Description

OpenCost and OpenCost UI

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
opencostdefault242High

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 opencost

Namespace: default  |  Automount:

🔑 Permissions (24)

RoleResourceVerbsRiskTags
ClusterRole opencostcore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole opencostcore/resourcequotasget · list · watchMediumInformationDisclosure QuotaTampering Reconnaissance ResourceConfiguration
ClusterRole opencostbatch/cronjobsget · list · watchLow
ClusterRole opencostapps/daemonsetslist · watchLow
ClusterRole opencostextensions/daemonsetsget · list · watchLow
ClusterRole opencostapps/deploymentslist · watchLow
ClusterRole opencostcore/deploymentsget · list · watchLow
ClusterRole opencostextensions/deploymentsget · list · watchLow
ClusterRole opencostcore/endpointsget · list · watchLow
ClusterRole opencostautoscaling/horizontalpodautoscalersget · list · watchLow
ClusterRole opencostbatch/jobsget · list · watchLow
ClusterRole opencostcore/limitrangesget · list · watchLowInformationDisclosure Reconnaissance ResourceConfiguration
ClusterRole opencostcore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole opencostcore/nodesget · list · watchLow
ClusterRole opencostcore/persistentvolumeclaimsget · list · watchLow
ClusterRole opencostcore/persistentvolumesget · list · watchLow
ClusterRole opencostpolicy/poddisruptionbudgetsget · list · watchLow
ClusterRole opencostcore/podsget · list · watchLow
ClusterRole opencostapps/replicasetslist · watchLow
ClusterRole opencostextensions/replicasetsget · list · watchLow
ClusterRole opencostcore/replicationcontrollersget · list · watchLow
ClusterRole opencostcore/servicesget · list · watchLow
ClusterRole opencostapps/statefulsetslist · watchLow
ClusterRole opencoststorage.k8s.io/storageclassesget · list · watchLow

⚠️ Potential Abuse (7)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymentopencostopencostghcr.io/opencost/opencost:1.120.0@sha256:c4fbe5f8fad2bc54872350460e705bf9ab43c90efa784a0cdf3a2a39a66b3b82
Deploymentopencostopencost-uighcr.io/opencost/opencost-ui:1.120.0@sha256:2a2ed5d423402b1d3f104398971191618a91bfc293f53c704606bbbd39b2652c