Description

Promtail is an agent which ships the contents of local logs to a Loki instance

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
promtaildefault51Low

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 promtail

Namespace: default  |  Automount:

🔑 Permissions (5)

RoleResourceVerbsRiskTags
ClusterRole promtailcore/endpointsget · list · watchLow
ClusterRole promtailcore/nodesget · list · watchLow
ClusterRole promtailcore/nodes/proxyget · list · watchLow
ClusterRole promtailcore/podsget · list · watchLow
ClusterRole promtailcore/servicesget · list · watchLow

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
DaemonSetpromtailpromtaildocker.io/grafana/promtail:3.5.1