Description

GitLab is the most comprehensive AI-powered DevSecOps Platform.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
gitlab-cert-managerdefault561Critical
gitlab-cert-manager-cainjectordefault81Critical
gitlab-cert-manager-webhookdefault21Critical
gitlab-gitlab-runnerdefault11Critical
gitlab-kubernetes-ingressdefault181Critical
gitlab-nginx-ingressdefault241Critical
gitlab-traefikdefault181Critical
gitlab-prometheus-serverdefault132High
gitlab-kube-state-metricsdefault321Medium
gitlab-cert-manager-startupapicheckdefault11Low
gitlab-certmanager-issuerdefault11Low
gitlab-shared-secretsdefault11Low
gitlab-alertmanagerdefault01
gitlab-gitlab-zoektdefault03
gitlab-postgresqldefault02
gitlab-prometheus-node-exporterdefault01
gitlab-prometheus-pushgatewaydefault01
gitlab-redis-masterdefault02

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 gitlab-cert-manager

Namespace: default  |  Automount:

🔑 Permissions (56)

RoleResourceVerbsRiskTags
ClusterRole gitlab-cert-manager-controller-challengescore/podscreate · delete · get · list · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation WorkloadExecution
ClusterRole gitlab-cert-manager-controller-certificatescore/secretscreate · delete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure Persistence (+4 more)
ClusterRole gitlab-cert-manager-controller-challengescore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole gitlab-cert-manager-controller-clusterissuerscore/secretscreate · delete · get · list · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole gitlab-cert-manager-controller-issuerscore/secretscreate · delete · get · list · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole gitlab-cert-manager-controller-orderscore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole gitlab-cert-manager-controller-certificatesigningrequestscertificates.k8s.io/certificatesigningrequests/statuspatch · updateMediumCertificateManagement DenialOfService Tampering
ClusterRole gitlab-cert-manager-controller-certificatesigningrequestsauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole gitlab-cert-manager-controller-certificatescert-manager.io/certificaterequestsget · list · patch · update · watchLow
ClusterRole gitlab-cert-manager-controller-ingress-shimcert-manager.io/certificaterequestscreate · delete · get · list · update · watchLow
ClusterRole gitlab-cert-manager-controller-certificatescert-manager.io/certificaterequests/finalizersupdateLow
ClusterRole gitlab-cert-manager-controller-certificatescert-manager.io/certificaterequests/statuspatch · updateLow
ClusterRole gitlab-cert-manager-controller-certificatescert-manager.io/certificatesget · list · patch · update · watchLow
ClusterRole gitlab-cert-manager-controller-ingress-shimcert-manager.io/certificatescreate · delete · get · list · update · watchLow
ClusterRole gitlab-cert-manager-controller-certificatescert-manager.io/certificates/finalizersupdateLow
ClusterRole gitlab-cert-manager-controller-certificatescert-manager.io/certificates/statuspatch · updateLow
ClusterRole gitlab-cert-manager-controller-certificatesigningrequestscertificates.k8s.io/certificatesigningrequestsget · list · update · watchLow
ClusterRole gitlab-cert-manager-controller-challengesacme.cert-manager.io/challengesget · list · patch · update · watchLow
ClusterRole gitlab-cert-manager-controller-ordersacme.cert-manager.io/challengescreate · delete · get · list · watchLow
ClusterRole gitlab-cert-manager-controller-challengesacme.cert-manager.io/challenges/finalizersupdateLow
ClusterRole gitlab-cert-manager-controller-challengesacme.cert-manager.io/challenges/statuspatch · updateLow
ClusterRole gitlab-cert-manager-controller-certificatescert-manager.io/clusterissuersget · list · watchLow
