Description

Helm chart for the deployment of JFrog Runtime Security Agents within a Kubernetes environment.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
runtimesadefault361High

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 runtimesa

Namespace: default  |  Automount:

🔑 Permissions (36)

RoleResourceVerbsRiskTags
ClusterRole runtime-viewcore/configmapsget · list · update · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole runtime-viewapps/configmapsget · list · update · watchLow
Role configmap-creatorcore/configmapscreate · updateLow
ClusterRole runtime-viewdeployments/configmapsget · list · update · watchLow
ClusterRole runtime-viewextensions/configmapsget · list · update · watchLow
ClusterRole runtime-viewnodes/configmapsget · list · update · watchLow
ClusterRole runtime-viewpods/configmapsget · list · update · watchLow
ClusterRole runtime-viewv1/configmapsget · list · update · watchLow
ClusterRole runtime-viewapps/deploymentsget · list · update · watchLow
ClusterRole runtime-viewcore/deploymentsget · list · update · watchLow
ClusterRole runtime-viewdeployments/deploymentsget · list · update · watchLow
ClusterRole runtime-viewextensions/deploymentsget · list · update · watchLow
ClusterRole runtime-viewnodes/deploymentsget · list · update · watchLow
ClusterRole runtime-viewpods/deploymentsget · list · update · watchLow
ClusterRole runtime-viewv1/deploymentsget · list · update · watchLow
ClusterRole runtime-viewapps/nodesget · list · update · watchLow
ClusterRole runtime-viewcore/nodesget · list · update · watchLow
ClusterRole runtime-viewdeployments/nodesget · list · update · watchLow
ClusterRole runtime-viewextensions/nodesget · list · update · watchLow
ClusterRole runtime-viewnodes/nodesget · list · update · watchLow
ClusterRole runtime-viewpods/nodesget · list · update · watchLow
ClusterRole runtime-viewv1/nodesget · list · update · watchLow
ClusterRole runtime-viewapps/podsget · list · update · watchLow
ClusterRole runtime-viewcore/podsget · list · update · watchLow
ClusterRole runtime-viewdeployments/podsget · list · update · watchLow
ClusterRole runtime-viewextensions/podsget · list · update · watchLow
ClusterRole runtime-viewnodes/podsget · list · update · watchLow
ClusterRole runtime-viewpods/podsget · list · update · watchLow
ClusterRole runtime-viewv1/podsget · list · update · watchLow
ClusterRole runtime-viewapps/replicationcontrollersget · list · update · watchLow
ClusterRole runtime-viewcore/replicationcontrollersget · list · update · watchLow
ClusterRole runtime-viewdeployments/replicationcontrollersget · list · update · watchLow
ClusterRole runtime-viewextensions/replicationcontrollersget · list · update · watchLow
ClusterRole runtime-viewnodes/replicationcontrollersget · list · update · watchLow
ClusterRole runtime-viewpods/replicationcontrollersget · list · update · watchLow
ClusterRole runtime-viewv1/replicationcontrollersget · list · update · watchLow

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentjfs-runtime-controllerjfs-runtime-controllerreleases-docker.jfrog.io/jfrog/runtime-k8s-controller:0.28.0