Description

Kasten’s K10 Data Management Platform

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
prometheus-serverdefault122Medium
k10-grafanadefault01
k10-k10default021

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 prometheus-server

Namespace: default  |  Automount:

🔑 Permissions (12)

RoleResourceVerbsRiskTags
Role k10-prometheus-servercore/configmapsget · list · watchMediumConfigMapAccess DataExposure InformationDisclosure
Role k10-prometheus-servercore/endpointsget · list · watchLow
Role k10-prometheus-servercore/ingressesget · list · watchLow
Role k10-prometheus-serverextensions/ingressesget · list · watchLow
Role k10-prometheus-servernetworking.k8s.io/ingressesget · list · watchLow
Role k10-prometheus-serverextensions/ingresses/statusget · list · watchLow
Role k10-prometheus-servernetworking.k8s.io/ingresses/statusget · list · watchLow
Role k10-prometheus-servercore/nodesget · list · watchLow
Role k10-prometheus-servercore/nodes/metricsget · list · watchLow
Role k10-prometheus-servercore/nodes/proxyget · list · watchLow
Role k10-prometheus-servercore/podsget · list · watchLow
Role k10-prometheus-servercore/servicesget · list · watchLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymentprometheus-serverprometheus-servergcr.io/kasten-images/prometheus:6.0.1
Deploymentprometheus-serverprometheus-server-configmap-reloadgcr.io/kasten-images/configmap-reload:6.0.1

🤖 k10-grafana

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentk10-grafanagrafanagcr.io/kasten-images/grafana:6.0.1

🤖 k10-k10

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (21)

KindNameContainerImage
Deploymentaggregatedapis-svcaggregatedapis-svcgcr.io/kasten-images/aggregatedapis:6.0.1
Deploymentauth-svcauth-svcgcr.io/kasten-images/auth:6.0.1
Deploymentcatalog-svccatalog-svcgcr.io/kasten-images/catalog:6.0.1
Deploymentcatalog-svckanister-sidecarghcr.io/kanisterio/kanister-tools:0.92.0
Deploymentcontrollermanager-svccontrollermanager-svcgcr.io/kasten-images/controllermanager:6.0.1
Deploymentcrypto-svcbloblifecyclemanager-svcgcr.io/kasten-images/bloblifecyclemanager:6.0.1
Deploymentcrypto-svccrypto-svcgcr.io/kasten-images/crypto:6.0.1
Deploymentcrypto-svcevents-svcgcr.io/kasten-images/events:6.0.1
Deploymentcrypto-svcgarbagecollector-svcgcr.io/kasten-images/garbagecollector:6.0.1
Deploymentdashboardbff-svcdashboardbff-svcgcr.io/kasten-images/dashboardbff:6.0.1
Deploymentdashboardbff-svcvbrintegrationapi-svcgcr.io/kasten-images/vbrintegrationapi:6.0.1
Deploymentexecutor-svcexecutor-svcgcr.io/kasten-images/executor:6.0.1
Deploymentexecutor-svctoolsgcr.io/kasten-images/cephtool:6.0.1
Deploymentfrontend-svcfrontend-svcgcr.io/kasten-images/frontend:6.0.1
Deploymentgatewayambassadorgcr.io/kasten-images/emissary:6.0.1
Deploymentjobs-svcjobs-svcgcr.io/kasten-images/jobs:6.0.1
Deploymentkanister-svckanister-svcgcr.io/kasten-images/kanister:6.0.1
Deploymentlogging-svclogging-svcgcr.io/kasten-images/logging:6.0.1
Deploymentmetering-svcmetering-svcgcr.io/kasten-images/metering:6.0.1
Deploymentstate-svcadmin-svcgcr.io/kasten-images/admin:6.0.1
Deploymentstate-svcstate-svcgcr.io/kasten-images/state:6.0.1