ClusterRole gitlab-cert-manager-controller-challengescert-manager.io/clusterissuersget · list · watchLow
ClusterRole gitlab-cert-manager-controller-clusterissuerscert-manager.io/clusterissuersget · list · patch · update · watchLow
ClusterRole gitlab-cert-manager-controller-ingress-shimcert-manager.io/clusterissuersget · list · watchLow
ClusterRole gitlab-cert-manager-controller-orderscert-manager.io/clusterissuersget · list · watchLow
ClusterRole gitlab-cert-manager-controller-clusterissuerscert-manager.io/clusterissuers/statuspatch · updateLow
ClusterRole gitlab-cert-manager-controller-certificatescore/eventscreate · patchLow
ClusterRole gitlab-cert-manager-controller-challengescore/eventscreate · patchLow
ClusterRole gitlab-cert-manager-controller-clusterissuerscore/eventscreate · patchLow
ClusterRole gitlab-cert-manager-controller-ingress-shimcore/eventscreate · patchLow
ClusterRole gitlab-cert-manager-controller-issuerscore/eventscreate · patchLow
ClusterRole gitlab-cert-manager-controller-orderscore/eventscreate · patchLow
ClusterRole gitlab-cert-manager-controller-ingress-shimgateway.networking.k8s.io/gatewaysget · list · watchLow
ClusterRole gitlab-cert-manager-controller-ingress-shimgateway.networking.k8s.io/gateways/finalizersupdateLow
ClusterRole gitlab-cert-manager-controller-challengesgateway.networking.k8s.io/httproutescreate · delete · get · list · update · watchLow
ClusterRole gitlab-cert-manager-controller-ingress-shimgateway.networking.k8s.io/httproutesget · list · watchLow
ClusterRole gitlab-cert-manager-controller-ingress-shimgateway.networking.k8s.io/httproutes/finalizersupdateLow
ClusterRole gitlab-cert-manager-controller-challengesnetworking.k8s.io/ingressescreate · delete · get · list · update · watchLow
ClusterRole gitlab-cert-manager-controller-ingress-shimnetworking.k8s.io/ingressesget · list · watchLow
ClusterRole gitlab-cert-manager-controller-ingress-shimnetworking.k8s.io/ingresses/finalizersupdateLow
ClusterRole gitlab-cert-manager-controller-certificatescert-manager.io/issuersget · list · watchLow
ClusterRole gitlab-cert-manager-controller-challengescert-manager.io/issuersget · list · watchLow
ClusterRole gitlab-cert-manager-controller-ingress-shimcert-manager.io/issuersget · list · watchLow
ClusterRole gitlab-cert-manager-controller-issuerscert-manager.io/issuersget · list · patch · update · watchLow
ClusterRole gitlab-cert-manager-controller-orderscert-manager.io/issuersget · list · watchLow
ClusterRole gitlab-cert-manager-controller-issuerscert-manager.io/issuers/statuspatch · updateLow
Role gitlab-cert-manager:leaderelectioncoordination.k8s.io/leasescreate · get · patch · updateLow
ClusterRole gitlab-cert-manager-controller-certificatesacme.cert-manager.io/orderscreate · delete · get · list · watchLow
ClusterRole gitlab-cert-manager-controller-ordersacme.cert-manager.io/ordersget · list · patch · update · watchLow
ClusterRole gitlab-cert-manager-controller-ordersacme.cert-manager.io/orders/finalizersupdateLow
ClusterRole gitlab-cert-manager-controller-ordersacme.cert-manager.io/orders/statuspatch · updateLow
ClusterRole gitlab-cert-manager-controller-challengesroute.openshift.io/routes/custom-hostcreateLow
ClusterRole gitlab-cert-manager-controller-challengescore/servicescreate · delete · get · list · watchLow
ClusterRole gitlab-cert-manager-controller-approve:cert-manager-iocert-manager.io/signersapproveLow
ClusterRole gitlab-cert-manager-controller-certificatesigningrequestscertificates.k8s.io/signerssignLow

⚠️ Potential Abuse (9)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentgitlab-cert-managercert-manager-controllerquay.io/jetstack/cert-manager-controller:v1.12.17

🤖 gitlab-nginx-ingress

Namespace: default  |  Automount:

🔑 Permissions (24)

