Description

Official Elastic helm chart for Metricbeat

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
metricbeat-kube-state-metricsdefault311Medium
metricbeat-metricbeatdefault112Medium

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 metricbeat-kube-state-metrics

Namespace: default  |  Automount:

🔑 Permissions (31)

RoleResourceVerbsRiskTags
ClusterRole metricbeat-kube-state-metricsadmissionregistration.k8s.io/mutatingwebhookconfigurationslist · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole metricbeat-kube-state-metricsadmissionregistration.k8s.io/validatingwebhookconfigurationslist · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole metricbeat-kube-state-metricscertificates.k8s.io/certificatesigningrequestslist · watchLow
ClusterRole metricbeat-kube-state-metricscore/configmapslist · watchLow
ClusterRole metricbeat-kube-state-metricsbatch/cronjobslist · watchLow
ClusterRole metricbeat-kube-state-metricsapps/daemonsetslist · watchLow
ClusterRole metricbeat-kube-state-metricsextensions/daemonsetslist · watchLow
ClusterRole metricbeat-kube-state-metricsapps/deploymentslist · watchLow
ClusterRole metricbeat-kube-state-metricsextensions/deploymentslist · watchLow
ClusterRole metricbeat-kube-state-metricscore/endpointslist · watchLow
ClusterRole metricbeat-kube-state-metricsautoscaling/horizontalpodautoscalerslist · watchLow
ClusterRole metricbeat-kube-state-metricsextensions/ingresseslist · watchLow
ClusterRole metricbeat-kube-state-metricsnetworking.k8s.io/ingresseslist · watchLow
ClusterRole metricbeat-kube-state-metricsbatch/jobslist · watchLow
ClusterRole metricbeat-kube-state-metricscore/limitrangeslist · watchLow
ClusterRole metricbeat-kube-state-metricscore/namespaceslist · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole metricbeat-kube-state-metricsnetworking.k8s.io/networkpolicieslist · watchLow
ClusterRole metricbeat-kube-state-metricscore/nodeslist · watchLow
ClusterRole metricbeat-kube-state-metricscore/persistentvolumeclaimslist · watchLow
ClusterRole metricbeat-kube-state-metricscore/persistentvolumeslist · watchLow
ClusterRole metricbeat-kube-state-metricspolicy/poddisruptionbudgetslist · watchLow
ClusterRole metricbeat-kube-state-metricscore/podslist · watchLow
ClusterRole metricbeat-kube-state-metricsapps/replicasetslist · watchLow
ClusterRole metricbeat-kube-state-metricsextensions/replicasetslist · watchLow
ClusterRole metricbeat-kube-state-metricscore/replicationcontrollerslist · watchLow
ClusterRole metricbeat-kube-state-metricscore/resourcequotaslist · watchLow
ClusterRole metricbeat-kube-state-metricscore/secretslist · watchLow
ClusterRole metricbeat-kube-state-metricscore/serviceslist · watchLow
ClusterRole metricbeat-kube-state-metricsapps/statefulsetslist · watchLow
ClusterRole metricbeat-kube-state-metricsstorage.k8s.io/storageclasseslist · watchLow
ClusterRole metricbeat-kube-state-metricsstorage.k8s.io/volumeattachmentslist · watchLow

⚠️ Potential Abuse (4)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentmetricbeat-kube-state-metricskube-state-metricsk8s.gcr.io/kube-state-metrics/kube-state-metrics:v2.4.1

🤖 metricbeat-metricbeat

Namespace: default  |  Automount:

🔑 Permissions (11)

RoleResourceVerbsRiskTags
ClusterRole metricbeat-metricbeat-cluster-rolecore/eventsget · list · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole metricbeat-metricbeat-cluster-roleapps/deploymentsget · list · watchLow
Role metricbeat-metricbeat-rolecoordination.k8s.io/leasescreate · get · updateLow
ClusterRole metricbeat-metricbeat-cluster-rolecore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole metricbeat-metricbeat-cluster-rolecore/nodesget · list · watchLow
ClusterRole metricbeat-metricbeat-cluster-rolecore/nodes/statsgetLow
ClusterRole metricbeat-metricbeat-cluster-rolecore/podsget · list · watchLow
ClusterRole metricbeat-metricbeat-cluster-roleapps/replicasetsget · list · watchLow
ClusterRole metricbeat-metricbeat-cluster-roleextensions/replicasetsget · list · watchLow
ClusterRole metricbeat-metricbeat-cluster-rolecore/servicesget · list · watchLow
ClusterRole metricbeat-metricbeat-cluster-roleapps/statefulsetsget · list · watchLow

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
DaemonSetmetricbeat-metricbeatmetricbeatdocker.elastic.co/beats/metricbeat:8.5.1
Deploymentmetricbeat-metricbeat-metricsmetricbeatdocker.elastic.co/beats/metricbeat:8.5.1