Description

Kasten’s K10 Data Management Platform

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
k10-grafanadefault11Low
k10-k10default017
prometheus-serverdefault02

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 k10-grafana

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
Role k10-grafanaextensions/podsecuritypolicies (restricted to: k10-grafana)useLowResourceNameRestricted

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentk10-grafanagrafanagrafana/grafana:8.1.7

🤖 k10-k10

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (17)

KindNameContainerImage
Deploymentaggregatedapis-svcaggregatedapis-svcgcr.io/kasten-images/aggregatedapis:4.5.2
Deploymentauth-svcauth-svcgcr.io/kasten-images/auth:4.5.2
Deploymentcatalog-svccatalog-svcgcr.io/kasten-images/catalog:4.5.2
Deploymentcatalog-svckanister-sidecarghcr.io/kanisterio/kanister-tools:0.69.0
Deploymentconfig-svcconfig-svcgcr.io/kasten-images/config:4.5.2
Deploymentcrypto-svcbloblifecyclemanager-svcgcr.io/kasten-images/bloblifecyclemanager:4.5.2
Deploymentcrypto-svccrypto-svcgcr.io/kasten-images/crypto:4.5.2
Deploymentdashboardbff-svcdashboardbff-svcgcr.io/kasten-images/dashboardbff:4.5.2
Deploymentexecutor-svcexecutor-svcgcr.io/kasten-images/executor:4.5.2
Deploymentexecutor-svctoolsgcr.io/kasten-images/cephtool:4.5.2
Deploymentfrontend-svcfrontend-svcgcr.io/kasten-images/frontend:4.5.2
Deploymentgatewayambassadorquay.io/datawire/ambassador:1.14.1
Deploymentjobs-svcjobs-svcgcr.io/kasten-images/jobs:4.5.2
Deploymentkanister-svckanister-svcgcr.io/kasten-images/kanister:4.5.2
Deploymentlogging-svclogging-svcgcr.io/kasten-images/logging:4.5.2
Deploymentmetering-svcmetering-svcgcr.io/kasten-images/metering:4.5.2
Deploymentstate-svcstate-svcgcr.io/kasten-images/state:4.5.2

🤖 prometheus-server

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (2)

KindNameContainerImage
Deploymentprometheus-serverprometheus-serverquay.io/prometheus/prometheus:v2.26.0
Deploymentprometheus-serverprometheus-server-configmap-reloadjimmidyson/configmap-reload:v0.5.0