RoleResourceVerbsRiskTags
Role gitlab-nginx-ingresscore/secretsget · list · watchCriticalCredentialAccess DataExposure InformationDisclosure SecretAccess
Role gitlab-nginx-ingresscore/configmapscreate · get · list · update · watchMediumConfigMapAccess DataExposure InformationDisclosure
ClusterRole gitlab-nginx-ingresscore/configmapslist · watchLow
ClusterRole gitlab-nginx-ingresscore/endpointslist · watchLow
Role gitlab-nginx-ingresscore/endpointsget · list · watchLow
ClusterRole gitlab-nginx-ingressdiscovery.k8s.io/endpointslicesget · list · watchLow
Role gitlab-nginx-ingressdiscovery.k8s.io/endpointslicesget · list · watchLow
ClusterRole gitlab-nginx-ingresscore/eventscreate · patchLow
Role gitlab-nginx-ingresscore/eventscreate · patchLow
ClusterRole gitlab-nginx-ingressnetworking.k8s.io/ingressclassesget · list · watchLow
Role gitlab-nginx-ingressnetworking.k8s.io/ingressclassesget · list · watchLow
ClusterRole gitlab-nginx-ingressnetworking.k8s.io/ingressesget · list · watchLow
Role gitlab-nginx-ingressnetworking.k8s.io/ingressesget · list · watchLow
ClusterRole gitlab-nginx-ingressnetworking.k8s.io/ingresses/statusupdateLow
Role gitlab-nginx-ingressnetworking.k8s.io/ingresses/statusupdateLow
ClusterRole gitlab-nginx-ingresscoordination.k8s.io/leaseslist · watchLow
Role gitlab-nginx-ingresscoordination.k8s.io/leasescreate · get · updateLow
Role gitlab-nginx-ingresscore/namespacesgetLow
ClusterRole gitlab-nginx-ingresscore/nodesget · list · watchLow
ClusterRole gitlab-nginx-ingresscore/podslist · watchLow
Role gitlab-nginx-ingresscore/podsget · list · watchLow
ClusterRole gitlab-nginx-ingresscore/secretslist · watchLow
ClusterRole gitlab-nginx-ingresscore/servicesget · list · watchLow
Role gitlab-nginx-ingresscore/servicesget · list · watchLow

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentgitlab-nginx-ingress-controllercontrollerregistry.gitlab.com/gitlab-org/cloud-native/mirror/images/ingress-nginx/controller:v1.11.5@sha256:a1cbad75b0a7098bf9325132794dddf9eef917e8a7fe246749a4cea7ff6f01eb

🤖 gitlab-kubernetes-ingress

Namespace: default  |  Automount:

🔑 Permissions (18)

RoleResourceVerbsRiskTags
ClusterRole gitlab-kubernetes-ingresscore/secretscreate · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole gitlab-kubernetes-ingresscore.haproxy.org/*get · list · update · watchHighClusterWideAccess WildcardPermission
ClusterRole gitlab-kubernetes-ingresscore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole gitlab-kubernetes-ingresscore/eventsget · list · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole gitlab-kubernetes-ingressapiextensions.k8s.io/customresourcedefinitionsget · list · update · watchLow
ClusterRole gitlab-kubernetes-ingresscore/endpointsget · list · watchLow
ClusterRole gitlab-kubernetes-ingressdiscovery.k8s.io/endpointslicesget · list · watchLow
ClusterRole gitlab-kubernetes-ingressextensions/ingressclassesget · list · watchLow
ClusterRole gitlab-kubernetes-ingressnetworking.k8s.io/ingressclassesget · list · watchLow
ClusterRole gitlab-kubernetes-ingressextensions/ingressesget · list · watchLow
ClusterRole gitlab-kubernetes-ingressnetworking.k8s.io/ingressesget · list · watchLow
ClusterRole gitlab-kubernetes-ingressextensions/ingresses/statusget · list · update · watchLow
ClusterRole gitlab-kubernetes-ingressnetworking.k8s.io/ingresses/statusget · list · update · watchLow
ClusterRole gitlab-kubernetes-ingresscore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole gitlab-kubernetes-ingresscore/nodesget · list · watchLow
ClusterRole gitlab-kubernetes-ingresscore/podsget · list · watchLow
ClusterRole gitlab-kubernetes-ingresscore/serviceaccountsget · list · watchLow
ClusterRole gitlab-kubernetes-ingresscore/servicesget · list · watchLow

