Description

A Helm chart for the nvidia-device-plugin on Kubernetes

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
nvidia-device-plugin-node-feature-discoverydefault21Critical
nvidia-device-plugin-node-feature-discovery-workerdefault01

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 nvidia-device-plugin-node-feature-discovery

Namespace: default  |  Automount:

🔑 Permissions (2)

RoleResourceVerbsRiskTags
ClusterRole nvidia-device-plugin-node-feature-discoverycore/nodesget · list · patch · updateCriticalDenialOfService NodeAccess PotentialPrivilegeEscalation Tampering
ClusterRole nvidia-device-plugin-node-feature-discoverynfd.k8s-sigs.io/nodefeaturerulesget · list · watchLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentnvidia-device-plugin-node-feature-discovery-mastermasterk8s.gcr.io/nfd/node-feature-discovery:v0.11.0

🤖 nvidia-device-plugin-node-feature-discovery-worker

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
DaemonSetnvidia-device-plugin-node-feature-discovery-workerworkerk8s.gcr.io/nfd/node-feature-discovery:v0.11.0