Description

Real-time performance monitoring, done right!

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
netdatadefault123Critical
netdata-opentelemetry-collectordefault00

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 netdata

Namespace: default  |  Automount:

🔑 Permissions (12)

RoleResourceVerbsRiskTags
ClusterRole netdatacore/nodes/proxyget · list · watchCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole netdatacore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole netdatacore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole netdatabatch/cronjobsget · list · watchLow
ClusterRole netdataapps/deploymentsget · list · watchLow
ClusterRole netdatabatch/jobsget · list · watchLow
ClusterRole netdatacore/namespacesgetLow
ClusterRole netdatacore/nodesget · list · watchLow
ClusterRole netdatacore/nodes/metricsget · list · watchLow
ClusterRole netdatacore/podsget · list · watchLow
ClusterRole netdatacore/servicesget · list · watchLow
ClusterRole netdata-psppolicy/podsecuritypolicies (restricted to: netdata-psp)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (7)

The following security risks were found based on the above permissions:

📦 Workloads (3)

KindNameContainerImage
DaemonSetnetdata-childnetdatanetdata/netdata:v2.10.3
Deploymentnetdata-k8s-statenetdatanetdata/netdata:v2.10.3
Deploymentnetdata-parentnetdatanetdata/netdata:v2.10.3

🤖 netdata-opentelemetry-collector

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (0)

No workloads use this ServiceAccount.