← Permission Reference
T2
delete daemonsets
Deleting a DaemonSet removes security agents, log collectors, or CNI plugins running on every node.
Deleting a critical DaemonSet (e.g. Calico, Cilium, Falco) can sever network connectivity or blind monitoring cluster-wide.
Contextual upgrade to T1:
T1 where the DaemonSet is the CNI or a security agent, because removing it takes away the control itself. NetworkPolicy stops being enforced once the plugin behind it is gone, and runtime detection stops recording.
The cluster keeps running, which is what makes it quiet.
- API Group
- apps
- Scope
- namespaced
- Audit Level
- RequestResponse

