1 Service Accounts
1 Workloads
15 Bindings
7 High
8 Low
Description
Gadgets for debugging and introspecting apps
Overview
| Identity | Namespace | Automount | Secrets | Permissions | Workloads | Risk |
|---|---|---|---|---|---|---|
gadget | gadget | ❌ | — | 15 | 0 | High |
Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.
Identities
🤖 gadget
Namespace: gadget | Automount: ❌
🔑 Permissions (15)
| Role | Resource | Verbs | Risk | Tags |
|---|---|---|---|---|
ClusterRole gadget-cluster-role | */cronjobs | get | High | ClusterWideAccess |
ClusterRole gadget-cluster-role | */daemonsets | get | High | ClusterWideAccess |
ClusterRole gadget-cluster-role | */deployments | get | High | ClusterWideAccess |
ClusterRole gadget-cluster-role | */jobs | get | High | ClusterWideAccess |
ClusterRole gadget-cluster-role | */replicasets | get | High | ClusterWideAccess |
ClusterRole gadget-cluster-role | */replicationcontrollers | get | High | ClusterWideAccess |
ClusterRole gadget-cluster-role | */statefulsets | get | High | ClusterWideAccess |
ClusterRole gadget-cluster-role | core/namespaces | get · list · watch | Low | ClusterStructure InformationDisclosure Reconnaissance |
ClusterRole gadget-cluster-role | core/nodes | get · list · watch | Low | |
ClusterRole gadget-cluster-role | core/pods | get · list · watch | Low | |
ClusterRole gadget-cluster-role | security-profiles-operator.x-k8s.io/seccompprofiles | create · list · watch | Low | |
ClusterRole gadget-cluster-role | core/services | list | Low | |
ClusterRole gadget-cluster-role | gadget.kinvolk.io/traces | create · delete · deletecollection · get · list · patch · update · watch | Low | |
ClusterRole gadget-cluster-role | gadget.kinvolk.io/traces/status | create · delete · deletecollection · get · list · patch · update · watch | Low | |
ClusterRole gadget-cluster-role | security.openshift.io/securitycontextconstraints (restricted to: privileged) | use | Low | ResourceNameRestricted |
⚠️ Potential Abuse (3)
The following security risks were found based on the above permissions:
📦 Workloads (0)
No workloads use this ServiceAccount.