Description

Install kube-state-metrics to generate and expose cluster-level metrics

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
kube-state-metricsdefault281Medium

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 kube-state-metrics

Namespace: default  |  Automount:

🔑 Permissions (28)

RoleResourceVerbsRiskTags
ClusterRole kube-state-metricsadmissionregistration.k8s.io/mutatingwebhookconfigurationslist · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole kube-state-metricsadmissionregistration.k8s.io/validatingwebhookconfigurationslist · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole kube-state-metricscertificates.k8s.io/certificatesigningrequestslist · watchLow
ClusterRole kube-state-metricscore/configmapslist · watchLow
ClusterRole kube-state-metricsbatch/cronjobslist · watchLow
ClusterRole kube-state-metricsapps/daemonsetslist · watchLow
ClusterRole kube-state-metricsapps/deploymentslist · watchLow
ClusterRole kube-state-metricscore/endpointslist · watchLow
ClusterRole kube-state-metricsautoscaling/horizontalpodautoscalerslist · watchLow
ClusterRole kube-state-metricsnetworking.k8s.io/ingresseslist · watchLow
ClusterRole kube-state-metricsbatch/jobslist · watchLow
ClusterRole kube-state-metricscoordination.k8s.io/leaseslist · watchLow
ClusterRole kube-state-metricscore/limitrangeslist · watchLow
ClusterRole kube-state-metricscore/namespaceslist · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole kube-state-metricsnetworking.k8s.io/networkpolicieslist · watchLow
ClusterRole kube-state-metricscore/nodeslist · watchLow
ClusterRole kube-state-metricscore/persistentvolumeclaimslist · watchLow
ClusterRole kube-state-metricscore/persistentvolumeslist · watchLow
ClusterRole kube-state-metricspolicy/poddisruptionbudgetslist · watchLow
ClusterRole kube-state-metricscore/podslist · watchLow
ClusterRole kube-state-metricsapps/replicasetslist · watchLow
ClusterRole kube-state-metricscore/replicationcontrollerslist · watchLow
ClusterRole kube-state-metricscore/resourcequotaslist · watchLow
ClusterRole kube-state-metricscore/secretslist · watchLow
ClusterRole kube-state-metricscore/serviceslist · watchLow
ClusterRole kube-state-metricsapps/statefulsetslist · watchLow
ClusterRole kube-state-metricsstorage.k8s.io/storageclasseslist · watchLow
ClusterRole kube-state-metricsstorage.k8s.io/volumeattachmentslist · watchLow

⚠️ Potential Abuse (4)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentkube-state-metricskube-state-metricsregistry.k8s.io/kube-state-metrics/kube-state-metrics:v2.15.0