Description

ExternalDNS is a Kubernetes addon that configures public DNS servers with information about exposed Kubernetes services to make them discoverable.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
external-dnsdefault301Low

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 external-dns

Namespace: default  |  Automount:

🔑 Permissions (30)

RoleResourceVerbsRiskTags
ClusterRole external-dns-defaultcore/endpointsget · list · watchLow
ClusterRole external-dns-defaultgateway.networking.k8s.io/gatewaysget · list · watchLow
ClusterRole external-dns-defaultnetworking.istio.io/gatewaysget · list · watchLow
ClusterRole external-dns-defaultgateway.networking.k8s.io/grpcroutesget · list · watchLow
ClusterRole external-dns-defaultextensions/hostsget · list · watchLow
ClusterRole external-dns-defaultgetambassador.io/hostsget · list · watchLow
ClusterRole external-dns-defaultnetworking.k8s.io/hostsget · list · watchLow
ClusterRole external-dns-defaultprojectcontour.io/httpproxiesget · list · watchLow
ClusterRole external-dns-defaultgateway.networking.k8s.io/httproutesget · list · watchLow
ClusterRole external-dns-defaultextensions/ingressesget · list · watchLow
ClusterRole external-dns-defaultgetambassador.io/ingressesget · list · watchLow
ClusterRole external-dns-defaultnetworking.k8s.io/ingressesget · list · watchLow
ClusterRole external-dns-defaultcore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole external-dns-defaultcore/nodesget · list · watchLow
ClusterRole external-dns-defaultcore/podsget · list · watchLow
ClusterRole external-dns-defaultgateway.solo.io/proxiesget · list · watchLow
ClusterRole external-dns-defaultgloo.solo.io/proxiesget · list · watchLow
ClusterRole external-dns-defaultzalando.org/routegroupsget · list · watchLow
ClusterRole external-dns-defaultzalando.org/routegroups/statuspatch · updateLow
ClusterRole external-dns-defaultroute.openshift.io/routesget · list · watchLow
ClusterRole external-dns-defaultcore/servicesget · list · watchLow
ClusterRole external-dns-defaultconfiguration.konghq.com/tcpingressesget · list · watchLow
ClusterRole external-dns-defaultgateway.networking.k8s.io/tcproutesget · list · watchLow
ClusterRole external-dns-defaultgateway.networking.k8s.io/tlsroutesget · list · watchLow
ClusterRole external-dns-defaultcis.f5.com/transportserversget · list · watchLow
ClusterRole external-dns-defaultgateway.networking.k8s.io/udproutesget · list · watchLow
ClusterRole external-dns-defaultcis.f5.com/virtualserversget · list · watchLow
ClusterRole external-dns-defaultgateway.solo.io/virtualservicesget · list · watchLow
ClusterRole external-dns-defaultgloo.solo.io/virtualservicesget · list · watchLow
ClusterRole external-dns-defaultnetworking.istio.io/virtualservicesget · list · watchLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentexternal-dnsexternal-dnsdocker.io/bitnami/external-dns:0.17.0-debian-12-r5