Description

A Helm chart to install Argo-Events in k8s Cluster

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
argo-events-sadefault183Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 argo-events-sa

Namespace: default  |  Automount:

🔑 Permissions (18)

RoleResourceVerbsRiskTags
Role argo-events-rolecore/secretscreate · delete · get · list · patch · update · watchCriticalCredentialAccess DataExposure InformationDisclosure Persistence PotentialPrivilegeEscalation (+2 more)
Role argo-events-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
Role argo-events-roleapps/deploymentscreate · delete · get · list · patch · update · watchHighPersistence PotentialPrivilegeEscalation Tampering WorkloadLifecycle
Role argo-events-rolecore/podscreate · delete · get · list · patch · update · watchHighLateralMovement Persistence PotentialPrivilegeEscalation Tampering WorkloadExecution
Role argo-events-rolecore/pods/execcreate · delete · get · list · patch · update · watchHighCodeExecution LateralMovement PodExec PotentialPrivilegeEscalation
Role argo-events-rolecore/servicescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
Role argo-events-roleapps/statefulsetscreate · delete · get · list · patch · update · watchHighPersistence PotentialPrivilegeEscalation Tampering WorkloadLifecycle
Role argo-events-roleapiextensions.k8s.io/customresourcedefinitionscreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/eventbuscreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/eventbus/finalizerscreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/eventbus/statuscreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/eventsourcescreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/eventsources/finalizerscreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/eventsources/statuscreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-rolecore/persistentvolumeclaimscreate · delete · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/sensorscreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/sensors/finalizerscreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/sensors/statuscreate · delete · deletecollection · get · list · patch · update · watchLow

⚠️ Potential Abuse (11)

The following security risks were found based on the above permissions:

📦 Workloads (3)

KindNameContainerImage
Deploymentargo-events-eventbus-controllereventbus-controllerquay.io/argoproj/argo-events:v1.5.0
Deploymentargo-events-eventsource-controllereventsource-controllerquay.io/argoproj/argo-events:v1.5.0
Deploymentargo-events-sensor-controllersensor-controllerquay.io/argoproj/argo-events:v1.5.0