Description

Helm chart for deploying a multi-tenant etcd cluster.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
kamaji-etcddefault43Low

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 kamaji-etcd

Namespace: default  |  Automount:

🔑 Permissions (4)

RoleResourceVerbsRiskTags
Role kamaji-etcd-gen-certs-rolecore/secretscreateLow
Role kamaji-etcd-gen-certs-roleapps/statefulsets (restricted to: kamaji-etcd)get · list · patch · watchLowResourceNameRestricted
Role kamaji-etcd-gen-certs-rolecore/secrets (restricted to: kamaji-etcd-certs)delete · get · patchLowResourceNameRestricted
Role kamaji-etcd-gen-certs-rolecore/secrets (restricted to: kamaji-etcd-root-client-certs)delete · get · patchLowResourceNameRestricted

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (3)

KindNameContainerImage
Jobkamaji-etcd-etcd-setup-1kubectlclastix/kubectl:v1.20
Jobkamaji-etcd-etcd-setup-2etcd-clientquay.io/coreos/etcd:v3.5.6
Jobkamaji-etcd-etcd-teardownkubectlclastix/kubectl:v1.20