⚠️ Potential Abuse (8)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentgitlab-kubernetes-ingresskubernetes-ingress-controllerhaproxytech/kubernetes-ingress:1.10.4

🤖 gitlab-traefik

Namespace: default  |  Automount:

🔑 Permissions (18)

RoleResourceVerbsRiskTags
ClusterRole gitlab-traefikcore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole gitlab-traefikcore/endpointsget · list · watchLow
ClusterRole gitlab-traefikextensions/ingressclassesget · list · watchLow
ClusterRole gitlab-traefiknetworking.k8s.io/ingressclassesget · list · watchLow
ClusterRole gitlab-traefikextensions/ingressesget · list · watchLow
ClusterRole gitlab-traefiknetworking.k8s.io/ingressesget · list · watchLow
ClusterRole gitlab-traefikextensions/ingresses/statusupdateLow
ClusterRole gitlab-traefiknetworking.k8s.io/ingresses/statusupdateLow
ClusterRole gitlab-traefiktraefik.containo.us/ingressroutesget · list · watchLow
ClusterRole gitlab-traefiktraefik.containo.us/ingressroutetcpsget · list · watchLow
ClusterRole gitlab-traefiktraefik.containo.us/ingressrouteudpsget · list · watchLow
ClusterRole gitlab-traefiktraefik.containo.us/middlewaresget · list · watchLow
ClusterRole gitlab-traefiktraefik.containo.us/middlewaretcpsget · list · watchLow
ClusterRole gitlab-traefiktraefik.containo.us/serverstransportsget · list · watchLow
ClusterRole gitlab-traefikcore/servicesget · list · watchLow
ClusterRole gitlab-traefiktraefik.containo.us/tlsoptionsget · list · watchLow
ClusterRole gitlab-traefiktraefik.containo.us/tlsstoresget · list · watchLow
ClusterRole gitlab-traefiktraefik.containo.us/traefikservicesget · list · watchLow

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentgitlab-traefikgitlab-traefiktraefik:2.6.3

🤖 gitlab-cert-manager-cainjector

Namespace: default  |  Automount:

🔑 Permissions (8)

RoleResourceVerbsRiskTags
ClusterRole gitlab-cert-manager-cainjectorcore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole gitlab-cert-manager-cainjectoradmissionregistration.k8s.io/mutatingwebhookconfigurationsget · list · patch · update · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole gitlab-cert-manager-cainjectoradmissionregistration.k8s.io/validatingwebhookconfigurationsget · list · patch · update · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole gitlab-cert-manager-cainjectorapiregistration.k8s.io/apiservicesget · list · patch · update · watchLow
ClusterRole gitlab-cert-manager-cainjectorcert-manager.io/certificatesget · list · watchLow
ClusterRole gitlab-cert-manager-cainjectorapiextensions.k8s.io/customresourcedefinitionsget · list · patch · update · watchLow
ClusterRole gitlab-cert-manager-cainjectorcore/eventscreate · get · patch · updateLow
Role gitlab-cert-manager-cainjector:leaderelectioncoordination.k8s.io/leasescreate · get · patch · updateLow

⚠️ Potential Abuse (5)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentgitlab-cert-manager-cainjectorcert-manager-cainjectorquay.io/jetstack/cert-manager-cainjector:v1.12.17

🤖 gitlab-cert-manager-webhook

Namespace: default  |  Automount:

🔑 Permissions (2)

RoleResourceVerbsRiskTags
Role gitlab-cert-manager-webhook:dynamic-servingcore/secretscreate · get · list · update · watchCriticalCredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole gitlab-cert-manager-webhook:subjectaccessreviewsauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentgitlab-cert-manager-webhookcert-manager-webhookquay.io/jetstack/cert-manager-webhook:v1.12.17

