Description

A Helm chart for Argo Rollouts

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
argo-rolloutsdefault461Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 argo-rollouts

Namespace: default  |  Automount:

🔑 Permissions (46)

RoleResourceVerbsRiskTags
ClusterRole argo-rolloutsbatch/jobscreate · delete · get · list · patch · update · watchCriticalPotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole argo-rolloutscore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole argo-rolloutscore/configmapscreate · get · list · update · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole argo-rolloutsnetworking.gloo.solo.io/routetables*HighClusterWideAccess WildcardPermission
ClusterRole argo-rolloutsgetambassador.io/ambassadormappingscreate · delete · get · list · update · watchLow
ClusterRole argo-rolloutsx.getambassador.io/ambassadormappingscreate · delete · get · list · update · watchLow
ClusterRole argo-rolloutsargoproj.io/analysisrunscreate · delete · get · list · patch · update · watchLow
ClusterRole argo-rolloutsargoproj.io/analysisruns/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole argo-rolloutsargoproj.io/analysistemplatesget · list · watchLow
ClusterRole argo-rolloutsapisix.apache.org/apisixroutesget · update · watchLow
ClusterRole argo-rolloutsargoproj.io/clusteranalysistemplatesget · list · watchLow
ClusterRole argo-rolloutsapps/deploymentsget · list · update · watchLow
ClusterRole argo-rolloutscore/deploymentsget · list · update · watchLow
ClusterRole argo-rolloutsnetworking.istio.io/destinationrulesget · list · patch · update · watchLow
ClusterRole argo-rolloutscore/endpointsgetLow
ClusterRole argo-rolloutscore/eventscreate · patch · updateLow
ClusterRole argo-rolloutsargoproj.io/experimentscreate · delete · get · list · patch · update · watchLow
ClusterRole argo-rolloutsargoproj.io/experiments/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole argo-rolloutsgateway.networking.k8s.io/grpcroutesget · list · update · watchLow
ClusterRole argo-rolloutsprojectcontour.io/httpproxiesget · list · update · watchLow
ClusterRole argo-rolloutsgateway.networking.k8s.io/httproutesget · list · update · watchLow
ClusterRole argo-rolloutsextensions/ingressescreate · get · list · patch · update · watchLow
ClusterRole argo-rolloutsnetworking.k8s.io/ingressescreate · get · list · patch · update · watchLow
ClusterRole argo-rolloutscoordination.k8s.io/leasescreate · get · updateLow
ClusterRole argo-rolloutsgetambassador.io/mappingscreate · delete · get · list · update · watchLow
ClusterRole argo-rolloutsx.getambassador.io/mappingscreate · delete · get · list · update · watchLow
ClusterRole argo-rolloutscore/podslist · update · watchLow
ClusterRole argo-rolloutscore/pods/evictioncreateLow
ClusterRole argo-rolloutsapps/podtemplatesget · list · update · watchLow
ClusterRole argo-rolloutscore/podtemplatesget · list · update · watchLow
ClusterRole argo-rolloutsapps/replicasetscreate · delete · get · list · patch · update · watchLow
ClusterRole argo-rolloutsargoproj.io/rolloutsget · list · patch · update · watchLow
ClusterRole argo-rolloutsargoproj.io/rollouts/finalizersget · list · patch · update · watchLow
ClusterRole argo-rolloutsargoproj.io/rollouts/statusget · list · patch · update · watchLow
ClusterRole argo-rolloutscore/servicescreate · delete · get · list · patch · watchLow
ClusterRole argo-rolloutselbv2.k8s.aws/targetgroupbindingsget · listLow
ClusterRole argo-rolloutsgateway.networking.k8s.io/tcproutesget · list · update · watchLow
ClusterRole argo-rolloutsgateway.networking.k8s.io/tlsroutesget · list · update · watchLow
ClusterRole argo-rolloutstraefik.containo.us/traefikservicesget · update · watchLow
ClusterRole argo-rolloutstraefik.io/traefikservicesget · update · watchLow
ClusterRole argo-rolloutssplit.smi-spec.io/trafficsplitscreate · get · patch · update · watchLow
ClusterRole argo-rolloutsgateway.networking.k8s.io/udproutesget · list · update · watchLow
ClusterRole argo-rolloutsappmesh.k8s.aws/virtualnodesget · list · patch · update · watchLow
ClusterRole argo-rolloutsappmesh.k8s.aws/virtualroutersget · list · patch · update · watchLow
ClusterRole argo-rolloutsappmesh.k8s.aws/virtualservicesget · list · watchLow
ClusterRole argo-rolloutsnetworking.istio.io/virtualservicesget · list · patch · update · watchLow

⚠️ Potential Abuse (8)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentargo-rolloutsargo-rolloutsquay.io/argoproj/argo-rollouts:v1.8.3