Description

vcluster - Virtual Kubernetes Clusters

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
vc-vclusterdefault211Critical
vc-workload-vclusterdefault00

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 vc-vcluster

Namespace: default  |  Automount:

🔑 Permissions (21)

RoleResourceVerbsRiskTags
Role vc-vclustercore/secretscreate · delete · get · list · patch · update · watchCriticalCredentialAccess DataExposure InformationDisclosure Persistence PotentialPrivilegeEscalation (+2 more)
Role vc-vclustercore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
Role vc-vclustercore/endpointscreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation Tampering TrafficRedirection
Role vc-vclusterdiscovery.k8s.io/endpointslicescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation Tampering TrafficRedirection
Role vc-vclustercore/podscreate · delete · get · list · patch · update · watchHighLateralMovement Persistence PotentialPrivilegeEscalation Tampering WorkloadExecution
Role vc-vclustercore/pods/attachcreate · delete · get · list · patch · update · watchHighCodeExecution LateralMovement PodAttach PotentialPrivilegeEscalation
Role vc-vclustercore/pods/ephemeralcontainerspatch · updateHighCodeExecution LateralMovement PotentialPrivilegeEscalation Tampering WorkloadExecution
Role vc-vclustercore/pods/execcreate · delete · get · list · patch · update · watchHighCodeExecution LateralMovement PodExec PotentialPrivilegeEscalation
Role vc-vclustercore/servicescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
Role vc-vclustercore/pods/logget · list · watchMediumDataExposure InformationDisclosure LogAccess
Role vc-vclustercore/pods/portforwardcreate · delete · get · list · patch · update · watchMediumLateralMovement NetworkManipulation PodPortForward
Role vc-vclusterapps/deploymentsget · list · watchLow
Role vc-vclustercore/eventscreate · get · list · watchLow
Role vc-vclustercore/persistentvolumeclaimscreate · delete · get · list · patch · update · watchLow
ClusterRole vc-vcluster-v-defaultcore/persistentvolumesget · listLow
Role vc-vclustercore/pods/statuspatch · updateLow
Role vc-vclusterapps/replicasetsget · list · watchLow
Role vc-vclusterapps/statefulsetsget · list · watchLow
ClusterRole vc-vcluster-v-defaultsnapshot.storage.k8s.io/volumesnapshotclassesget · listLow
ClusterRole vc-vcluster-v-defaultsnapshot.storage.k8s.io/volumesnapshotcontentscreate · delete · get · list · patch · updateLow
Role vc-vclustersnapshot.storage.k8s.io/volumesnapshotscreate · delete · get · list · patch · updateLow

⚠️ Potential Abuse (14)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
StatefulSetvclustersyncerghcr.io/loft-sh/vcluster-pro:0.32.0-next.0

🤖 vc-workload-vcluster

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (0)

No workloads use this ServiceAccount.