Description

Loki: like Prometheus, but for logs.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
lokidefault52Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 loki

Namespace: default  |  Automount:

🔑 Permissions (5)

RoleResourceVerbsRiskTags
ClusterRole loki-promtail-clusterrolecore/nodes/proxyget · list · watchCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole loki-promtail-clusterrolecore/endpointsget · list · watchLow
ClusterRole loki-promtail-clusterrolecore/nodesget · list · watchLow
ClusterRole loki-promtail-clusterrolecore/podsget · list · watchLow
ClusterRole loki-promtail-clusterrolecore/servicesget · list · watchLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
DaemonSetloki-promtailpromtailgrafana/promtail:latest
Deploymentlokilokigrafana/loki:latest