.k8s.io/podsget · list · watchLow
ClusterRole grafana-agentnetworking.k8s.io/podsget · list · watchLow
ClusterRole grafana-agentmonitoring.coreos.com/probesget · list · watchLow
ClusterRole grafana-agentmonitoring.coreos.com/prometheusrulesget · list · watchLow
ClusterRole grafana-agentapps/replicasetsget · list · watchLow
ClusterRole grafana-agentextensions/replicasetsget · list · watchLow
ClusterRole grafana-agentmonitoring.coreos.com/servicemonitorsget · list · watchLow
ClusterRole grafana-agentcore/servicesget · list · watchLow
ClusterRole grafana-agentdiscovery.k8s.io/servicesget · list · watchLow
ClusterRole grafana-agentnetworking.k8s.io/servicesget · list · watchLow

⚠️ Potential Abuse (10)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
DaemonSetgrafana-agentconfig-reloaderghcr.io/jimmidyson/configmap-reload:v0.12.0
DaemonSetgrafana-agentgrafana-agentdocker.io/grafana/agent:v0.44.2