Description

A Helm chart for Argo Events, the event-driven workflow automation framework

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
argo-events-controller-managerdefault191Critical
argo-events-events-webhookdefault00

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 argo-events-controller-manager

Namespace: default  |  Automount:

🔑 Permissions (19)

RoleResourceVerbsRiskTags
ClusterRole argo-events-controller-managercore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole argo-events-controller-managerapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole argo-events-controller-managercoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService LeaderElectionAbuse Tampering
ClusterRole argo-events-controller-managercore/podscreate · delete · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole argo-events-controller-managercore/pods/execcreate · delete · get · list · patch · update · watchCriticalClusterWidePodExec CodeExecution ElevationOfPrivilege LateralMovement PodExec (+1 more)
ClusterRole argo-events-controller-managercore/secretscreate · delete · get · list · patch · updateCriticalClusterWideSecretAccess Persistence PotentialPrivilegeEscalation PrivilegeEscalation SecretAccess (+1 more)
ClusterRole argo-events-controller-managercore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole argo-events-controller-managerapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole argo-events-controller-managerargoproj.io/eventbuscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-controller-managerargoproj.io/eventbus/finalizerscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-controller-managerargoproj.io/eventbus/statuscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-controller-managercore/eventscreate · patchLow
ClusterRole argo-events-controller-managerargoproj.io/eventsourcescreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-controller-managerargoproj.io/eventsources/finalizerscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-controller-managerargoproj.io/eventsources/statuscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-controller-managercore/persistentvolumeclaimscreate · delete · get · list · patch · update · watchLow
ClusterRole argo-events-controller-managerargoproj.io/sensorscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-controller-managerargoproj.io/sensors/finalizerscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-controller-managerargoproj.io/sensors/statuscreate · delete · deletecollection · get · list · patch · update · watchLow

⚠️ Potential Abuse (21)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentargo-events-controller-managercontroller-managerquay.io/argoproj/argo-events:v1.9.6

🤖 argo-events-events-webhook

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (0)

No workloads use this ServiceAccount.