Description

The Cloud-Native Ingress and API-management

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
kong-kongdefault462Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 kong-kong

Namespace: default  |  Automount:

🔑 Permissions (46)

RoleResourceVerbsRiskTags
Role kong-kongcoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
ClusterRole kong-kongcore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
Role kong-kongcore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
Role kong-kongcoordination.k8s.io/configmapscreate · delete · get · list · patch · update · watchLow
ClusterRole kong-kongapiextensions.k8s.io/customresourcedefinitionslist · watchLow
ClusterRole kong-kongdiscovery.k8s.io/endpointslicesget · list · watchLow
ClusterRole kong-kongcore/eventscreate · patchLow
Role kong-kongcore/eventscreate · patchLow
ClusterRole kong-kongnetworking.k8s.io/ingressclassesget · list · watchLow
ClusterRole kong-kongconfiguration.konghq.com/ingressclassparametersesget · list · watchLow
ClusterRole kong-kongextensions/ingressesget · list · watchLow
ClusterRole kong-kongnetworking.k8s.io/ingressesget · list · watchLow
ClusterRole kong-kongextensions/ingresses/statusget · patch · updateLow
ClusterRole kong-kongnetworking.k8s.io/ingresses/statusget · patch · updateLow
ClusterRole kong-kongconfiguration.konghq.com/kongclusterpluginsget · list · watchLow
ClusterRole kong-kongconfiguration.konghq.com/kongclusterplugins/statusget · patch · updateLow
ClusterRole kong-kongconfiguration.konghq.com/kongconsumergroupsget · list · watchLow
ClusterRole kong-kongconfiguration.konghq.com/kongconsumergroups/statusget · patch · updateLow
ClusterRole kong-kongconfiguration.konghq.com/kongconsumersget · list · watchLow
ClusterRole kong-kongconfiguration.konghq.com/kongconsumers/statusget · patch · updateLow
ClusterRole kong-kongconfiguration.konghq.com/kongcustomentitiesget · list · watchLow
ClusterRole kong-kongconfiguration.konghq.com/kongcustomentities/statusget · patch · updateLow
ClusterRole kong-kongconfiguration.konghq.com/kongingressesget · list · watchLow
ClusterRole kong-kongconfiguration.konghq.com/kongingresses/statusget · patch · updateLow
ClusterRole kong-kongconfiguration.konghq.com/konglicensesget · list · watchLow
ClusterRole kong-kongconfiguration.konghq.com/konglicenses/statusget · patch · updateLow
ClusterRole kong-kongconfiguration.konghq.com/kongpluginsget · list · watchLow
ClusterRole kong-kongconfiguration.konghq.com/kongplugins/statusget · patch · updateLow
ClusterRole kong-kongconfiguration.konghq.com/kongupstreampoliciesget · list · watchLow
ClusterRole kong-kongconfiguration.konghq.com/kongupstreampolicies/statusget · patch · updateLow
ClusterRole kong-kongconfiguration.konghq.com/kongvaultsget · list · watchLow
ClusterRole kong-kongconfiguration.konghq.com/kongvaults/statusget · patch · updateLow
Role kong-kongcore/leasescreate · delete · get · list · patch · update · watchLow
Role kong-kongcore/namespacesgetLow
ClusterRole kong-kongcore/nodeslist · watchLow
ClusterRole kong-kongcore/podsget · list · watchLow
Role kong-kongcore/podsgetLow
ClusterRole kong-kongcore/secretslist · watchLow
Role kong-kongcore/secretsgetLow
ClusterRole kong-kongcore/servicesget · list · watchLow
Role kong-kongcore/servicesgetLow
ClusterRole kong-kongcore/services/statusget · patch · updateLow
ClusterRole kong-kongconfiguration.konghq.com/tcpingressesget · list · watchLow
ClusterRole kong-kongconfiguration.konghq.com/tcpingresses/statusget · patch · updateLow
ClusterRole kong-kongconfiguration.konghq.com/udpingressesget · list · watchLow
ClusterRole kong-kongconfiguration.konghq.com/udpingresses/statusget · patch · updateLow

⚠️ Potential Abuse (5)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymentkong-kongingress-controllerkong/kubernetes-ingress-controller:3.4
Deploymentkong-kongproxykong:3.9