Description

Kasten’s K10 Data Management Platform

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
prometheus-serverdefault122Medium
k10-grafanadefault01
k10-k10default020

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 prometheus-server

Namespace: default  |  Automount:

🔑 Permissions (12)

RoleResourceVerbsRiskTags
Role k10-prometheus-servercore/configmapsget · list · watchMediumConfigMapAccess DataExposure InformationDisclosure
Role k10-prometheus-servercore/endpointsget · list · watchLow
Role k10-prometheus-servercore/ingressesget · list · watchLow
Role k10-prometheus-serverextensions/ingressesget · list · watchLow
Role k10-prometheus-servernetworking.k8s.io/ingressesget · list · watchLow
Role k10-prometheus-serverextensions/ingresses/statusget · list · watchLow
Role k10-prometheus-servernetworking.k8s.io/ingresses/statusget · list · watchLow
Role k10-prometheus-servercore/nodesget · list · watchLow
Role k10-prometheus-servercore/nodes/metricsget · list · watchLow
Role k10-prometheus-servercore/nodes/proxyget · list · watchLow
Role k10-prometheus-servercore/podsget · list · watchLow
Role k10-prometheus-servercore/servicesget · list · watchLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymentprometheus-serverprometheus-serverquay.io/prometheus/prometheus:v2.34.0
Deploymentprometheus-serverprometheus-server-configmap-reloadjimmidyson/configmap-reload:v0.5.0

🤖 k10-grafana

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentk10-grafanagrafanagrafana/grafana:9.1.5

🤖 k10-k10

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (20)

KindNameContainerImage
Deploymentaggregatedapis-svcaggregatedapis-svcgcr.io/kasten-images/aggregatedapis:5.5.2
Deploymentauth-svcauth-svcgcr.io/kasten-images/auth:5.5.2
Deploymentcatalog-svccatalog-svcgcr.io/kasten-images/catalog:5.5.2
Deploymentcatalog-svckanister-sidecarghcr.io/kanisterio/kanister-tools:0.85.0
Deploymentcontrollermanager-svccontrollermanager-svcgcr.io/kasten-images/controllermanager:5.5.2
Deploymentcrypto-svcbloblifecyclemanager-svcgcr.io/kasten-images/bloblifecyclemanager:5.5.2
Deploymentcrypto-svccrypto-svcgcr.io/kasten-images/crypto:5.5.2
Deploymentcrypto-svcevents-svcgcr.io/kasten-images/events:5.5.2
Deploymentcrypto-svcgarbagecollector-svcgcr.io/kasten-images/garbagecollector:5.5.2
Deploymentdashboardbff-svcdashboardbff-svcgcr.io/kasten-images/dashboardbff:5.5.2
Deploymentexecutor-svcexecutor-svcgcr.io/kasten-images/executor:5.5.2
Deploymentexecutor-svctoolsgcr.io/kasten-images/cephtool:5.5.2
Deploymentfrontend-svcfrontend-svcgcr.io/kasten-images/frontend:5.5.2
Deploymentgatewayambassadorgcr.io/kasten-images/emissary:5.5.2
Deploymentjobs-svcjobs-svcgcr.io/kasten-images/jobs:5.5.2
Deploymentkanister-svckanister-svcgcr.io/kasten-images/kanister:5.5.2
Deploymentlogging-svclogging-svcgcr.io/kasten-images/logging:5.5.2
Deploymentmetering-svcmetering-svcgcr.io/kasten-images/metering:5.5.2
Deploymentstate-svcadmin-svcgcr.io/kasten-images/admin:5.5.2
Deploymentstate-svcstate-svcgcr.io/kasten-images/state:5.5.2