🤖 gitlab-gitlab-runner

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
Role gitlab-gitlab-runnercore/**CriticalCodeExecution ConfigMapAccess CredentialAccess DataExposure DenialOfService (+21 more)

⚠️ Potential Abuse (17)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentgitlab-gitlab-runnergitlab-gitlab-runnerregistry.gitlab.com/gitlab-org/gitlab-runner:alpine-v18.0.2

🤖 gitlab-prometheus-server

Namespace: default  |  Automount:

🔑 Permissions (13)

RoleResourceVerbsRiskTags
ClusterRole gitlab-prometheus-servercore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole gitlab-prometheus-servercore/endpointsget · list · watchLow
ClusterRole gitlab-prometheus-serverdiscovery.k8s.io/endpointslicesget · list · watchLow
ClusterRole gitlab-prometheus-servercore/ingressesget · list · watchLow
ClusterRole gitlab-prometheus-serverextensions/ingressesget · list · watchLow
ClusterRole gitlab-prometheus-servernetworking.k8s.io/ingressesget · list · watchLow
ClusterRole gitlab-prometheus-serverextensions/ingresses/statusget · list · watchLow
ClusterRole gitlab-prometheus-servernetworking.k8s.io/ingresses/statusget · list · watchLow
ClusterRole gitlab-prometheus-servercore/nodesget · list · watchLow
ClusterRole gitlab-prometheus-servercore/nodes/metricsget · list · watchLow
ClusterRole gitlab-prometheus-servercore/nodes/proxyget · list · watchLow
ClusterRole gitlab-prometheus-servercore/podsget · list · watchLow
ClusterRole gitlab-prometheus-servercore/servicesget · list · watchLow

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymentgitlab-prometheus-serverprometheus-serverquay.io/prometheus/prometheus:v3.3.1
Deploymentgitlab-prometheus-serverprometheus-server-configmap-reloadquay.io/prometheus-operator/prometheus-config-reloader:v0.82.0

🤖 gitlab-kube-state-metrics

Namespace: default  |  Automount:

🔑 Permissions (32)

RoleResourceVerbsRiskTags
ClusterRole gitlab-kube-state-metricsadmissionregistration.k8s.io/mutatingwebhookconfigurationslist · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole gitlab-kube-state-metricsadmissionregistration.k8s.io/validatingwebhookconfigurationslist · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole gitlab-kube-state-metricscertificates.k8s.io/certificatesigningrequestslist · watchLow
ClusterRole gitlab-kube-state-metricscore/configmapslist · watchLow
ClusterRole gitlab-kube-state-metricsbatch/cronjobslist · watchLow
ClusterRole gitlab-kube-state-metricsapps/daemonsetslist · watchLow
ClusterRole gitlab-kube-state-metricsextensions/daemonsetslist · watchLow
ClusterRole gitlab-kube-state-metricsapps/deploymentslist · watchLow
ClusterRole gitlab-kube-state-metricsextensions/deploymentslist · watchLow
ClusterRole gitlab-kube-state-metricscore/endpointslist · watchLow
ClusterRole gitlab-kube-state-metricsautoscaling/horizontalpodautoscalerslist · watchLow
ClusterRole gitlab-kube-state-metricsextensions/ingresseslist · watchLow
ClusterRole gitlab-kube-state-metricsnetworking.k8s.io/ingresseslist · watchLow
ClusterRole gitlab-kube-state-metricsbatch/jobslist · watchLow
ClusterRole gitlab-kube-state-metricscoordination.k8s.io/leaseslist · watchLow
ClusterRole gitlab-kube-state-metricscore/limitrangeslist · watchLow
ClusterRole gitlab-kube-state-metricscore/namespaceslist · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole gitlab-kube-state-metricsnetworking.k8s.io/networkpolicieslist · watchLow
ClusterRole gitlab-kube-state-metricscore/nodeslist · watchLow
ClusterRole gitlab-kube-state-metricscore/persistentvolumeclaimslist · watchLow
ClusterRole gitlab-kube-state-metricscore/persistentvolumeslist · watchLow
ClusterRole gitlab-kube-state-metricspolicy/poddisruptionbudgetslist · watchLow
ClusterRole gitlab-kube-state-metricscore/podslist · watchLow
ClusterRole gitlab-kube-state-metricsapps/replicasetslist · watchLow
ClusterRole gitlab-kube-state-metricsextensions/replicasetslist · watchLow
ClusterRole gitlab-kube-state-metricscore/replicationcontrollerslist · watchLow
ClusterRole gitlab-kube-state-metricscore/resourcequotaslist · watchLow
ClusterRole gitlab-kube-state-metricscore/secretslist · watchLow
ClusterRole gitlab-kube-state-metricscore/serviceslist · watchLow
ClusterRole gitlab-kube-state-metricsapps/statefulsetslist · watchLow
ClusterRole gitlab-kube-state-metricsstorage.k8s.io/storageclasseslist · watchLow
ClusterRole gitlab-kube-state-metricsstorage.k8s.io/volumeattachmentslist · watchLow

