Description

vnode-runtime - Multi-Tenancy Container Runtime

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
vnode-runtimedefault31Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 vnode-runtime

Namespace: default  |  Automount:

🔑 Permissions (3)

RoleResourceVerbsRiskTags
ClusterRole vnode-runtimecore/nodes/proxygetCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole vnode-runtimecore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole vnode-runtimecore/podsget · list · watchLow

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
DaemonSetvnode-runtimevnode-runtimeghcr.io/loft-sh/vnode-runtime:0.2.0