ClusterRole
The agent runs with aClusterRole that grants read-only access to standard Kubernetes resources.
Why These Permissions?
- Pods/Nodes: To map IPs to workloads.
- Services: To identify service endpoints and DNS names.
- Deployments/StatefulSets: To understand the ownership hierarchy (Pod -> ReplicaSet -> Deployment).
- Ingresses: To map external entry points.