Description

A Helm chart to install Argo-Events in k8s Cluster

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
argo-events-sadefault213Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 argo-events-sa

Namespace: default  |  Automount:

🔑 Permissions (21)

RoleResourceVerbsRiskTags
Role argo-events-rolecore/secretscreate · delete · get · list · patch · update · watchCriticalCredentialAccess DataExposure InformationDisclosure Persistence PotentialPrivilegeEscalation (+2 more)
Role argo-events-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
Role argo-events-roleapps/deploymentscreate · delete · get · list · patch · update · watchHighPersistence PotentialPrivilegeEscalation Tampering WorkloadLifecycle
Role argo-events-rolebatch/jobscreate · delete · get · list · patch · update · watchHighPotentialPrivilegeEscalation Tampering WorkloadLifecycle
Role argo-events-rolecore/podscreate · delete · get · list · patch · update · watchHighLateralMovement Persistence PotentialPrivilegeEscalation Tampering WorkloadExecution
Role argo-events-rolecore/pods/execcreate · delete · get · list · patch · update · watchHighCodeExecution LateralMovement PodExec PotentialPrivilegeEscalation
Role argo-events-rolecore/servicescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
Role argo-events-roleapps/statefulsetscreate · delete · get · list · patch · update · watchHighPersistence PotentialPrivilegeEscalation Tampering WorkloadLifecycle
Role argo-events-roleapiextensions.k8s.io/customresourcedefinitionscreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/eventbuscreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/eventbus/finalizerscreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-rolecore/eventscreate · delete · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/eventsourcescreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/eventsources/finalizerscreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-rolecore/persistentvolumeclaimscreate · delete · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/sensorscreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/sensors/finalizerscreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/workflowscreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/workflows/finalizerscreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/workflowtemplatescreate · delete · deletecollection · get · list · patch · update · watchLow
Role argo-events-roleargoproj.io/workflowtemplates/finalizerscreate · delete · deletecollection · get · list · patch · update · watchLow

⚠️ Potential Abuse (12)

The following security risks were found based on the above permissions:

📦 Workloads (3)

KindNameContainerImage
Deploymentargo-events-eventbus-controllereventbus-controllerargoproj/eventbus-controller:v1.2.3
Deploymentargo-events-eventsource-controllereventsource-controllerargoproj/eventsource-controller:v1.2.3
Deploymentargo-events-sensor-controllersensor-controllerargoproj/sensor-controller:v1.2.3