{
  "schemaVersion": "catalog-shared-check-receipt-v1",
  "subject": {
    "id": "grafana-promtail-6-17-1-default",
    "chart": "grafana/promtail",
    "version": "6.17.1",
    "base": "default",
    "renderPath": "recipes/grafana/promtail/6.17.1/revisions/default/r001/rendered/release-objects.yaml",
    "renderFileSHA256": "sha256:06ff3623536aeca2cb083040a0b0c22d6627e57cd6600f3f3482dd1e7d56eb35"
  },
  "catalogReview": {
    "path": "recipes/grafana/promtail/6.17.1/revisions/default/r001/receipts/scan-receipt.yaml",
    "note": "Separate chart-specific Catalog review; not a cub check result."
  },
  "scannerResult": {
    "schema_version": "risk-scan-findings-v1",
    "surface": "cub-scan",
    "finding_count": 6,
    "findings": [
      {
        "id": "CCVE-2025-3755",
        "name": "DaemonSet container does not set runAsNonRoot",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "DaemonSet",
          "name": "promtail",
          "namespace": "default"
        },
        "message": "Container promtail does not set runAsNonRoot: true",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set securityContext.runAsNonRoot to true at pod or container level",
            "Set runAsUser to a non-zero UID"
          ],
          "commands": [
            "kubectl get daemonset <name> -n <namespace> -o jsonpath='{.spec.template.spec.securityContext}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set securityContext.runAsNonRoot to true at pod or container level",
          "command": "kubectl get daemonset <name> -n <namespace> -o jsonpath='{.spec.template.spec.securityContext}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3755"
        }
      },
      {
        "id": "CCVE-2025-3756",
        "name": "DaemonSet containers omit resource limits",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "DaemonSet",
          "name": "promtail",
          "namespace": "default"
        },
        "message": "DaemonSet containers omit resource limits",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set resources.limits.cpu and resources.limits.memory on every container",
            "Size limits based on observed steady-state usage with headroom"
          ],
          "commands": [
            "kubectl get daemonset <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set resources.limits.cpu and resources.limits.memory on every container",
          "command": "kubectl get daemonset <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3756"
        }
      },
      {
        "id": "CCVE-2025-3757",
        "name": "DaemonSet containers omit resource requests",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "DaemonSet",
          "name": "promtail",
          "namespace": "default"
        },
        "message": "DaemonSet containers omit resource requests; HPA and scheduler decisions will be unreliable",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set resources.requests.cpu and resources.requests.memory on every container",
            "Align requests with observed steady-state usage"
          ],
          "commands": [
            "kubectl get daemonset <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set resources.requests.cpu and resources.requests.memory on every container",
          "command": "kubectl get daemonset <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3757"
        }
      },
      {
        "id": "CCVE-2025-3758",
        "name": "DaemonSet does not disable automountServiceAccountToken",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "DaemonSet",
          "name": "promtail",
          "namespace": "default"
        },
        "message": "DaemonSet does not set automountServiceAccountToken: false; pods get unnecessary API credentials",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set automountServiceAccountToken to false in the pod spec",
            "Only enable for DaemonSets that genuinely need Kubernetes API access"
          ],
          "commands": [
            "kubectl get daemonset <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0002"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set automountServiceAccountToken to false in the pod spec",
          "command": "kubectl get daemonset <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3758"
        }
      },
      {
        "id": "CCVE-2025-4075",
        "name": "ClusterRole grants nodes/proxy enabling Kubelet API RCE",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "ClusterRole",
          "name": "promtail",
          "namespace": "default"
        },
        "message": "ClusterRole grants nodes/proxy access, enabling full Kubelet API (exec/run/attach) on all nodes",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Audit all ClusterRoles for nodes/proxy permissions",
            "Remove nodes/proxy from ClusterRole rules unless strictly required",
            "Implement network policies restricting pod access to port 10250",
            "Deploy node-level runtime detection (Falco, Tetragon) for Kubelet connections",
            "Consider deploying Kyverno policy restrict-clusterrole-nodesproxy as admission guard",
            "Kyverno equivalents: KPOL-0279 and KPOL-0367",
            "Monitor KEP-2862 progress for fine-grained Kubelet authorization (K8s 1.36+)"
          ],
          "commands": [
            "kubectl get clusterroles -o json | jq '.items[] | select(.rules[]?.resources[]? == \"nodes/proxy\") | .metadata.name'",
            "kubectl get clusterrolebindings -o json | jq '.items[] | select(.roleRef.name == \"<ROLE_NAME>\") | {name: .metadata.name, subjects: .subjects}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0001"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Audit all ClusterRoles for nodes/proxy permissions",
          "command": "kubectl get clusterroles -o json | jq '.items[] | select(.rules[]?.resources[]? == \"nodes/proxy\") | .metadata.name'",
          "doc_ref": "cub-scan --explain CCVE-2025-4075"
        }
      },
      {
        "id": "CCVE-2025-4076",
        "name": "ClusterRoleBinding binds nodes/proxy ClusterRole to subjects",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "ClusterRoleBinding",
          "name": "promtail",
          "namespace": "default"
        },
        "message": "ClusterRoleBinding grants nodes/proxy via ClusterRole \"promtail\" to ServiceAccount default/promtail",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Identify which subjects are bound to the nodes/proxy ClusterRole",
            "Remove unnecessary bindings or switch to more restrictive ClusterRoles",
            "Audit ServiceAccount usage to verify necessity",
            "Restrict binding scope where possible",
            "Related policy controls: KPOL-0279 and KPOL-0367"
          ],
          "commands": [
            "kubectl get clusterrolebindings -o json | jq '.items[] | select(.roleRef.name == \"<ROLE_NAME>\") | {name: .metadata.name, subjects: .subjects}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0001"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Identify which subjects are bound to the nodes/proxy ClusterRole",
          "command": "kubectl get clusterrolebindings -o json | jq '.items[] | select(.roleRef.name == \"<ROLE_NAME>\") | {name: .metadata.name, subjects: .subjects}'",
          "doc_ref": "cub-scan --explain CCVE-2025-4076"
        }
      }
    ],
    "provenance": {
      "source": "cub-scan",
      "source_version": "v0.7.3",
      "scan_time": "2026-08-24T16:00:33Z",
      "catalog_version": "risk-catalog-v1.json@7ff79a126ad9"
    },
    "pattern_bundle": {
      "schema_version": "bundle-manifest-v1",
      "version": "v0.7.3",
      "source_repo": "confighubai/confighub-scan",
      "manifest_sha256": "0405f6ffe21e567adf5d6a732d181c7f228194920456d046b4338baeb14de1a8",
      "catalog_sha256": "7ff79a126ad99bba2505fec8b2b7711c03f50eb362141128ec1c83e27a5036ba"
    },
    "input": {
      "object_count": 5,
      "object_set_sha256": "sha256:d9d922ef14822717f96c8969547bd1a3635a9192ef91c6c4ab4307ecb8d76c03"
    }
  }
}