⚠️ Potential Abuse (4)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentgitlab-kube-state-metricskube-state-metricsregistry.k8s.io/kube-state-metrics/kube-state-metrics:v2.15.0

🤖 gitlab-cert-manager-startupapicheck

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
Role gitlab-cert-manager-startupapicheck:create-certcert-manager.io/certificatescreateLow

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Jobgitlab-cert-manager-startupapicheckcert-manager-startupapicheckquay.io/jetstack/cert-manager-ctl:v1.12.17

🤖 gitlab-certmanager-issuer

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
Role gitlab-certmanager-issuercert-manager.io/issuerscreate · get · list · patch · updateLow

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Jobgitlab-issuer-a1b239ecreate-issuerregistry.gitlab.com/gitlab-org/build/cng/kubectl:v18.0.1

🤖 gitlab-shared-secrets

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
Role gitlab-shared-secretscore/secretscreate · get · list · patchLow

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Jobgitlab-shared-secrets-c2e476egitlabregistry.gitlab.com/gitlab-org/build/cng/kubectl:v18.0.1

🤖 gitlab-alertmanager

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
StatefulSetgitlab-alertmanageralertmanagerquay.io/prometheus/alertmanager:v0.28.1

🤖 gitlab-gitlab-zoekt

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (3)

KindNameContainerImage
StatefulSetgitlab-gitlab-zoektzoekt-indexerregistry.gitlab.com/gitlab-org/build/cng/gitlab-zoekt:v0.16.0-33e0d
StatefulSetgitlab-gitlab-zoektzoekt-internal-gatewaynginx:1.25.5
StatefulSetgitlab-gitlab-zoektzoekt-webserverregistry.gitlab.com/gitlab-org/build/cng/gitlab-zoekt:v0.16.0-33e0d

🤖 gitlab-postgresql

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (2)

KindNameContainerImage
StatefulSetgitlab-postgresqlmetricsdocker.io/bitnami/postgres-exporter:0.15.0-debian-11-r7
StatefulSetgitlab-postgresqlpostgresqldocker.io/bitnami/postgresql:16.6.0

🤖 gitlab-prometheus-node-exporter

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
DaemonSetgitlab-prometheus-node-exporternode-exporterquay.io/prometheus/node-exporter:v1.9.1

🤖 gitlab-prometheus-pushgateway

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentgitlab-prometheus-pushgatewaypushgatewayquay.io/prometheus/pushgateway:v1.11.1

🤖 gitlab-redis-master

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (2)

KindNameContainerImage
StatefulSetgitlab-redis-mastermetricsdocker.io/bitnami/redis-exporter:1.58.0-debian-12-r4
StatefulSetgitlab-redis-masterredisdocker.io/bitnami/redis:7.2.4-debian-12-r9