Description

vcluster - Virtual Kubernetes Clusters

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
vc-vclusterdefault152Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 vc-vcluster

Namespace: default  |  Automount:

🔑 Permissions (15)

RoleResourceVerbsRiskTags
Role vclustercore/secretscreate · delete · get · list · patch · update · watchCriticalCredentialAccess DataExposure InformationDisclosure Persistence PotentialPrivilegeEscalation (+2 more)
Role vclustercore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
Role vclustercore/endpointscreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation Tampering TrafficRedirection
Role vclusternetworking.k8s.io/ingressescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
Role vclustercore/podscreate · delete · get · list · patch · update · watchHighLateralMovement Persistence PotentialPrivilegeEscalation Tampering WorkloadExecution
Role vclustercore/pods/attachcreate · delete · get · list · patch · update · watchHighCodeExecution LateralMovement PodAttach PotentialPrivilegeEscalation
Role vclustercore/pods/execcreate · delete · get · list · patch · update · watchHighCodeExecution LateralMovement PodExec PotentialPrivilegeEscalation
Role vclustercore/servicescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
Role vclustercore/pods/logget · list · watchMediumDataExposure InformationDisclosure LogAccess
Role vclustercore/pods/portforwardcreate · delete · get · list · patch · update · watchMediumLateralMovement NetworkManipulation PodPortForward
Role vclusterapps/deploymentsget · list · watchLow
Role vclustercore/eventsget · list · watchLow
Role vclustercore/persistentvolumeclaimscreate · delete · get · list · patch · update · watchLow
Role vclusterapps/replicasetsget · list · watchLow
Role vclusterapps/statefulsetsget · list · watchLow

⚠️ Potential Abuse (14)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
StatefulSetvclustersyncerloftsh/vcluster:0.5.0
StatefulSetvclustervclusterrancher/k3s:v1.22.2-k3s1