Description

A Helm chart for Argo CD Image Updater, a tool to automatically update the container images of Kubernetes workloads which are managed by Argo CD

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
argocd-image-updaterdefault41Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 argocd-image-updater

Namespace: default  |  Automount:

🔑 Permissions (4)

RoleResourceVerbsRiskTags
Role argocd-image-updatercore/secretsget · list · watchCriticalCredentialAccess DataExposure InformationDisclosure SecretAccess
Role argocd-image-updatercore/configmapsget · list · watchMediumConfigMapAccess DataExposure InformationDisclosure
ClusterRole argocd-image-updaterargoproj.io/applicationsget · list · patch · updateLow
ClusterRole argocd-image-updatercore/eventscreateLow

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentargocd-image-updaterargocd-image-updaterquay.io/argoprojlabs/argocd-image-updater:v0.16.0