Description

Kasten’s K10 Data Management Platform

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
k10-grafanadefault11Low
k10-grafana-testdefault11Low
k10-k10default017
prometheus-serverdefault02

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 k10-grafana

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
Role k10-grafanaextensions/podsecuritypolicies (restricted to: k10-grafana)useLowResourceNameRestricted

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentk10-grafanagrafanagrafana/grafana:8.1.0

🤖 k10-grafana-test

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
Role k10-grafana-testpolicy/podsecuritypolicies (restricted to: k10-grafana-test)useLowResourceNameRestricted

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Podk10-grafana-testk10-testbats/bats:v1.1.0

🤖 k10-k10

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (17)

KindNameContainerImage
Deploymentaggregatedapis-svcaggregatedapis-svcgcr.io/kasten-images/aggregatedapis:4.0.11
Deploymentauth-svcauth-svcgcr.io/kasten-images/auth:4.0.11
Deploymentcatalog-svccatalog-svcgcr.io/kasten-images/catalog:4.0.11
Deploymentcatalog-svckanister-sidecarghcr.io/kanisterio/kanister-tools:0.66.0
Deploymentconfig-svcconfig-svcgcr.io/kasten-images/config:4.0.11
Deploymentcrypto-svcbloblifecyclemanager-svcgcr.io/kasten-images/bloblifecyclemanager:4.0.11
Deploymentcrypto-svccrypto-svcgcr.io/kasten-images/crypto:4.0.11
Deploymentdashboardbff-svcdashboardbff-svcgcr.io/kasten-images/dashboardbff:4.0.11
Deploymentexecutor-svcexecutor-svcgcr.io/kasten-images/executor:4.0.11
Deploymentexecutor-svctoolsgcr.io/kasten-images/cephtool:4.0.11
Deploymentfrontend-svcfrontend-svcgcr.io/kasten-images/frontend:4.0.11
Deploymentgatewayambassadorquay.io/datawire/ambassador:1.13.8
Deploymentjobs-svcjobs-svcgcr.io/kasten-images/jobs:4.0.11
Deploymentkanister-svckanister-svcgcr.io/kasten-images/kanister:4.0.11
Deploymentlogging-svclogging-svcgcr.io/kasten-images/logging:4.0.11
Deploymentmetering-svcmetering-svcgcr.io/kasten-images/metering:4.0.11
Deploymentstate-svcstate-svcgcr.io/kasten-images/state:4.0.11

🤖 prometheus-server

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (2)

KindNameContainerImage
Deploymentprometheus-serverprometheus-serverquay.io/prometheus/prometheus:v2.26.0
Deploymentprometheus-serverprometheus-server-configmap-reloadjimmidyson/configmap-reload:v0.5.0