The gRPC event stream refuses to start plaintext and unauthenticated.
If you run the agent with --grpc-bind-address and no transport security, it now exits at startup instead of serving. The stream carries every denial on the node - which pods exist, which paths they read, which destinations they dial, the full command line of every exec - and that is a reconnaissance report.
Previously it started anyway and logged a warning. The person who forgets the certificate and the person who reads the startup log are rarely the same person, so the warning was not a control.
To upgrade, pick one:
# mTLS, the right answer in a cluster. cert-manager can issue the pair.
- --grpc-tls-cert=/etc/pahlevan/tls/tls.crt
- --grpc-tls-key=/etc/pahlevan/tls/tls.key
- --grpc-client-ca=/etc/pahlevan/tls/ca.crt
# TLS plus a bearer token, for a collector that cannot present a certificate.
- --grpc-tls-cert=/etc/pahlevan/tls/tls.crt
- --grpc-tls-key=/etc/pahlevan/tls/tls.key
- --grpc-token=$(PAHLEVAN_GRPC_TOKEN)
# Or say explicitly that this listener is unreachable and you accept it.
- --grpc-insecure
A bearer token without TLS is still refused: in cleartext it is a token you have published. If you do not set --grpc-bind-address at all, nothing changes for you - the listener is off by default and always was.