Description

A Helm chart to install Argo-Events in k8s Cluster

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
argo-events-sadefault212Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 argo-events-sa

Namespace: default  |  Automount:

🔑 Permissions (21)

RoleResourceVerbsRiskTags
ClusterRole argo-events-rolecore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole argo-events-roleapiextensions.k8s.io/customresourcedefinitionscreate · delete · deletecollection · get · list · patch · update · watchCriticalCRDManipulation PotentialPrivilegeEscalation Tampering
ClusterRole argo-events-roleapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole argo-events-rolebatch/jobscreate · delete · get · list · patch · update · watchCriticalPotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole argo-events-rolecore/podscreate · delete · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole argo-events-rolecore/pods/execcreate · delete · get · list · patch · update · watchCriticalClusterWidePodExec CodeExecution ElevationOfPrivilege LateralMovement PodExec (+1 more)
ClusterRole argo-events-rolecore/secretscreate · delete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure Persistence (+4 more)
ClusterRole argo-events-rolecore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole argo-events-rolecore/eventscreate · delete · get · list · patch · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole argo-events-roleapiextensions.k8s.io/v1beta1/customresourcedefinitionscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-roleargoproj.io/eventsourcescreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-roleargoproj.io/eventsources/finalizerscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-roleargoproj.io/gatewayscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-roleargoproj.io/gateways/finalizerscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-rolecore/persistentvolumeclaimscreate · delete · get · list · patch · update · watchLow
ClusterRole argo-events-roleargoproj.io/sensorscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-roleargoproj.io/sensors/finalizerscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-roleargoproj.io/workflowscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-roleargoproj.io/workflows/finalizerscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-roleargoproj.io/workflowtemplatescreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole argo-events-roleargoproj.io/workflowtemplates/finalizerscreate · delete · deletecollection · get · list · patch · update · watchLow

⚠️ Potential Abuse (23)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymentargo-events-gateway-controllergateway-controllerargoproj/gateway-controller:v0.13.0
Deploymentargo-events-sensor-controllersensor-controllerargoproj/sensor-controller:v0.13.0